> ## Documentation Index
> Fetch the complete documentation index at: https://nango.dev/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate the webhook signing key

> Replace the key Nango signs its webhooks with. The previous key stops being used within 5 minutes,
so verify against both during that window. Requires the `environment:webhook_signing_key:rotate` scope.


<Info>
  Requires an [Environment API key](/docs/reference/backend/http-api/api-keys#environment-api-keys) with the `environment:webhook_signing_key:rotate` scope. It rotates the key of the environment the API key belongs to.
</Info>

Replaces the key Nango uses to [sign webhooks](/docs/guides/platform/webhooks-from-nango#verifying-webhooks-from-nango). The new key is returned once, and stays readable under **Environment Settings > Webhooks > Signing key**.

<Warning>
  For up to 5 minutes after a rotation, webhooks are signed with either the old or the new key. Accept both until then.
</Warning>

<ResponseExample>
  ```json Example Response theme={null}
  {
    "data": {
      "webhook_signing_key": "5f1c0d2e-6a1b-4f3c-9d8e-7b6a5c4d3e2f"
    }
  }
  ```
</ResponseExample>


## OpenAPI

````yaml POST /environment/webhook-signing-key/rotate
openapi: 3.1.0
info:
  title: Nango API
  description: Nango API specs used to authorize & sync data with external APIs.
  version: 1.0.0
servers:
  - url: https://api.nango.dev
    description: Production server
  - url: http://localhost:3003
    description: Local server
security:
  - bearerAuth: []
externalDocs:
  url: https://nango.dev/docs/reference/backend/http-api/authentication
paths:
  /environment/webhook-signing-key/rotate:
    post:
      summary: Rotate the webhook signing key
      description: >
        Replace the key Nango signs its webhooks with. The previous key stops
        being used within 5 minutes,

        so verify against both during that window. Requires the
        `environment:webhook_signing_key:rotate` scope.
      responses:
        '200':
          description: The new webhook signing key
          content:
            application/json:
              schema:
                type: object
                required:
                  - data
                properties:
                  data:
                    type: object
                    required:
                      - webhook_signing_key
                    properties:
                      webhook_signing_key:
                        type: string
                        description: The new webhook signing key
                        example: 5f1c0d2e-6a1b-4f3c-9d8e-7b6a5c4d3e2f
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          description: >-
            The environment has more than one webhook signing key and cannot be
            rotated automatically.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StdError'
        '500':
          $ref: '#/components/responses/ServerError'
components:
  responses:
    BadRequest:
      description: Bad request
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/StdError'
    Unauthorized:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/StdError'
    Forbidden:
      description: Forbidden
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/StdError'
    NotFound:
      description: Not Found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/StdError'
    ServerError:
      description: Server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/StdError'
  schemas:
    StdError:
      type: object
      additionalProperties: false
      properties:
        error:
          type: object
          additionalProperties: false
          required:
            - code
          properties:
            code:
              type: string
            message:
              type: string
            errors:
              type: array
              items:
                type: object
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        An Environment API key from your Nango environment, or an Account API
        key for account-level endpoints.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.