Skip to content

Regenerate a webhook secret ​

POST/api/v2/workspaces/{slug}/webhooks/{pk}/regenerate/

Webhooks push Plane events to a URL you control.

Path Parameters ​

slug:requiredstring

The workspace slug. It appears in your Plane URLs — in https://app.plane.so/my-team/projects/, the slug is my-team.

pk:requiredstring (uuid)

The webhook id.

Response shaping ​

fields:optionalstring

Comma-separated list of fields to return. Unrequested keys are omitted, not returned as null. id always comes back. Pass all for every requestable field. An unknown name is a 400. See Sparse fields.

Requestable here: content_type, created_at, created_by_id, id, is_active, name, scopes, secret_key, url, version.

Scopes ​

webhooks:write

Errors ​

StatusCodeCause
400invalid_requestThe request body or a query parameter failed validation.
401unauthorizedMissing or invalid credentials.
402payment_requiredThe feature this endpoint belongs to isn't enabled on your plan or is switched off.
403forbiddenYour role or token scope doesn't allow this.
404not_foundNo such resource, or it's outside your tenant.
406not_acceptableThe Accept header asks for a representation the API can't produce.
409conflictA business rule blocks the write — see the notes above.
413payload_too_largeThe request body is over the size limit.
415unsupported_media_typeThe Content-Type isn't one this endpoint accepts.
429rate_limitedThrottled. Honor the Retry-After header before retrying.
Regenerate a webhook secret
bash
curl -X POST \
  "https://api.plane.so/api/v2/workspaces/my-team/webhooks/9c1f0b3d-6d2e-4c9a-8b41-2f7e5a0d6c88/regenerate/" \
  -H "X-Api-Key: $PLANE_API_KEY"
Response200
json
{
  "content_type": "application/json",
  "created_at": "2026-01-14T09:22:41.478363Z",
  "created_by_id": "16c61a3a-512a-48ac-b0be-b6b46fe6f430",
  "id": "b7e42a19-3c5d-4f80-9a26-8d1c0f4e7b53",
  "is_active": true,
  "name": "Example name",
  "scopes": ["example"],
  "secret_key": "example",
  "url": "https://example.com/spec",
  "version": "1.4.0"
}