> ## Documentation Index
> Fetch the complete documentation index at: https://docs.olira.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate action destination secret

> Generates a new signing secret for a destination.

<CodeGroup>
  ```python Python theme={null}
  olira.rotate_action_destination_secret(destination_id: str) -> ActionDestination
  ```

  ```csharp C# theme={null}
  OliraModule.RotateActionDestinationSecret(string destinationId)  // -> ActionDestination
  ```
</CodeGroup>

**Requires scope:** `sdk:actions`

The old secret stays valid for 24h (dual-signing — the Olira-Signature header carries both during the overlap) so an in-progress rotation on the receiving end never drops a delivery.

## Parameters

<ParamField body="destination_id" type="str" required>
  The destination's id.
</ParamField>

## Returns

`ActionDestination` — Updated destination, including the new signing\_secret (plaintext, shown once).

<ResponseField name="id" type="str">
  Destination id.
</ResponseField>

<ResponseField name="signing_secret_last4" type="str | None">
  Last 4 characters of the new secret.
</ResponseField>

<ResponseField name="rotated_at" type="str | None">
  When the rotation happened.
</ResponseField>

<ResponseField name="signing_secret" type="str | None">
  New plaintext signing secret, shown once.
</ResponseField>

## Raises

| Exception         | When                                                                                                                  |
| ----------------- | --------------------------------------------------------------------------------------------------------------------- |
| `AuthError`       | HTTP 401 or 403 — invalid API key or insufficient OAuth scope for this endpoint.                                      |
| `ValidationError` | HTTP 400, 404, or 422 — malformed JSON or validation failure (message includes response excerpt).                     |
| `ServerError`     | HTTP 409 (e.g. conflicting external identifier) or repeated 5xx after retries; includes status\_code when applicable. |
| `RateLimitError`  | HTTP 429 — rate limited; check retry\_after (seconds).                                                                |
| `NetworkError`    | Connection timeout, DNS failure, or read error after retries.                                                         |

<RequestExample>
  ```python Python theme={null}
  import olira

  olira.init(api_key="YOUR_API_KEY")
  destination = olira.rotate_action_destination_secret(destination_id="68582e4a0a0b3c1234567890")
  print(destination.signing_secret)  # new secret, shown once
  ```

  ```csharp C# theme={null}
  using Olira;

  OliraModule.Init(apiKey: "YOUR_API_KEY");
  var destination = OliraModule.RotateActionDestinationSecret(destinationId: "68582e4a0a0b3c1234567890");
  Console.WriteLine(destination.SigningSecret); // new secret, shown once
  ```

  ```http HTTP theme={null}
  POST /v1/actions/destinations/68582e4a0a0b3c1234567890/rotate-secret
  Authorization: Bearer YOUR_API_KEY
  ```
</RequestExample>

<ResponseExample>
  ```python 200 theme={null}
  ActionDestination(
      id="68582e4a0a0b3c1234567890",
      signing_secret_last4="jUaE",
      rotated_at="2026-08-13T11:12:00Z",
      signing_secret="whsec_XCoIKJoGMRLnQJf8DoZT8dvXYfM1A8G7B0tqH_OjUaE",
  )
  ```

  ```json 401 theme={null}
  {
    "error": true,
    "status_code": 401,
    "error_type": "authentication_error",
    "message": "Could not validate credentials",
    "details": [
      {
        "type": "authentication_error",
        "message": "Could not validate credentials"
      }
    ],
    "timestamp": "2026-05-06T12:00:00+00:00"
  }
  ```

  ```json 403 theme={null}
  {
    "error": true,
    "status_code": 403,
    "error_type": "authorization_error",
    "message": "Insufficient OAuth scope for this endpoint",
    "details": [
      {
        "type": "authorization_error",
        "message": "Insufficient OAuth scope for this endpoint"
      }
    ],
    "timestamp": "2026-05-06T12:00:00+00:00"
  }
  ```

  ```json 404 theme={null}
  {
    "error": true,
    "status_code": 404,
    "error_type": "not_found_error",
    "message": "Destination not found",
    "details": [
      {
        "type": "not_found_error",
        "message": "Destination not found"
      }
    ],
    "timestamp": "2026-05-06T12:00:00+00:00"
  }
  ```

  ```json 422 theme={null}
  {
    "error": true,
    "status_code": 422,
    "error_type": "validation_error",
    "message": "Request validation failed (1 error)",
    "details": [
      {
        "type": "value_error",
        "message": "Request validation failed"
      }
    ],
    "timestamp": "2026-05-06T12:00:00+00:00"
  }
  ```

  ```json 429 theme={null}
  {
    "error": true,
    "status_code": 429,
    "error_type": "server_error",
    "message": "Rate limit exceeded",
    "details": [
      {
        "type": "rate_limit",
        "message": "Too many requests; retry after backoff"
      }
    ],
    "timestamp": "2026-05-06T12:00:00+00:00"
  }
  ```

  ```json 500 theme={null}
  {
    "error": true,
    "status_code": 500,
    "error_type": "internal_server_error",
    "message": "An internal server error occurred",
    "details": [
      {
        "type": "internal_server_error",
        "message": "An unexpected error occurred while processing your request"
      }
    ],
    "timestamp": "2026-05-06T12:00:00+00:00"
  }
  ```
</ResponseExample>
