> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lapyme.com.ar/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotar secreto de webhook

> Reemplaza el secreto inmediatamente y devuelve el nuevo signing_secret una sola vez.



## OpenAPI

````yaml /api-reference/openapi.json post /api/v1/webhook-endpoints/{webhook_endpoint_id}/rotate-secret
openapi: 3.1.0
info:
  title: La Pyme API
  description: >-
    Resources and workflows for purchases, sales, inventory, contacts, products,
    reports, and settings.
  version: 1.0.0
  contact:
    name: La Pyme Support
    email: hola@lapyme.com.ar
  license:
    name: Proprietary
    url: https://lapyme.com.ar/terminos
servers:
  - url: https://api.lapyme.com.ar
    description: Servidor de producción
security:
  - bearerAuth: []
tags:
  - name: API
    description: Public API operations for La Pyme integrations.
paths:
  /api/v1/webhook-endpoints/{webhook_endpoint_id}/rotate-secret:
    post:
      tags:
        - API
      summary: Rotar secreto de webhook
      description: >-
        Reemplaza el secreto inmediatamente y devuelve el nuevo signing_secret
        una sola vez.
      operationId: rotateSecretApiWebhookEndpoint
      parameters:
        - name: webhook_endpoint_id
          in: path
          description: ID del endpoint de webhook
          required: true
          schema:
            type: string
            format: uuid
        - name: Idempotency-Key
          in: header
          description: Clave estable para deduplicar reintentos de la misma operación.
          required: true
          schema:
            type: string
      responses:
        '200':
          description: Operación de webhook aceptada
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiWebhookEndpointSecretResponse'
        '400':
          description: Solicitud inválida
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorEnvelope'
              examples:
                default:
                  summary: INVALID_REQUEST
                  value:
                    request_id: req_error_1
                    error:
                      type: invalid_request_error
                      code: INVALID_REQUEST
                      message: Solicitud inválida
                      retryable: false
                      details: []
        '401':
          description: API key faltante o inválida
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorEnvelope'
              examples:
                default:
                  summary: INVALID_REQUEST
                  value:
                    request_id: req_error_1
                    error:
                      type: invalid_request_error
                      code: INVALID_REQUEST
                      message: API key faltante o inválida
                      retryable: false
                      details: []
        '403':
          description: Scopes insuficientes
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorEnvelope'
              examples:
                default:
                  summary: INVALID_REQUEST
                  value:
                    request_id: req_error_1
                    error:
                      type: invalid_request_error
                      code: INVALID_REQUEST
                      message: Scopes insuficientes
                      retryable: false
                      details: []
        '404':
          description: Endpoint no encontrado
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorEnvelope'
              examples:
                default:
                  summary: INVALID_REQUEST
                  value:
                    request_id: req_error_1
                    error:
                      type: invalid_request_error
                      code: INVALID_REQUEST
                      message: Endpoint no encontrado
                      retryable: false
                      details: []
        '409':
          description: Conflicto de estado o idempotencia
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorEnvelope'
              examples:
                default:
                  summary: INVALID_REQUEST
                  value:
                    request_id: req_error_1
                    error:
                      type: invalid_request_error
                      code: INVALID_REQUEST
                      message: Conflicto de estado o idempotencia
                      retryable: false
                      details: []
        '429':
          description: Límite de solicitudes excedido para la organización
          headers:
            Retry-After:
              description: Segundos a esperar antes de volver a intentar la solicitud.
              schema:
                type: string
                example: '30'
            X-RateLimit-Limit:
              description: Límite de la ventana activa.
              schema:
                type: string
                example: '5000'
            X-RateLimit-Remaining:
              description: Solicitudes restantes en la ventana activa.
              schema:
                type: string
                example: '0'
            X-RateLimit-Reset:
              description: Segundos restantes hasta el reset de la ventana activa.
              schema:
                type: string
                example: '30'
            RateLimit-Limit:
              description: Límite de la ventana activa en formato estándar.
              schema:
                type: string
                example: '5000'
            RateLimit-Remaining:
              description: Solicitudes restantes en la ventana activa en formato estándar.
              schema:
                type: string
                example: '0'
            RateLimit-Reset:
              description: >-
                Segundos hasta el reset de la ventana activa en formato
                estándar.
              schema:
                type: string
                example: '30'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorEnvelope'
              examples:
                default:
                  summary: RATE_LIMITED
                  value:
                    request_id: req_rate_limit_1
                    error:
                      type: rate_limit_error
                      code: RATE_LIMITED
                      message: >-
                        The organization request limit was reached. Try again
                        later.
                      retryable: true
                      details: []
        '500':
          description: Error interno del servidor
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorEnvelope'
              examples:
                default:
                  summary: INVALID_REQUEST
                  value:
                    request_id: req_error_1
                    error:
                      type: invalid_request_error
                      code: INVALID_REQUEST
                      message: Error interno del servidor
                      retryable: false
                      details: []
      x-codeSamples:
        - lang: typescript
          label: La Pyme SDK
          source: |
            import { Lapyme } from "lapyme";

            const lapyme = new Lapyme({
              bearerAuth: process.env["LAPYME_API_KEY"] ?? "",
            });

            const endpoint = await lapyme.webhookEndpoints.rotateSecret({
              webhookEndpointId,
              idempotencyKey: crypto.randomUUID(),
            });
components:
  schemas:
    ApiWebhookEndpointSecretResponse:
      type: object
      properties:
        request_id:
          type: string
        data:
          type: object
          properties:
            object:
              type: string
              const: webhook_endpoint
            id:
              type: string
              format: uuid
            label:
              type: string
            url:
              type: string
              format: uri
            enabled_events:
              minItems: 1
              type: array
              items:
                $ref: '#/components/schemas/ApiSharedEnum4091526d90'
            api_version:
              $ref: '#/components/schemas/ApiSharedEnum5f610d8b6a'
            status:
              $ref: '#/components/schemas/ApiSharedEnum1c9cda998e'
            owner_type:
              $ref: '#/components/schemas/ApiSharedEnum4b017f6476'
            failure_count:
              type: integer
              minimum: 0
            last_success_at:
              anyOf:
                - type: string
                  format: date-time
                - type: 'null'
            last_failure_at:
              anyOf:
                - type: string
                  format: date-time
                - type: 'null'
            disabled_at:
              anyOf:
                - type: string
                  format: date-time
                - type: 'null'
            created_at:
              type: string
              format: date-time
            updated_at:
              type: string
              format: date-time
            signing_secret:
              type: string
          required:
            - object
            - id
            - label
            - url
            - enabled_events
            - api_version
            - status
            - owner_type
            - failure_count
            - last_success_at
            - last_failure_at
            - disabled_at
            - created_at
            - updated_at
            - signing_secret
          additionalProperties: false
      required:
        - request_id
        - data
      additionalProperties: false
    ApiErrorEnvelope:
      type: object
      properties:
        request_id:
          type: string
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - api_error
                - authentication_error
                - authorization_error
                - business_error
                - external_dependency_error
                - idempotency_error
                - invalid_request_error
                - rate_limit_error
            code:
              type: string
            message:
              type: string
            retryable:
              type: boolean
            details:
              type: array
              items:
                $ref: '#/components/schemas/ApiSharedObjectc671832641'
          required:
            - type
            - code
            - message
            - retryable
            - details
          additionalProperties: false
      required:
        - request_id
        - error
      additionalProperties: false
    ApiSharedEnum4091526d90:
      type: string
      enum:
        - sale.created
        - sale.updated
        - order.created
        - order.updated
        - order.completed
        - order.cancelled
        - order.partially_fulfilled
        - order.fulfilled
        - fulfillment.created
        - webhook_endpoint.disabled
    ApiSharedEnum5f610d8b6a:
      type: string
      enum:
        - '2026-06-29'
    ApiSharedEnum1c9cda998e:
      type: string
      enum:
        - active
        - paused
        - disabled
    ApiSharedEnum4b017f6476:
      type: string
      enum:
        - organization
        - connected_app
    ApiSharedObjectc671832641:
      type: object
      properties:
        code:
          type: string
        message:
          type: string
        field:
          type: string
      required:
        - code
        - message
      additionalProperties: false
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: Incluí tu API key en el header Authorization con el prefijo Bearer.

````