> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zavu.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate a tool's webhook secret

> Generate a new signing secret for this tool. The previous one stops working on the next call, with no overlap, so update your endpoint first. The tool keeps its id, so flows that reference it by name are unaffected.



## OpenAPI

````yaml /openapi.json post /v1/senders/{senderId}/agent/tools/{toolId}/webhook/secret
openapi: 3.0.3
info:
  title: Zavu Unified Messaging Layer API
  version: 0.2.0
  description: >
    Unified multi-channel messaging API for Zavu.


    Supported channels:

    - **SMS**: Simple text messages

    - **WhatsApp**: Rich messaging with media, buttons, lists, CTA URL buttons,
    location requests, and templates

    - **Telegram**: Bot messaging with text, media, and interactive elements

    - **Email**: Transactional emails via Amazon SES


    Design goals:

    - Simple `send()` entrypoint for developers

    - Project-level authentication via Bearer token

    - Support for all WhatsApp message types (text, image, video, audio,
    document, sticker, location, contact, buttons, list, cta_url,
    location_request, reaction, template)

    - If a non-text message type is sent, WhatsApp channel is used automatically

    - 24-hour WhatsApp conversation window enforcement

    - Universal `to` field accepts phone numbers (E.164), email addresses, or
    numeric chat IDs (Telegram/Instagram/Messenger)
servers:
  - url: https://api.zavu.dev
security:
  - bearerAuth: []
paths:
  /v1/senders/{senderId}/agent/tools/{toolId}/webhook/secret:
    post:
      tags:
        - Agent Tools
      summary: Rotate a tool's webhook secret
      description: >-
        Generate a new signing secret for this tool. The previous one stops
        working on the next call, with no overlap, so update your endpoint
        first. The tool keeps its id, so flows that reference it by name are
        unaffected.
      operationId: rotateAgentToolWebhookSecret
      parameters:
        - $ref: '#/components/parameters/SenderIdParam'
        - $ref: '#/components/parameters/ToolIdParam'
      responses:
        '200':
          description: New secret generated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebhookSecretResponse'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Tool not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearerAuth: []
components:
  parameters:
    SenderIdParam:
      name: senderId
      in: path
      required: true
      schema:
        type: string
    ToolIdParam:
      name: toolId
      in: path
      required: true
      schema:
        type: string
  schemas:
    WebhookSecretResponse:
      type: object
      required:
        - secret
      properties:
        secret:
          type: string
          description: The new webhook secret.
          example: whsec_abc123...
    Error:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: string
          example: invalid_request
        message:
          type: string
          example: Phone number is invalid
        details:
          type: object
          additionalProperties: true
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````