> ## Documentation Index
> Fetch the complete documentation index at: https://docs.eversince.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# create or rotate the signing secret

> Creates the secret when there is none. rotate: true issues a new one; the old one keeps verifying for 24 hours, and deliveries carry both signatures meanwhile.



## OpenAPI

````yaml /openapi.json post /webhook-secret
openapi: 3.1.0
info:
  title: Eversince API
  version: '1'
  description: >-
    Every Eversince tool as one POST call, plus the routes beside them: the tool
    list, account and keys, uploads, webhooks and models. The prose is at
    https://docs.eversince.ai.
servers:
  - url: https://eversince.ai/api/v1
security:
  - bearer: []
tags:
  - name: Discovery
    description: The tool list, the same on the MCP server, the REST API and the CLI.
  - name: Workspace
    description: Jobs, balances, settings, templates, skills and the overview.
  - name: Library
    description: >-
      Items, search, import, reading media, comments, boards, calendars, the
      brand kit and public links.
  - name: Timeline
    description: 'Video editing: timelines, clips, captions, sound, language and rendering.'
  - name: Canvas
    description: 'Still editing: canvases, slides, layers and rendering.'
  - name: Generation
    description: Image, video and audio generation, upscaling, cutouts and models.
  - name: Research
    description: 'What platforms publish: pulling and keeping posts.'
  - name: Account
    description: Balances, keys, workspaces and script sessions.
  - name: Uploads
    description: Files into the library by presigned upload or by URL.
  - name: Webhooks
    description: Job results posted to a URL as they complete.
  - name: Models
    description: Generation models and cost estimates.
paths:
  /webhook-secret:
    post:
      tags:
        - Webhooks
      summary: create or rotate the signing secret
      description: >-
        Creates the secret when there is none. rotate: true issues a new one;
        the old one keeps verifying for 24 hours, and deliveries carry both
        signatures meanwhile.
      operationId: create_or_rotate_webhook_secret
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                rotate:
                  type: boolean
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  secret:
                    type: string
                  rotated:
                    type: boolean
                required:
                  - secret
                  - rotated
        '401':
          description: 'unauthorized: the credential did not check out.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                      status:
                        type: number
                    required:
                      - code
                      - message
                      - status
                required:
                  - error
        '403':
          description: 'forbidden: the credential has no access to this.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                      status:
                        type: number
                    required:
                      - code
                      - message
                      - status
                required:
                  - error
        '429':
          description: 'rate_limited: Retry-After says when.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                      status:
                        type: number
                    required:
                      - code
                      - message
                      - status
                required:
                  - error
        '500':
          description: internal_error.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                      status:
                        type: number
                    required:
                      - code
                      - message
                      - status
                required:
                  - error
components:
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      description: >-
        An API key (es_live_…) from Settings, under API keys, or an OAuth access
        token.

````