> ## Documentation Index
> Fetch the complete documentation index at: https://vastai-80aa3a82-auto-openapi-preview-pr-5003.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate Webhook Secret

> Rotate the signing secret for one of the caller's webhooks; the new secret is returned once and the prior secret is invalidated immediately.



## OpenAPI

````yaml /api-reference/openapi.yaml post /api/v0/webhooks/{id}/rotate-secret
openapi: 3.1.0
info:
  title: Vast.ai API
  description: >-
    Vast.ai REST API for managing GPU cloud instances, machine operations, and
    AI/ML workflows.


    ## AI Agent Quick-Start


    Install the CLI skill for your agent (Claude Code, Cursor, Windsurf, etc.):
      npx skills add vast-ai/vast-cli

    CLI reference:
    https://raw.githubusercontent.com/vast-ai/vast-cli/master/vastai/SKILL.md

    SDK reference:
    https://raw.githubusercontent.com/vast-ai/vast-cli/master/vastai_sdk/SKILL.md


    ## Auth

    All endpoints require `Authorization: Bearer $VAST_API_KEY`.

    Get your key at: https://cloud.vast.ai/manage-keys/


    ## Key Quirks

    - `gpu_ram` in CLI = GB; in REST API = MB (CLI auto-converts)

    - SSH keys must be registered BEFORE creating an instance (VM: no recovery;
    Docker: can add post-create)

    - `onstart` field is limited to 4048 characters -- gzip+base64 for longer
    scripts

    - `POST /api/v0/asks/{id}/` (create instance) returns `new_contract` as the
    instance ID, not `id`

    - Poll trap: if `actual_status` becomes `exited`, `unknown`, or `offline` it
    will never reach `running` -- destroy and retry
  version: 1.0.0
  contact:
    name: Vast.ai Support
    url: https://discord.gg/vast
  license:
    name: Vast.ai Terms of Service
    url: https://vast.ai/terms/
servers:
  - url: https://console.vast.ai
    description: Production server
security:
  - BearerAuth: []
paths:
  /api/v0/webhooks/{id}/rotate-secret:
    post:
      tags:
        - Accounts
      summary: Rotate Webhook Secret
      description: >-
        Rotate the signing secret for one of the caller's webhooks; the new
        secret is returned once and the prior secret is invalidated immediately.
      operationId: rotateWebhookSecret
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: integer
          description: >-
            Unique identifier of the webhook whose signing secret is being
            rotated.
      responses:
        '200':
          description: >-
            Success; returns {success: true, webhook: object} where webhook
            includes the new webhook_secret (revealed once only)
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    description: Always true on success.
                  webhook:
                    type: object
                    description: >-
                      The webhook object with id, user_id, name, webhook_url,
                      event_types, created_at, updated_at, and the new
                      webhook_secret.
                    properties:
                      id:
                        type: integer
                        description: Webhook ID.
                      user_id:
                        type: integer
                        description: Owning user ID.
                      name:
                        type: string
                        description: Optional display name.
                      webhook_url:
                        type: string
                        description: The HTTPS endpoint URL.
                      event_types:
                        type: array
                        items:
                          type: string
                        description: Subscribed event type slugs.
                      created_at:
                        type: number
                        description: Unix timestamp of creation.
                      updated_at:
                        type: number
                        description: Unix timestamp of last update.
                      webhook_secret:
                        type: string
                        description: New signing secret; returned only at rotation time.
        '404':
          description: >-
            Webhook not found; returns {success: false, msg: 'Webhook not
            found'}
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - BearerAuth: []
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
        msg:
          type: string
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: API key must be provided in the Authorization header

````