InstaWebhook
Contents

Security

Rotate Endpoint Secrets

Updated July 5, 2026

Rotate Endpoint Secrets

Rotate endpoint tokens after suspected exposure, when a vendor integration changes ownership, or as part of scheduled credential hygiene.

Rotation changes the endpoint URL used by webhook senders. Existing stored events and delivery history remain intact, but future ingest requests must use the new token.

Rotation creates an audit log entry. Update the sender configuration before retiring the old token. If a grace period is enabled in your environment, keep it as short as practical and monitor for old-token traffic before ending it.

Related articles