Skip to navigation

Rotate a project's signing key

View as MarkdownOpen in Claude

Rotates the project’s signing key and returns the project with the new signing_key.

The previous key may take about 1–2 minutes to stop working. As with create, the signing_key is only returned on this response and cannot be retrieved afterward.

Use it when the project’s webhook-signing credential has been exposed or is due for rotation; this is separate from creating or revoking REST API tokens.

Permissions

With a project API token, the token must have the following scope(s) enabled to make a successful request: Management.

With a Personal access token there are no scopes. The token holder must be an owner or admin of the space, and the request reaches only the projects the holder is enabled for, plus their subprojects.

Learn more about API scopes.

Authentication

AuthorizationBasic

SignalWire Basic Authentication using Project ID and API Token.

The client sends HTTP requests with the Authorization header containing the word Basic followed by a space and a base64-encoded string of project_id:token. The project ID will be used as the username and the API token as the password.

Example:

Authorization: Basic base64(project_id:token)
OR
AuthorizationBasic

Personal access token authentication for space-wide administration.

Send HTTP Basic auth with an empty username and the Personal access token as the password. A Personal access token carries your own authority rather than a project's: it is created from your user menu in the Dashboard, is prefixed pat_, and has no scopes. The holder must be an owner or admin of the space named by the subdomain, and the token acts only on that space.

Example:

Authorization: Basic base64(:pat_...)

Path parameters

idstringRequiredformat: "uuid"
The unique identifier of the project or subproject.

Response

The request has succeeded.
idstringformat: "uuid"
The unique identifier of the project.
namestring
The name of the project.
parent_project_idstring or nullformat: "uuid"

The unique identifier of the root project. null when this project is itself a root project.

subprojectboolean

true when this project is a subproject.

region_preferencestring

The effective region preference for the project. Returned in all responses; it is not currently settable through this API.

protect_recordingsboolean
When enabled, recordings created within the project require authentication to access.
protect_message_mediaboolean
When enabled, message media created within the project requires authentication to access.
protect_fax_mediaboolean
When enabled, fax media created within the project requires authentication to access.
force_https_requestsboolean
When enabled, requests made to the project's webhooks and callbacks must use HTTPS.
created_atdatetime
The date and time when the project was created.
updated_atdatetime
The date and time when the project was last updated.
signing_keystring

The project's signing key. Only returned on create and signing-key rotation responses; it cannot be retrieved through the API afterward.

Errors

401
Unauthorized Error
404
Not Found Error
500
Internal Server Error