> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentarea.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate Signing Secret

> Generate a new signing secret for a generic webhook and return it once.

Signs an unsigned webhook, or replaces the secret of a signed one: from
this call on, requests signed with any previous secret, or not signed, are
refused. The secret is in ``signing_secret`` of this response only.

Raises:
    HTTPException: 404 if the trigger does not exist; 400 if it is not a
        generic webhook (other channels are signed with their provider's
        secret); 409 if its secret is set inline in ``validation_rules`` or
        ``webhook_config``, which this call cannot replace.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/workspaces/{workspace}/triggers/{trigger_id}/signing-secret
openapi: 3.1.0
info:
  description: >-
    Modular and extensible framework for building AI agents. This API requires
    JWT Bearer token authentication for most endpoints. Include your JWT token
    in the Authorization header. Public endpoints include /, /health, /docs,
    /redoc, and /openapi.json.
  title: AgentArea API
  version: 0.1.0
servers: []
security:
  - bearer: []
paths:
  /v1/workspaces/{workspace}/triggers/{trigger_id}/signing-secret:
    post:
      tags:
        - v1
        - protected
        - triggers
      summary: Rotate Signing Secret
      description: >-
        Generate a new signing secret for a generic webhook and return it once.


        Signs an unsigned webhook, or replaces the secret of a signed one: from

        this call on, requests signed with any previous secret, or not signed,
        are

        refused. The secret is in ``signing_secret`` of this response only.


        Raises:
            HTTPException: 404 if the trigger does not exist; 400 if it is not a
                generic webhook (other channels are signed with their provider's
                secret); 409 if its secret is set inline in ``validation_rules`` or
                ``webhook_config``, which this call cannot replace.
      operationId: rotate_signing_secret_v1_triggers__trigger_id__signing_secret_post
      parameters:
        - in: path
          name: trigger_id
          required: true
          schema:
            format: uuid
            title: Trigger Id
            type: string
        - description: Slug of the workspace the request acts in
          in: path
          name: workspace
          required: true
          schema:
            description: Slug of the workspace the request acts in
            maxLength: 120
            pattern: ^[a-z0-9]+(?:-[a-z0-9]+)*$
            title: Workspace
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TriggerResponse'
          description: Successful Response
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Validation Error
      security:
        - HTTPBearer: []
components:
  schemas:
    TriggerResponse:
      description: Response model for trigger data.
      properties:
        agent_id:
          format: uuid
          title: Agent Id
          type: string
        allowed_methods:
          anyOf:
            - items:
                type: string
              type: array
            - type: 'null'
          title: Allowed Methods
        conditions:
          additionalProperties: true
          title: Conditions
          type: object
        consecutive_failures:
          title: Consecutive Failures
          type: integer
        created_at:
          format: date-time
          title: Created At
          type: string
        created_by:
          title: Created By
          type: string
        cron_expression:
          anyOf:
            - type: string
            - type: 'null'
          title: Cron Expression
        data_extractor:
          anyOf:
            - type: string
            - type: 'null'
          title: Data Extractor
        description:
          title: Description
          type: string
        event_types:
          items:
            type: string
          title: Event Types
          type: array
        failure_threshold:
          title: Failure Threshold
          type: integer
        has_channel_credentials:
          default: false
          title: Has Channel Credentials
          type: boolean
        id:
          format: uuid
          title: Id
          type: string
        is_active:
          title: Is Active
          type: boolean
        last_execution_at:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
          title: Last Execution At
        name:
          title: Name
          type: string
        next_run_time:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
          title: Next Run Time
        signature_scheme:
          anyOf:
            - $ref: '#/components/schemas/WebhookSignatureScheme'
            - type: 'null'
          description: Signing scheme of a generic webhook; null for other types.
        signing_secret:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Generated signing secret of a generic webhook. Returned only by the
            create and rotate calls that generated it; never readable
            afterwards.
          title: Signing Secret
        task_parameters:
          additionalProperties: true
          title: Task Parameters
          type: object
        timezone:
          anyOf:
            - type: string
            - type: 'null'
          title: Timezone
        trigger_type:
          title: Trigger Type
          type: string
        updated_at:
          format: date-time
          title: Updated At
          type: string
        validation_rules:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Validation Rules
        webhook_config:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Webhook Config
        webhook_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Webhook Id
        webhook_signing:
          anyOf:
            - enum:
                - signed
                - unsigned
                - unsupported
              type: string
            - type: 'null'
          description: >-
            What protects the public webhook URL. 'signed': requests without a
            valid signature or token are refused. 'unsigned': this trigger has
            no secret, so any request starts the agent. 'unsupported': the
            platform does not verify this provider's requests. Null for
            non-webhook triggers, or when the stored secret could not be read.
          title: Webhook Signing
        webhook_type:
          anyOf:
            - type: string
            - type: 'null'
          title: Webhook Type
      required:
        - id
        - name
        - description
        - agent_id
        - trigger_type
        - is_active
        - task_parameters
        - conditions
        - created_at
        - updated_at
        - created_by
        - failure_threshold
        - consecutive_failures
      title: TriggerResponse
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    WebhookSignatureScheme:
      description: How a sender signs requests to a generic webhook.
      properties:
        algorithm:
          description: HMAC digest, e.g. 'sha256'.
          title: Algorithm
          type: string
        header:
          description: Request header carrying the signature.
          title: Header
          type: string
        prefix:
          description: Text before the hex digest in the header; often empty.
          title: Prefix
          type: string
      required:
        - header
        - algorithm
        - prefix
      title: WebhookSignatureScheme
      type: object
    ValidationError:
      properties:
        ctx:
          title: Context
          type: object
        input:
          title: Input
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object
  securitySchemes:
    bearer:
      bearerFormat: JWT
      description: JWT Bearer token for authentication
      scheme: bearer
      type: http
    HTTPBearer:
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.