Rotate the secret
Replace the subscription's secret token with a new one. The new token is returned in this response only, and the old one stops being sent immediately — update your receiver first.
POST
https://api.centerfy.ai/webhooks/inbound/outbound-webhooks/:id/rotate-secret Headers
| Header | Required | Value | Description |
|---|---|---|---|
x-api-key | Yes | your sub-account API key (cfy_…) | Authenticates the request; or use Authorization: Bearer <key>. |
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id | string (uuid) | Yes | The outbound webhook subscription id. |
Example
curl -X POST "https://api.centerfy.ai/webhooks/inbound/outbound-webhooks/{id}/rotate-secret" \
-H "x-api-key: $CENTERFY_API_KEY" import { CenterfyClient } from "@centerfy/sdk";
const centerfy = new CenterfyClient({ apiKey: process.env.CENTERFY_API_KEY! });
const result = await centerfy.outboundWebhooks.rotateSecret("<webhookId>");
console.log(result); centerfy outboundWebhooks rotate-secret <webhookId> MCP tool: centerfy_outbound_webhooks_rotate_secret (see MCP server)
Response
{
"status": "success",
"webhook": {
"id": "6f7a8b9c-0d1e-4f2a-8b3c-4d5e6f7a8b9c",
"name": "CRM sync",
"url": "https://hooks.example.com/centerfy",
"events": [
"contact.created",
"contact.updated"
],
"is_active": true,
"source": "my-crm",
"has_secret": true,
"created_at": "2026-10-01T10:00:00.000Z",
"updated_at": "2026-10-01T10:00:00.000Z"
},
"secret_token": "1111111111111111111111111111111111111111111111111111111111111111"
}Errors
404— if the subscription is not in this sub-account.
Notes
Also adds a secret to a subscription created without one. No request body.