Skip to main content
DialNexa webhook secrets are named signing keys your receiving systems use to verify webhook events. A workspace can hold several secrets, and one secret can sign several webhooks. Manage them in the Signing secrets section under Workspace Settings, Developer, Webhooks, where you can create a secret, reveal or copy its key, rename it, rotate it, and delete it.
You no longer need to share one secret across everything. Give each receiving system its own secret, or reuse one secret across several webhooks that land on the same system.

Webhook Secret Actions

Each secret is a named key with its own lifecycle.

Rotation And The 24 Hour Grace Window

Rotating generates a new key for the secret. You choose what happens to the previous key:
  • Keep previous secret valid for 24 hours (the default). During the window, every delivery carries two signatures: x-dialnexa-signature still verifies with the previous key, and x-dialnexa-signature-new verifies with the new key. A receiver that has not been updated yet keeps verifying without interruption. See signature verification during rotation for receiver code.
  • Expire previous secret now. The old key stops working immediately. Use this when a secret may have leaked.
While a grace window is running, the Rotate action is unavailable for that secret, and the dashboard shows when you can rotate again. Rotating again early would cut off receivers that are still verifying with the previous key. Expiring now remains available at all times.
When you rotate, add the new key to your receiver alongside the old one rather than replacing it, and accept a delivery when any configured key matches. Remove the old key after the window ends. A receiver written this way never rejects a valid event across a rotation.

Rotate A Webhook Secret Safely

1

Open Workspace Settings, Developer, Webhooks

Use the correct workspace and find the secret in the Signing secrets table.
2

Choose Rotate from the secret's menu

Keep the default 24 hour option unless the secret leaked.
3

Copy the new key

The table reveals it after the rotation.
4

Add the new key to your receiver

Keep the old key configured too, and verify against any configured key.
5

Send a test event

Place a test call and confirm the receiver accepts it.
6

Remove the old key after 24 hours

Once the window ends, deliveries are signed with the new key only.

Delete Rules

A secret cannot be deleted while any webhook uses it. The dashboard lists the webhooks that still sign with it; reassign each one to another secret from its edit dialog, then delete. Deleting a secret frees its name for reuse. For a migration with no deadline, create a new secret, move webhooks over to it one at a time, and delete the old secret when nothing uses it.

Webhook Secret Questions

No. API keys authenticate requests to DialNexa. Webhook secrets verify events sent from DialNexa.
The one attached to the webhook that received the event. Each webhook picks exactly one signing secret, shown in the Webhooks table.
Yes. One secret can sign any number of webhooks, which is convenient when several endpoints belong to the same receiving system.
No. After the grace window ends, or after an expire-now rotation, the previous key is gone. Copy keys into your receiver’s configuration when you create or rotate them.

External Webhooks

Create webhooks and pick their signing secret.

Signature Verification

Verify events in your receiver.

Webhook Failures

Debug delivery.

Agent Webhooks

Route each agent’s events.