> Fetch clean Markdown by appending `.md` to any page URL under https://signalwire.com/docs or requesting it with the HTTP header `Accept: text/markdown`. The root index at https://signalwire.com/docs/llms.txt lists the available documentation indexes. # rotate_signing_key > Issue a new signing key for a project, invalidating the old one. ### projects.rotate\_signing\_key Issue a new signing key for a project. The response is the only place the new key is returned. ### Schema ```yaml openapi: 3.1.0 info: title: API version: 1.0.0 paths: /api/projects/{id}/signing-key/rotate: post: operationId: subpackageProjects_rotate_signing_key summary: Rotate a project's signing key description: >- Rotates the project's signing key and returns the project with the new `signing_key`. The previous key may take about 1–2 minutes to stop working. As with create, the `signing_key` is only returned on this response and cannot be retrieved afterward. Use it when the project's webhook-signing credential has been exposed or is due for rotation; this is separate from creating or revoking REST API tokens. #### Permissions With a project API token, the token must have the following scope(s) enabled to make a successful request: _Management_. With a [Personal access token](/docs/apis/authorization#personal-access-tokens) there are no scopes. The token holder must be an owner or admin of the space, and the request reaches only the projects the holder is enabled for, plus their subprojects. [Learn more about API scopes](/docs/platform/your-signalwire-api-space). tags: - subpackage_projects parameters: - name: id in: path description: The unique identifier of the project or subproject. required: true schema: $ref: '#/components/schemas/uuid' responses: '200': description: The request has succeeded. content: application/json: schema: $ref: '#/components/schemas/Projects.ProjectWithSigningKey' '401': description: Access is unauthorized. content: application/json: schema: $ref: '#/components/schemas/Types.StatusCodes.StatusCode401' '404': description: The server cannot find the requested resource. content: application/json: schema: $ref: '#/components/schemas/Types.StatusCodes.StatusCode404' '500': description: An internal server error occurred. content: application/json: schema: $ref: '#/components/schemas/Types.StatusCodes.StatusCode500' tags: - name: subpackage_projects servers: - url: https://%7BYour_Space_Name%7D.signalwire.com description: SignalWire API components: schemas: uuid: type: string format: uuid description: Universal Unique Identifier. title: uuid Projects.ProjectWithSigningKey: type: object properties: id: $ref: '#/components/schemas/uuid' description: The unique identifier of the project. name: type: string description: The name of the project. parent_project_id: oneOf: - $ref: '#/components/schemas/uuid' - type: 'null' description: >- The unique identifier of the root project. `null` when this project is itself a root project. subproject: type: boolean description: '`true` when this project is a subproject.' region_preference: type: string description: >- The effective region preference for the project. Returned in all responses; it is not currently settable through this API. protect_recordings: type: boolean description: >- When enabled, recordings created within the project require authentication to access. protect_message_media: type: boolean description: >- When enabled, message media created within the project requires authentication to access. protect_fax_media: type: boolean description: >- When enabled, fax media created within the project requires authentication to access. force_https_requests: type: boolean description: >- When enabled, requests made to the project's webhooks and callbacks must use HTTPS. created_at: type: string format: date-time description: The date and time when the project was created. updated_at: type: string format: date-time description: The date and time when the project was last updated. signing_key: type: string description: >- The project's signing key. Only returned on create and signing-key rotation responses; it cannot be retrieved through the API afterward. required: - id - name - parent_project_id - subproject - region_preference - protect_recordings - protect_message_media - protect_fax_media - force_https_requests - created_at - updated_at - signing_key description: >- A project, including its `signing_key`. The `signing_key` is only returned when creating a subproject or rotating a project's signing key. It is not retrievable afterward, so capture it from the response. title: Projects.ProjectWithSigningKey TypesStatusCodesStatusCode401Error: type: string enum: - Unauthorized title: TypesStatusCodesStatusCode401Error Types.StatusCodes.StatusCode401: type: object properties: error: $ref: '#/components/schemas/TypesStatusCodesStatusCode401Error' required: - error description: Access is unauthorized. title: Types.StatusCodes.StatusCode401 TypesStatusCodesStatusCode404Error: type: string enum: - Not Found title: TypesStatusCodesStatusCode404Error Types.StatusCodes.StatusCode404: type: object properties: error: $ref: '#/components/schemas/TypesStatusCodesStatusCode404Error' required: - error description: The server cannot find the requested resource. title: Types.StatusCodes.StatusCode404 TypesStatusCodesStatusCode500Error: type: string enum: - Internal Server Error title: TypesStatusCodesStatusCode500Error Types.StatusCodes.StatusCode500: type: object properties: error: $ref: '#/components/schemas/TypesStatusCodesStatusCode500Error' required: - error description: An internal server error occurred. title: Types.StatusCodes.StatusCode500 ``` ## Parameters **`id`** `str` — required ID of the project whose key to rotate. --- **`request_options`** `RequestOptions | None` — default: None Per-call timeout and retry overrides. See [`RequestOptions`](/docs/server-sdks/reference/python/rest/request-options). --- ## Returns `ProjectWithSigningKey` — the project with its new signing key. ## Response Example ### Response (200) ```json { "id": "8f14e45f-ceea-467d-9c2b-7a1d3a9b2c34", "name": "Acme Staging", "parent_project_id": "b3877739-5c7e-4d4f-9d1a-2f0c8c2f1a11", "subproject": true, "region_preference": "us-west", "protect_recordings": false, "protect_message_media": false, "protect_fax_media": false, "force_https_requests": true, "created_at": "2024-05-06T12:20:00Z", "updated_at": "2024-05-06T12:20:00Z", "signing_key": "PSK_4d8c2b1a9f3e7c6d5b4a3e2f1d0c9b8a" } ``` ## Example ```python {9} from signalwire.rest import RestClient client = RestClient( project="your-project-id", token="your-api-token", host="your-space.signalwire.com", ) project = client.projects.rotate_signing_key("project-id") print(project["id"]) ``` > Issue a new signing key for a project, invalidating the old one.