> ## Documentation Index
> Fetch the complete documentation index at: https://docs.omni.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotate webhook secret

> <Note>
  This endpoint requires Modeler permissions or higher.
</Note>

Rotate the pull request webhook signing secret for a shared model's Git configuration, and return the updated Git configuration with the new secret. The previous secret stops validating webhook deliveries immediately.

If the git repository is shared across multiple models, the secret belongs to whichever model owns the shared configuration. Rotating the secret for any of the sharing models rotates the one shared secret for all of them.

This is the only endpoint that returns the new secret value. Call `GET /v1/models/{modelId}/git?include=webhookSecret` to retrieve it after the rotation, if needed.




## OpenAPI

````yaml /api/openapi.yaml post /v1/models/{modelId}/git/rotate-webhook-secret
openapi: 3.1.0
info:
  title: Omni API
  description: >
    The Omni REST API provides programmatic access to your Omni instance for
    managing users, documents, queries, schedules, and more.  
  version: 1.0.0
  contact:
    name: Omni Support
    url: https://docs.omni.co
servers:
  - url: https://{instance}.omniapp.co/api
    description: Production
    variables:
      instance:
        default: blobsrus
        description: Your production Omni instance subdomain
  - url: https://{instance}.playground.exploreomni.dev/api
    description: Playground
    variables:
      instance:
        default: blobsrus
        description: Your playground Omni instance subdomain
security:
  - bearerAuth: []
  - orgApiKey: []
tags:
  - name: Who Am I
    description: Inspect your own user permissions
  - name: AI
    description: AI-powered query generation
  - name: AI Credit Controls
    description: Manage organization-level AI credit usage
  - name: AI Credit Usage
    description: Monitor AI credit usage
  - name: AI Evals
    description: >-
      Manage prompt sets and runs used to score AI quality against curated
      prompt suites.
  - name: AI Model Suggestions
    description: Manage AI-generated suggestions for shared models
  - name: AI Routines
    description: >-
      Manage Routines, which are scheduled, recurring AI-powered tasks that run
      automatically on your data
  - name: Apps
    description: Draft and publish app documents.
  - name: Documents v2
    description: >
      A draft-based workflow for creating and editing documents: create a
      document, patch a draft, then publish.
  - name: Documents
    description: Create, retrieve, and manage documents
  - name: API Tokens
    description: >-
      Manage API tokens (Organization keys, Personal Access Tokens, MCP OAuth
      grants)
  - name: Connections
    description: Manage database connections
  - name: Connection environments
    description: Manage connection environments database connections
  - name: Content
    description: Unified content retrieval (documents and folders)
  - name: Content migration
    description: Export and import dashboards
  - name: Content validator
    description: Validate content against models and perform find/replace operations
  - name: Dashboard downloads
    description: Download dashboards and tiles as PDF, PNG, XLSX, CSV, or JSON files
  - name: Dashboard filters and controls
    description: Read and update dashboard filter and control default values
  - name: dbt
    description: Manage dbt configuration for connections
  - name: Document favorites
    description: Favorite and unfavorite documents
  - name: Document labels
    description: Apply and manage labels on documents
  - name: Document permissions
    description: Manage document-level access
  - name: Labels
    description: |
      Manage labels in the organization
  - name: Folders
    description: Create and organize content folders
  - name: Folder labels
    description: Apply and manage labels on folders
  - name: Folder permissions
    description: Manage folder-level access
  - name: Jobs
    description: Check status of asynchronous jobs
  - name: Models
    description: Create and manage data models
  - name: Model branches
    description: Manage model branches and merge changes
  - name: Model git configuration
    description: Manage git configuration for shared models
  - name: Queries
    description: Execute workbook queries
  - name: Schedules
    description: Create and manage scheduled tasks
  - name: Schedule recipients
    description: Manage schedule recipients
  - name: Schema refresh schedules
    description: Manage automated schema refresh schedules for connections
  - name: Topics
    description: Retrieve topic information from models
  - name: Uploads
    description: Manage file uploads
  - name: Users
    description: Manage users
  - name: User attributes
    description: Manage user attribute definitions
  - name: User groups
    description: Manage user groups
  - name: User model roles
    description: Manage model and connection role assignments for users
  - name: User group model roles
    description: Manage model and connection role assignments for user groups
  - name: Uploads
    description: Manage CSV and spreadsheet uploads
paths:
  /v1/models/{modelId}/git/rotate-webhook-secret:
    post:
      tags:
        - Model Git configuration
      summary: Rotate webhook secret
      description: >
        <Note>
          This endpoint requires Modeler permissions or higher.
        </Note>


        Rotate the pull request webhook signing secret for a shared model's Git
        configuration, and return the updated Git configuration with the new
        secret. The previous secret stops validating webhook deliveries
        immediately.


        If the git repository is shared across multiple models, the secret
        belongs to whichever model owns the shared configuration. Rotating the
        secret for any of the sharing models rotates the one shared secret for
        all of them.


        This is the only endpoint that returns the new secret value. Call `GET
        /v1/models/{modelId}/git?include=webhookSecret` to retrieve it after the
        rotation, if needed.
      operationId: modelsGitRotateWebhookSecret
      parameters:
        - name: modelId
          in: path
          required: true
          schema:
            type: string
            format: uuid
          description: The unique identifier of the shared model.
      responses:
        '200':
          description: >-
            Webhook secret rotated successfully. The response includes the new
            webhook secret.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/ModelsGitGetResponse'
                  - type: object
                    properties:
                      webhookSecret:
                        type: string
                        description: >-
                          The new webhook secret. Returned only here — read it
                          back later with GET /git?include=webhookSecret.
                    required:
                      - webhookSecret
              example:
                authMethod: ssh
                baseBranch: main
                branchPerPullRequest: false
                gitFollower: false
                gitServiceProvider: github
                modelPath: omni/blobs_r_us
                publicKey: ssh-ed25519 AAAA...
                requirePullRequest: users-only
                cloneUrl: git@github.com:org/repo.git
                webUrl: https://github.com/org/repo
                webhookUrl: https://app.omni.co/api/webhooks/model/...
                webhookSecret: whsec_new_secret_value
        '401':
          description: Missing or invalid authentication
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError401'
        '403':
          description: |
            Forbidden

            Possible error messages:

            - `Forbidden: Requires MANAGE_MODEL permission`
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError403'
        '404':
          description: |
            Not Found

            Possible error messages:

            - `Not Found: Model does not exist`
            - `Not Found: Git configuration not found for this model`
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError404'
        '422':
          description: |
            Unprocessable Entity

            Possible error messages:

            - `Model is not a shared model`
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          $ref: '#/components/responses/TooManyRequests'
      security:
        - bearerAuth: []
components:
  schemas:
    ModelsGitGetResponse:
      type: object
      properties:
        authMethod:
          type: string
          enum:
            - ssh
            - https_token
            - github_app
          description: >-
            Authentication method. "ssh" for deploy key, "https_token" for
            deploy token/PAT, "github_app" for a GitHub App installation.
          example: ssh
        baseBranch:
          type: string
          description: The target branch for Omni pull requests
          example: main
        branchPerPullRequest:
          type: boolean
          description: |
            If `true`, all pull requests will create a branch in Omni
          example: false
        cloneUrl:
          type: string
          description: Clone URL of the git repository (SSH or HTTPS)
          example: git@github.com:org/repo.git
        commitSigningCommitterEmail:
          type: string
          nullable: true
          description: >
            Committer email written into signed commits (`github_app` auth).
            Null when signing is not configured.
          example: omni-bot@example.com
        commitSigningCommitterName:
          type: string
          nullable: true
          description: >
            Committer display name written into signed commits (`github_app`
            auth). Null when signing is not configured.
          example: Omni Bot
        commitSigningPublicKey:
          type: string
          nullable: true
          description: >
            SSHSIG signing public key to register on the committer's GitHub user
            (`github_app` auth). Null for other auth methods.
          example: ssh-ed25519 AAAA...
        gitFollower:
          type: boolean
          description: >
            If `true`, the shared model is read-only and can only be updated by
            merging pull requests to the base branch
          example: false
        gitServiceProvider:
          type: string
          description: The git provider type
          example: github
        githubAppInstallationId:
          type: string
          nullable: true
          description: |
            GitHub App installation ID. Null unless `github_app` auth.
          example: '12345678'
        modelPath:
          type: string
          nullable: true
          description: Path to model files in the repository
          example: omni/my_model
        publicKey:
          type: string
          nullable: true
          description: >-
            SSH public key for repository access (deploy key). Null for HTTPS
            token auth.
          example: ssh-ed25519 AAAA...
        requirePullRequest:
          type: string
          enum:
            - always
            - users-only
            - never
          description: >
            When pull requests are required: `always` for all changes,
            `users-only` for user-initiated changes only, `never` for direct
            commits.
          example: users-only
        sshUrl:
          type: string
          deprecated: true
          description: |
            Deprecated — use `cloneUrl`. Clone URL of the git repository.
        webUrl:
          type: string
          nullable: true
          description: Custom web URL for the git repository, or null if not set
          example: https://github.com/org/repo
        webhookSecret:
          type: string
          description: >
            Webhook secret for signature verification. Only included if
            requested via `?include=webhookSecret`
        webhookUrl:
          type: string
          description: Webhook URL to configure in your git provider
          example: https://app.omni.co/api/webhooks/model/...
      required:
        - authMethod
        - baseBranch
        - branchPerPullRequest
        - cloneUrl
        - commitSigningCommitterEmail
        - commitSigningCommitterName
        - commitSigningPublicKey
        - gitFollower
        - gitServiceProvider
        - githubAppInstallationId
        - modelPath
        - publicKey
        - requirePullRequest
        - sshUrl
        - webUrl
        - webhookUrl
    ApiError401:
      type: object
      properties:
        detail:
          type: string
          description: Human-readable error message describing what went wrong.
          example: 'Unauthorized: Missing or invalid API key'
        status:
          type: integer
          description: HTTP status code of the error.
          example: 401
      required:
        - detail
        - status
    ApiError403:
      type: object
      properties:
        detail:
          type: string
          description: Human-readable error message describing what went wrong.
        status:
          type: integer
          description: HTTP status code of the error.
          example: 403
      required:
        - detail
        - status
    ApiError404:
      type: object
      properties:
        detail:
          type: string
          description: Human-readable error message describing what went wrong.
        status:
          type: integer
          description: HTTP status code of the error.
          example: 404
      required:
        - detail
        - status
    Error:
      type: object
      properties:
        error:
          type: string
          description: HTTP response code for the error
          example: <response_code>
        message:
          type: string
          description: Detailed error description
          example: <error_reason>
  responses:
    TooManyRequests:
      description: Too Many Requests - Rate limit exceeded (60 requests/minute)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Can be either an [Organization API
        Key](/api/authentication#organization-api-keys) or [Personal Access
        Token (PAT)](/api/authentication#token-types).


        Include in the `Authorization` header as: `Bearer YOUR_TOKEN`
    orgApiKey:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Requires an [Organization API
        Key](/api/authentication#organization-api-keys). Personal Access Tokens
        (PATs) are not supported for this endpoint.


        Include in the `Authorization` header as: `Bearer ORGANIZATION_API_KEY`

````