# 轮换回调密钥 (/zh/docs/conta-digital/endpoints/webhooks/post_callback_secret_rotate)

## POST /transactions/callback-secret/rotate

`POST https://api.hub.payzu.com.br/api/v1/transactions/callback-secret/rotate`

Scope: `WEBHOOK_WRITE`. Generates a new callback secret. The previous one stops working immediately.

### Responses

**200** New secret. It only appears in this response.

| Field | Type | Required | Details |
| --- | --- | --- | --- |
| `secret` | string | yes | Account callback secret, prefixed with `cbsec_`. It signs the webhooks sent to the `callbackUrl` and only appears in this response. |

**401** Missing, invalid or expired credential.

| Field | Type | Required | Details |
| --- | --- | --- | --- |
| `message` | string | yes | Description in Portuguese, ready to display. It may change at any time. |
| `code` | string | yes | Stable error code. Your system decides what to do based on it. |
| `details` | object | no | Structured error context, when available. |

**403** Not allowed: scope, IP or disabled operation.

| Field | Type | Required | Details |
| --- | --- | --- | --- |
| `message` | string | yes | Description in Portuguese, ready to display. It may change at any time. |
| `code` | string | yes | Stable error code. Your system decides what to do based on it. |
| `details` | object | no | Structured error context, when available. |