Rotate a webhook endpoint's secret
import { createClient, createResources } from "@morevoice/sdk";
const mv = createResources({ client: createClient({ baseUrl: "https://api.morevoice.ai/v1", auth: process.env.MOREVOICE_API_KEY }),});
const webhookEndpoint = await mv.webhookEndpoints.rotateSecret("we_Fr16fYQoriAw3w17jl7hn3", { expire_previous_in_hours: 24,});console.log(webhookEndpoint);import osimport uuid
import requests
response = requests.post( "https://api.morevoice.ai/v1/webhook_endpoints/we_Fr16fYQoriAw3w17jl7hn3/rotate_secret", headers={"Authorization": f"Bearer {os.environ['MOREVOICE_API_KEY']}", "Idempotency-Key": str(uuid.uuid4())}, json={ "expire_previous_in_hours": 24, },)response.raise_for_status()print(response.json())curl -X POST https://api.morevoice.ai/v1/webhook_endpoints/we_Fr16fYQoriAw3w17jl7hn3/rotate_secret \ -H "Authorization: Bearer $MOREVOICE_API_KEY" \ -H "Content-Type: application/json" \ -H "Idempotency-Key: $(uuidgen)" \ -d '{ "expire_previous_in_hours": 24}'Creates a new signing secret and returns it (this once). The previous secret keeps signing alongside it for expire_previous_in_hours (default 24), so webhook-signature carries both signatures until your receivers switch.
Try it in the API playground with a test-mode key.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”A webhook endpoint ID (we_…).
Header Parameters
Section titled “Header Parameters”The API version to use for this request. Defaults to the version the API key is pinned to.
Example
2026-11-01A unique key (for example a UUID) that makes this request safe to retry: for 24 hours, a retry with the same key and parameters returns the first response instead of acting twice.
Example
5f0c1e8a-7b2d-4c3e-9f1a-2b6d8e4c0a17Request Body
Section titled “Request Body”object
How long the previous secret keeps signing alongside the new one (0–72 hours, default 24; 0 stops it at once).
Responses
Section titled “Responses”OK
A URL that receives signed events (Standard Webhooks: webhook-id, webhook-timestamp, webhook-signature).
object
The API version event payloads are rendered in. legacy: an endpoint moved from the old webhook settings, which keeps getting the previous body ({id, event, createdAt, data}).
An ISO-8601 timestamp in UTC.
The event types sent to this endpoint; ["*"] means every event.
A webhook endpoint ID (prefix we_).
Also sends the previous X-Webhook-* headers (moved endpoints, for one deprecation cycle).
true in live mode, false in test mode.
Deliveries in flight to this endpoint at once; more wait their turn.
Up to 50 key/value pairs (keys up to 40 characters, values up to 500) you attach to an object. Returned as sent.
object
The signing secret (whsec_…). Returned only when the endpoint is created and when its secret is rotated: store it then.
auto_disabled: every delivery failed for 72 hours, so sending stopped (and your admins were told). Set status: enabled to resume.
An ISO-8601 timestamp in UTC.
Where events are POSTed.
Example
{ "api_version": "2026-11-01", "campaign_id": null, "created": "2026-11-03T09:14:22.000Z", "description": "CRM sync", "disabled_at": null, "disabled_reason": null, "enabled_events": [ "call.ended", "call.analyzed" ], "id": "we_4Gk2LmN9pQ4rS6tV8wX0yZ", "legacy_headers": false, "livemode": true, "max_in_flight": 10, "metadata": {}, "object": "webhook_endpoint", "previous_secret_expires_at": null, "status": "enabled", "updated": "2026-11-03T09:14:22.000Z", "url": "https://hooks.example.com/webhooks"}The request is invalid: a parameter is missing, malformed or unknown, or the version header is unknown.
Every /v1 error.
object
object
A stable, machine-readable code from the error-code catalogue.
Structured context, e.g. required_scope or the compliance verdict.
object
A link to the documentation of this code.
A human-readable explanation. Do not parse it.
The request parameter the error relates to, e.g. to or metadata[order_id].
The X-Request-Id of this request. Quote it when you contact support.
The category of the error.
Example
{ "error": { "code": "parameter_missing", "doc_url": "https://docs.morevoice.ai/api/errors#parameter-missing", "message": "Missing required parameter: to.", "param": "to", "request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ", "type": "invalid_request_error" }}Headers
Section titled “Headers”The request’s ID (req_…). Quote it when you contact support.
No valid API key was sent.
Every /v1 error.
object
object
A stable, machine-readable code from the error-code catalogue.
Structured context, e.g. required_scope or the compliance verdict.
object
A link to the documentation of this code.
A human-readable explanation. Do not parse it.
The request parameter the error relates to, e.g. to or metadata[order_id].
The X-Request-Id of this request. Quote it when you contact support.
The category of the error.
Example
{ "error": { "code": "invalid_api_key", "doc_url": "https://docs.morevoice.ai/api/errors#invalid-api-key", "message": "Invalid API key.", "request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ", "type": "authentication_error" }}Headers
Section titled “Headers”The request’s ID (req_…). Quote it when you contact support.
The key may not do this (a missing scope, a plan limit, or a compliance block).
Every /v1 error.
object
object
A stable, machine-readable code from the error-code catalogue.
Structured context, e.g. required_scope or the compliance verdict.
object
A link to the documentation of this code.
A human-readable explanation. Do not parse it.
The request parameter the error relates to, e.g. to or metadata[order_id].
The X-Request-Id of this request. Quote it when you contact support.
The category of the error.
Example
{ "error": { "code": "missing_scope", "doc_url": "https://docs.morevoice.ai/api/errors#missing-scope", "message": "This API key lacks the calls:write scope.", "request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ", "type": "permission_error" }}Headers
Section titled “Headers”The request’s ID (req_…). Quote it when you contact support.
No object with this ID exists in this organisation and mode.
Every /v1 error.
object
object
A stable, machine-readable code from the error-code catalogue.
Structured context, e.g. required_scope or the compliance verdict.
object
A link to the documentation of this code.
A human-readable explanation. Do not parse it.
The request parameter the error relates to, e.g. to or metadata[order_id].
The X-Request-Id of this request. Quote it when you contact support.
The category of the error.
Example
{ "error": { "code": "resource_missing", "doc_url": "https://docs.morevoice.ai/api/errors#resource-missing", "message": "No such object: 'call_4Gk2'.", "param": "id", "request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ", "type": "not_found" }}Headers
Section titled “Headers”The request’s ID (req_…). Quote it when you contact support.
The request conflicts with the object’s state, or the Idempotency-Key was reused with other parameters.
Every /v1 error.
object
object
A stable, machine-readable code from the error-code catalogue.
Structured context, e.g. required_scope or the compliance verdict.
object
A link to the documentation of this code.
A human-readable explanation. Do not parse it.
The request parameter the error relates to, e.g. to or metadata[order_id].
The X-Request-Id of this request. Quote it when you contact support.
The category of the error.
Example
{ "error": { "code": "idempotency_mismatch", "doc_url": "https://docs.morevoice.ai/api/errors#idempotency-mismatch", "message": "This Idempotency-Key was already used with different parameters.", "request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ", "type": "idempotency_error" }}Headers
Section titled “Headers”The request’s ID (req_…). Quote it when you contact support.
Too many requests, or no call capacity right now. Retry after the Retry-After delay.
Every /v1 error.
object
object
A stable, machine-readable code from the error-code catalogue.
Structured context, e.g. required_scope or the compliance verdict.
object
A link to the documentation of this code.
A human-readable explanation. Do not parse it.
The request parameter the error relates to, e.g. to or metadata[order_id].
The X-Request-Id of this request. Quote it when you contact support.
The category of the error.
Example
{ "error": { "code": "rate_limited", "doc_url": "https://docs.morevoice.ai/api/errors#rate-limited", "message": "Too many requests. Retry after 1 second.", "request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ", "type": "rate_limit_error" }}Headers
Section titled “Headers”Seconds to wait before retrying.
The request’s ID (req_…). Quote it when you contact support.
Something went wrong on MoreVoice’s side. Retry with the same Idempotency-Key.
Every /v1 error.
object
object
A stable, machine-readable code from the error-code catalogue.
Structured context, e.g. required_scope or the compliance verdict.
object
A link to the documentation of this code.
A human-readable explanation. Do not parse it.
The request parameter the error relates to, e.g. to or metadata[order_id].
The X-Request-Id of this request. Quote it when you contact support.
The category of the error.
Example
{ "error": { "code": "internal_error", "doc_url": "https://docs.morevoice.ai/api/errors#internal-error", "message": "Something went wrong on MoreVoice's side.", "request_id": "req_7Hk2LmN9pQ4rS6tV8wX0yZ", "type": "api_error" }}Headers
Section titled “Headers”The request’s ID (req_…). Quote it when you contact support.