> ## Documentation Index
> Fetch the complete documentation index at: https://docs.octavehq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate an entity webhook signing secret

> Workspace-scoped; requires a workspace owner or Octave admin API key. Requires write API access. Signing secrets are returned only on creation or rotation; store them securely.  



## OpenAPI

````yaml post /api/v2/entity-webhook/rotate-secret
openapi: 3.0.0
info:
  version: 6.0.0
  title: Octave API
  description: API for Octave workspace management and AI-powered content generation
servers:
  - url: https://app.octavehq.com
security:
  - ApiKeyAuth: []
paths:
  /api/v2/entity-webhook/rotate-secret:
    post:
      tags:
        - Entity Webhooks
      summary: Rotate an entity webhook signing secret
      description: >-
        Workspace-scoped; requires a workspace owner or Octave admin API key.
        Requires write API access. Signing secrets are returned only on creation
        or rotation; store them securely.  
      operationId: rotateEntityWebhookSecret
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                oId:
                  type: string
                  minLength: 1
              required:
                - oId
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  _metadata:
                    $ref: '#/components/schemas/Metadata'
                  secret:
                    type: string
                required:
                  - _metadata
                  - secret
        '403':
          description: Insufficient permission or read-only key
        '404':
          description: Endpoint not found in this workspace
components:
  schemas:
    Metadata:
      type: object
      properties:
        usage:
          type: number
          default: 0
          example: 0
          description: API usage
        requestId:
          type: string
          example: requestId
          description: Request ID
        message:
          type: string
          example: message
          description: Message
        timestamp:
          type: string
          example: '2021-01-01T00:00:00.000Z'
          description: Timestamp
      required:
        - requestId
        - timestamp
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: api_key

````