> ## Documentation Index
> Fetch the complete documentation index at: https://docs.telepatia.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate a webhook signing secret

> Generate a new signing secret for the webhook, bumping its version. The new `signingSecret` is shown only once. The previous secret stops verifying immediately.



## OpenAPI

````yaml /pt-BR/scribe-api/openapi-institutional.json post /v1/webhooks/{webhook_id}/rotate-secret
openapi: 3.1.0
info:
  title: Scribe Public API
  description: >-
    API REST externa para integração com a plataforma Telepatia. Autentique-se
    com chaves de API, defina o contexto da consulta e busque sessões de scribe.
  version: 0.1.0
servers:
  - url: https://scribe-api.telepatia.ai
    description: Production
security:
  - BearerAuth: []
paths:
  /v1/webhooks/{webhook_id}/rotate-secret:
    post:
      tags:
        - Webhooks
      summary: Rotate a webhook signing secret
      description: >-
        Generate a new signing secret for the webhook, bumping its version. The
        new `signingSecret` is shown only once. The previous secret stops
        verifying immediately.
      operationId: >-
        api_webhook_rotate_secret_post_v1_webhooks__webhook_id__rotate_secret_post
      parameters:
        - name: webhook_id
          in: path
          required: true
          schema:
            type: string
            title: Webhook Id
      responses:
        '200':
          description: Resposta bem-sucedida
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RotateSecretResponse'
        '401':
          description: Não autorizado — chave de API ausente ou inválida.
          content:
            application/json:
              examples:
                authentication_required:
                  summary: Invalid or missing API key
                  value:
                    error:
                      type: authentication_error
                      code: authentication_required
                      message: Invalid API key.
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              examples:
                permission_denied:
                  summary: Caller lacks permission for this resource
                  value:
                    error:
                      type: permission_error
                      code: permission_denied
                      message: You do not have permission to access this resource.
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: Não encontrado — o recurso solicitado não existe.
          content:
            application/json:
              examples:
                resource_not_found:
                  summary: Resource not found
                  value:
                    error:
                      type: invalid_request_error
                      code: resource_not_found
                      message: No session scribe found for the given consultation ID.
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '503':
          description: Serviço indisponível — uma dependência externa está indisponível.
          content:
            application/json:
              examples:
                service_unavailable:
                  summary: External service unavailable
                  value:
                    error:
                      type: api_error
                      code: service_unavailable
                      message: >-
                        Unable to generate verification code. Please try again
                        later.
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - BearerAuth: []
components:
  schemas:
    RotateSecretResponse:
      properties:
        id:
          type: string
          title: Id
        url:
          type: string
          title: Url
        name:
          anyOf:
            - type: string
            - type: 'null'
          title: Name
          description: Optional human-readable label, or null if unset.
        events:
          items:
            $ref: '#/components/schemas/WebhookEventName'
          type: array
          title: Events
        event:
          anyOf:
            - $ref: '#/components/schemas/WebhookEventName'
            - type: 'null'
          description: 'Deprecated: the first subscribed event (events[0]). Use `events`.'
          deprecated: true
        isActive:
          type: boolean
          title: Isactive
        signingSecretPrefix:
          anyOf:
            - type: string
            - type: 'null'
          title: Signingsecretprefix
          description: >-
            Display hint for the signing secret (e.g. 'whsec_a1b2c3d4'). The raw
            secret is only returned at creation/rotation.
        signingSecretVersion:
          anyOf:
            - type: integer
            - type: 'null'
          title: Signingsecretversion
        createdAt:
          anyOf:
            - type: string
            - type: 'null'
          title: Createdat
        updatedAt:
          anyOf:
            - type: string
            - type: 'null'
          title: Updatedat
        deletedAt:
          anyOf:
            - type: string
            - type: 'null'
          title: Deletedat
        signingSecret:
          type: string
          title: Signingsecret
          description: >-
            Raw HMAC signing secret. Shown once at creation — store it now; it
            is never retrievable again. Use it to verify the
            X-Scribe-Api-Signature header.
      type: object
      required:
        - id
        - url
        - events
        - isActive
        - signingSecret
      title: RotateSecretResponse
      description: Rotate response — same shape as create; carries the new raw secret once.
    ErrorResponse:
      description: Envelope padronizado de resposta de erro.
      properties:
        error:
          $ref: '#/components/schemas/ErrorDetail'
      required:
        - error
      title: ErrorResponse
      type: object
    WebhookEventName:
      type: string
      enum:
        - scribe_session.created
        - scribe_session.completed
        - scribe_session.error
        - scribe_session.updated
        - scribe_session.cancelled
        - scribe_session.deleted
      title: WebhookEventName
      description: |-
        Webhook event types exposed to API clients.

        Mirrors `SynapseWebhookEventType` enum in datalayer (camelCase) but
        rendered to clients as snake_case dotted strings (closer to Stripe
        convention and easier to grep in caller logs).
    ErrorDetail:
      description: >-
        Detalhe do erro com códigos legíveis por máquina e mensagem legível por
        humanos.
      properties:
        type:
          description: Broad error category for high-level handling.
          examples:
            - invalid_request_error
          title: Type
          type: string
        code:
          description: Machine-readable error code. Clients should switch on this value.
          examples:
            - parameter_invalid
          title: Code
          type: string
        message:
          description: Human-readable error message ending with a period.
          examples:
            - >-
              idCountry must be a valid country name, ISO alpha-2, or ISO
              alpha-3 code.
          title: Message
          type: string
        param:
          anyOf:
            - type: string
            - type: 'null'
          default: null
          description: The request field that caused the error, if applicable.
          examples:
            - idCountry
          title: Param
        details:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          default: null
          description: Optional structured, machine-readable context for the error.
          examples:
            - pendingConsultations:
                - sessionId: abc123
                  url: https://...
          title: Details
      required:
        - type
        - code
        - message
      title: ErrorDetail
      type: object
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: Chave de API enviada como token Bearer

````