> Fetch clean Markdown by appending `.md` to any page URL under https://signalwire.com/docs or requesting it with the HTTP header `Accept: text/markdown`. The root index at https://signalwire.com/docs/llms.txt lists the available documentation indexes. # Rotate a project's signing key POST https://%7BYour_Space_Name%7D.signalwire.com/api/projects/{id}/signing-key/rotate Rotates the project's signing key and returns the project with the new `signing_key`. The previous key may take about 1–2 minutes to stop working. As with create, the `signing_key` is only returned on this response and cannot be retrieved afterward. Use it when the project's webhook-signing credential has been exposed or is due for rotation; this is separate from creating or revoking REST API tokens. #### Permissions With a project API token, the token must have the following scope(s) enabled to make a successful request: _Management_. With a [Personal access token](/docs/apis/authorization#personal-access-tokens) there are no scopes. The token holder must be an owner or admin of the space, and the request reaches only the projects the holder is enabled for, plus their subprojects. [Learn more about API scopes](/docs/platform/your-signalwire-api-space). Reference: https://signalwire.com/docs/apis/rest/projects/rotate-signing-key ## Authentication - `Authorization` header (basic auth, required) — SignalWire Basic Authentication using Project ID and API Token. The client sends HTTP requests with the Authorization header containing the word Basic followed by a space and a base64-encoded string of project_id:token. The project ID will be used as the username and the API token as the password. Example: ``` Authorization: Basic base64(project_id:token) ``` - `Authorization` header (basic auth, required) — Personal access token authentication for space-wide administration. Send HTTP Basic auth with an empty username and the Personal access token as the password. A Personal access token carries your own authority rather than a project's: it is created from your user menu in the Dashboard, is prefixed `pat_`, and has no scopes. The holder must be an owner or admin of the space named by the subdomain, and the token acts only on that space. Example: ``` Authorization: Basic base64(:pat_...) ``` ## Request ### Path parameters - `id` (string, required) — The unique identifier of the project or subproject. ## Response ### 200 The request has succeeded. - `id` (string, required) — The unique identifier of the project. - `name` (string, required) — The name of the project. - `parent_project_id` (string, required, nullable) — The unique identifier of the root project. `null` when this project is itself a root project. - `subproject` (boolean, required) — `true` when this project is a subproject. - `region_preference` (string, required) — The effective region preference for the project. Returned in all responses; it is not currently settable through this API. - `protect_recordings` (boolean, required) — When enabled, recordings created within the project require authentication to access. - `protect_message_media` (boolean, required) — When enabled, message media created within the project requires authentication to access. - `protect_fax_media` (boolean, required) — When enabled, fax media created within the project requires authentication to access. - `force_https_requests` (boolean, required) — When enabled, requests made to the project's webhooks and callbacks must use HTTPS. - `created_at` (datetime, required) — The date and time when the project was created. - `updated_at` (datetime, required) — The date and time when the project was last updated. - `signing_key` (string, required) — The project's signing key. Only returned on create and signing-key rotation responses; it cannot be retrieved through the API afterward. ## Errors ### 401 Unauthorized Error Access is unauthorized. - `error` (enum, required) - Allowed values: `Unauthorized` ### 404 Not Found Error The server cannot find the requested resource. - `error` (enum, required) - Allowed values: `Not Found` ### 500 Internal Server Error An internal server error occurred. - `error` (enum, required) - Allowed values: `Internal Server Error` ## Examples **Response** ```json { "id": "8f14e45f-ceea-467d-9c2b-7a1d3a9b2c34", "name": "Acme Staging", "parent_project_id": "b3877739-5c7e-4d4f-9d1a-2f0c8c2f1a11", "subproject": true, "region_preference": "us-west", "protect_recordings": false, "protect_message_media": false, "protect_fax_media": false, "force_https_requests": true, "created_at": "2024-05-06T12:20:00Z", "updated_at": "2024-05-06T12:20:00Z", "signing_key": "PSK_4d8c2b1a9f3e7c6d5b4a3e2f1d0c9b8a" } ``` **SDK Code** ```python import requests url = "https://{your_space_name}.signalwire.com/api/projects/id/signing-key/rotate" response = requests.post(url, auth=("", "")) print(response.json()) ``` ```javascript const url = 'https://{your_space_name}.signalwire.com/api/projects/id/signing-key/rotate'; const credentials = btoa(":"); const options = {method: 'POST', headers: {Authorization: `Basic ${credentials}`}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://{your_space_name}.signalwire.com/api/projects/id/signing-key/rotate" req, _ := http.NewRequest("POST", url, nil) req.SetBasicAuth("", "") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://{your_space_name}.signalwire.com/api/projects/id/signing-key/rotate") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request.basic_auth("", "") response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://{your_space_name}.signalwire.com/api/projects/id/signing-key/rotate") .basicAuth("", "") .asString(); ``` ```php request('POST', 'https://{your_space_name}.signalwire.com/api/projects/id/signing-key/rotate', [ 'headers' => [ ], 'auth' => ['', ''], ]); echo $response->getBody(); ``` ```csharp using RestSharp; using RestSharp.Authenticators; var client = new RestClient("https://{your_space_name}.signalwire.com/api/projects/id/signing-key/rotate"); client.Authenticator = new HttpBasicAuthenticator("", ""); var request = new RestRequest(Method.POST); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let credentials = Data(":".utf8).base64EncodedString() let headers = ["Authorization": "Basic \(credentials)"] let request = NSMutableURLRequest(url: NSURL(string: "https://{your_space_name}.signalwire.com/api/projects/id/signing-key/rotate")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```