Rotate the secret

Replace the subscription's secret token with a new one. The new token is returned in this response only, and the old one stops being sent immediately — update your receiver first.

POST https://api.centerfy.ai/webhooks/inbound/outbound-webhooks/:id/rotate-secret

Headers

HeaderRequiredValueDescription
x-api-keyYesyour sub-account API key (cfy_…)Authenticates the request; or use Authorization: Bearer <key>.

Path parameters

NameTypeRequiredDescription
idstring (uuid)YesThe outbound webhook subscription id.

Example

curl -X POST "https://api.centerfy.ai/webhooks/inbound/outbound-webhooks/{id}/rotate-secret" \
  -H "x-api-key: $CENTERFY_API_KEY"
import { CenterfyClient } from "@centerfy/sdk";

const centerfy = new CenterfyClient({ apiKey: process.env.CENTERFY_API_KEY! });

const result = await centerfy.outboundWebhooks.rotateSecret("<webhookId>");
console.log(result);
centerfy outboundWebhooks rotate-secret <webhookId>

MCP tool: centerfy_outbound_webhooks_rotate_secret (see MCP server)

Response

{
  "status": "success",
  "webhook": {
    "id": "6f7a8b9c-0d1e-4f2a-8b3c-4d5e6f7a8b9c",
    "name": "CRM sync",
    "url": "https://hooks.example.com/centerfy",
    "events": [
      "contact.created",
      "contact.updated"
    ],
    "is_active": true,
    "source": "my-crm",
    "has_secret": true,
    "created_at": "2026-10-01T10:00:00.000Z",
    "updated_at": "2026-10-01T10:00:00.000Z"
  },
  "secret_token": "1111111111111111111111111111111111111111111111111111111111111111"
}

Errors

  • 404 — if the subscription is not in this sub-account.

Notes

Also adds a secret to a subscription created without one. No request body.

© 2026 Centerfy AI. All rights reserved.