> ## Documentation Index
> Fetch the complete documentation index at: https://docs.eclatira.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get the webhook signing secret

> Returns the tenant's webhook-signing secret, generating one on first
call if none exists yet. Use it to verify the X-Webhook-Signature header
(HMAC-SHA256 over the raw request body) on incoming call.completed /
batch.completed webhooks. Unlike an API key, this isn't shown once and
thrown away: it authenticates payloads we send to you, not requests you
send to us, so it's safe to fetch again any time you need it.

Verifying a webhook's signature confirms that a request claiming to be a
`call.completed` or `batch.completed` notification genuinely came from
us, and that its contents weren't altered in transit. Every webhook is
signed with HMAC-SHA256 over the raw bytes of the request body, using
your tenant's webhook secret, and the resulting signature is sent in the
`X-Webhook-Signature` header.

To verify a webhook, compute the same HMAC-SHA256 signature yourself
over the exact raw bytes your server received, not a version you've
parsed into an object and re-serialized, since re-serializing can
produce a different byte sequence than what was originally signed even
for a genuine, unmodified payload, which would make a valid signature
appear invalid. Compare your computed signature to the
`X-Webhook-Signature` header using a constant-time comparison function,
such as `hmac.compare_digest` in Python, rather than a plain equality
check: an ordinary comparison can leak timing information that makes a
correct signature easier to guess one byte at a time.



## OpenAPI

````yaml /openapi.json get /api/v1/webhooks/secret
openapi: 3.1.0
info:
  title: Eclatira API
  description: >-
    Programmatically create calls and batches, manage agents/tools/knowledge,
    and retrieve conversation analytics.
  contact:
    name: Eclatira Support
    email: contact@eclatira.com
  version: 1.0.0
servers:
  - url: https://app.eclatira.com
    description: API Server
security: []
tags:
  - name: developer-api
    description: >-
      The API-key-authenticated developer surface: calls, batches, and agents.
      Authenticate with `Authorization: Bearer ek_...`.
  - name: Calls
    description: Place outbound calls with an agent, check status, list history.
  - name: Batches
    description: 'Outbound call campaigns: create, list, inspect, cancel, retry.'
  - name: Agents
    description: Create and manage the agents that place and receive calls.
  - name: Tools
    description: Custom actions an agent can call mid-call, attached per-agent.
  - name: MCP Servers
    description: >-
      Connect an agent to an external MCP (Model Context Protocol) server so it
      can call that server's tools, with static or OAuth auth.
  - name: Knowledge Base
    description: Upload files and index them into an agent's knowledge base.
  - name: Realtime
    description: >-
      Mint a short-lived session token to open a live voice/video WebSocket
      connection: the only supported way for an API-key holder to authenticate
      into /ws/{user_id}.
  - name: Webhooks
    description: >-
      Register a durable callback URL to receive call.completed and
      batch.completed events for every matching workspace event, and fetch the
      tenant signing secret used to verify X-Webhook-Signature.
  - name: developer-api-keys
    description: >-
      Account-management routes (create/list/revoke API keys), authenticated via
      dashboard login, not an API key, since they mint the credentials the rest
      of the developer API uses.
paths:
  /api/v1/webhooks/secret:
    get:
      tags:
        - Webhooks
        - developer-api
      summary: Get the webhook signing secret
      description: |-
        Returns the tenant's webhook-signing secret, generating one on first
        call if none exists yet. Use it to verify the X-Webhook-Signature header
        (HMAC-SHA256 over the raw request body) on incoming call.completed /
        batch.completed webhooks. Unlike an API key, this isn't shown once and
        thrown away: it authenticates payloads we send to you, not requests you
        send to us, so it's safe to fetch again any time you need it.

        Verifying a webhook's signature confirms that a request claiming to be a
        `call.completed` or `batch.completed` notification genuinely came from
        us, and that its contents weren't altered in transit. Every webhook is
        signed with HMAC-SHA256 over the raw bytes of the request body, using
        your tenant's webhook secret, and the resulting signature is sent in the
        `X-Webhook-Signature` header.

        To verify a webhook, compute the same HMAC-SHA256 signature yourself
        over the exact raw bytes your server received, not a version you've
        parsed into an object and re-serialized, since re-serializing can
        produce a different byte sequence than what was originally signed even
        for a genuine, unmodified payload, which would make a valid signature
        appear invalid. Compare your computed signature to the
        `X-Webhook-Signature` header using a constant-time comparison function,
        such as `hmac.compare_digest` in Python, rather than a plain equality
        check: an ordinary comparison can leak timing information that makes a
        correct signature easier to guess one byte at a time.
      operationId: getWebhookSecretWithApiKey
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/V1WebhookSecretResponse'
      security:
        - ApiKeyAuth: []
components:
  schemas:
    V1WebhookSecretResponse:
      properties:
        webhook_secret:
          type: string
          title: Webhook Secret
      type: object
      required:
        - webhook_secret
      title: V1WebhookSecretResponse
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      description: >-
        A long-lived, privileged API key (`ek_...` prefix), minted once from the
        dashboard. Intended for trusted server-side use only; never expose it in
        client-side code. Send as `Authorization: Bearer ek_...`. Required by
        every Calls, Batches, Agents, Tools, MCP Servers, Documents, and
        Realtime route.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.