Rotate this page's webhook signing secret (old secret invalidated immediately)
X-Api-Key<token>
Business API key, e.g. vuz_ab12cdef... Created via Settings → Integrations → API Keys. Unlike partner keys, a public API key's STRING does not encode its environment — isolation instead comes from a completely separate sandbox database: a key minted on the Sandbox server (above) only ever reads/writes sandbox data and can never see or affect production, regardless of what the key looks like.
In: header
Path Parameters
pageId*string
Response Body
application/json
curl -X POST "https://example.com/payment-pages/string/rotate-webhook-secret"{ "webhookSecret": "whsec_3f9a1c2e4b5d6f7081920a3b4c5d6e7f"}
