# DELETE /v1/webhooks/{id}/secrets/{secretId}

Delete a signing secret

Deliveries are no longer signed with it from the next one on. The last live secret of a webhook cannot be deleted, so its deliveries always carry a signature.

Takes a server key (`sk_…`, or `sk_test_…` on a test server) as a bearer token. TypeScript: `sendora.webhooks.deleteSecret(webhookId, secretId)`. Python: `sendora.webhooks.delete_secret(webhook_id, secret_id)`.

## Parameters

- `id` (path, required, string (uuid)): The webhook id.
- `secretId` (path, required, string (uuid)): The secret id.

## Responses

### 204 Removed. The body is empty.

## Errors

Every error answers `error`, the code, and `message`, a sentence for a person. A code that adds fields is shown in full below the table.

| Code | Status | Meaning |
| --- | --- | --- |
| `unauthorized` | 401 | The key is missing, malformed or revoked. |
| `wrong_token_kind` | 403 | The key is of the other kind: a server key (sk_) where an account key (ak_) is needed, or the reverse. The message names the kind the operation takes. |
| `not_found` | 404 | No such webhook or secret of this server. |
| `last_secret` | 409 | The only live secret of a webhook cannot be deleted; create another first. |
