Skip to main content
POST
Rotate the signing secret

Authorizations

X-API-Key
string
header
required

API key (wg_live_…) created in the dashboard (Account → API Keys). Shown once at creation; only a hash is stored server-side.

Response

New secret.

secret
string
required
Example:

"whsec_kJ8s..."

previousSecretValidForMs
integer
required

How long the old secret still verifies (24 h).