Generates a new cryptographically random 32-byte hex signing secret, encrypts it at rest (AES-256-GCM), and immediately invalidates the previous secret. All subsequent deliveries will be signed with the new secret.Update your verification code immediately after rotation — any in-flight deliveries signed with the old secret will fail verification on your end.
{ "id": "a1b2c3d4-...", "signing_secret": "new_secret_hex_here...", "_note": "Save the new signing_secret — it will not be shown again. The old secret is now invalid."}
The new secret is shown once. If you lose it, you’ll need to rotate again.