> For the documentation index, fetch https://sync.so/docs/llms.txt. Append .md to a page URL for Markdown. Documentation-search MCP: https://sync.so/docs/_mcp/server. # Get Webhook Secret GET https://api.sync.so/v2/organizations/webhook/secret Retrieve your organization's webhook signing secret. This is a public, authenticated endpoint you can use to verify the `Sync-Signature` header on generation and batch webhook deliveries: Sync signs the raw JSON request body as HMAC-SHA256 over `${timestamp}.${rawBody}` and sends it as `Sync-Signature: t=,v1=`. Store the full `whsec_...` value securely. `masked=true` returns a display-only value; do not use it as a verification secret. The same secret is available on the [webhooks settings page](https://sync.so/settings/webhooks). Reference: https://sync.so/docs/api-reference/api/organizations-api/get-webhook-secret ## Authentication - `x-api-key` header (required) — API Key authentication via header ## Servers - `https://api.sync.so` (Default, default) - `https://dev-api.sync.so` (dev) - `http://localhost:3001` (local) ## Request ### Query parameters - `masked` (boolean, optional, default: false) — When true, returns a display-only masked version of the secret that must not be used as a verification secret. Omit or set false when configuring a webhook verifier so you get the usable value. ## Response ### 200 Webhook secret retrieved successfully - `secret` (string, required) — The webhook signing secret, prefixed with `whsec_`. When the request sets `masked=true`, this is a display-only masked value and must not be used to verify signatures. ## Errors ### 401 Unauthorized Error Unauthorized - Invalid or missing authentication - `message` (GenerationErrorMessage, required) — A message describing the error. - `statusCode` (double, required) — The type of error that occurred. - `errorCode` (string, optional) — Stable, machine-readable error code (e.g. project_not_found, voice_not_found, concurrency_limit_reached). Branch your error handling on this, not on the message text. The full catalog of codes with messages and suggested fixes is served unauthenticated at GET /v2/errors. - `suggestion` (string, optional) — A suggested fix an agent can act on. - `field` (string, optional) — The request field the error refers to, when the failure is tied to a specific field (e.g. projectId, voiceId, input[].assetId). - `docsUrl` (string, optional) — Link to the documentation page for the failing operation. - `requestId` (string, optional) — Present on unexpected 500 responses. Include it when contacting support so the failing request can be located directly. - `generationId` (string, optional) — Original generation ID when available for an uncertain keyed submission. Poll this ID; do not create another action to bypass IDEMPOTENCY_OUTCOME_UNKNOWN. - `dialogueEditSection` (DialogueEditRetimeFailureSection, optional) — For dialogue_edit_removal_too_large: the section to change, when it can be identified. Create a new dialogue edit preview before submitting again. ### 500 Internal Server Error Internal Server Error - An unexpected failure on our side. The body carries errorCode internal_error and a requestId; include the requestId when contacting support. - `message` (GenerationErrorMessage, required) — A message describing the error. - `statusCode` (double, required) — The type of error that occurred. - `errorCode` (string, optional) — Stable, machine-readable error code (e.g. project_not_found, voice_not_found, concurrency_limit_reached). Branch your error handling on this, not on the message text. The full catalog of codes with messages and suggested fixes is served unauthenticated at GET /v2/errors. - `suggestion` (string, optional) — A suggested fix an agent can act on. - `field` (string, optional) — The request field the error refers to, when the failure is tied to a specific field (e.g. projectId, voiceId, input[].assetId). - `docsUrl` (string, optional) — Link to the documentation page for the failing operation. - `requestId` (string, optional) — Present on unexpected 500 responses. Include it when contacting support so the failing request can be located directly. - `generationId` (string, optional) — Original generation ID when available for an uncertain keyed submission. Poll this ID; do not create another action to bypass IDEMPOTENCY_OUTCOME_UNKNOWN. - `dialogueEditSection` (DialogueEditRetimeFailureSection, optional) — For dialogue_edit_removal_too_large: the section to change, when it can be identified. Create a new dialogue edit preview before submitting again. ## Types ### GenerationErrorMessage A message describing the error. ### DialogueEditRetimeFailureSection The dialogue-edit section that removes too much speech to stay in sync. - `slotIndex` (integer, required) — Zero-based index of the section in the preview's `resultSlots`. - `sourceStartMs` (integer, optional) — Start of the section in the source video, in absolute milliseconds. - `sourceDurationMs` (integer, optional) — Length of the section in the source video, in milliseconds. ## Examples **Response** ```json { "secret": "whsec_a1b2c3d4e5f6" } ``` **SDK Code** ```python import requests url = "https://api.sync.so/v2/organizations/webhook/secret" headers = {"x-api-key": ""} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api.sync.so/v2/organizations/webhook/secret'; const options = {method: 'GET', headers: {'x-api-key': ''}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.sync.so/v2/organizations/webhook/secret" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("x-api-key", "") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api.sync.so/v2/organizations/webhook/secret") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["x-api-key"] = '' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api.sync.so/v2/organizations/webhook/secret") .header("x-api-key", "") .asString(); ``` ```php request('GET', 'https://api.sync.so/v2/organizations/webhook/secret', [ 'headers' => [ 'x-api-key' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api.sync.so/v2/organizations/webhook/secret"); var request = new RestRequest(Method.GET); request.AddHeader("x-api-key", ""); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = ["x-api-key": ""] let request = NSMutableURLRequest(url: NSURL(string: "https://api.sync.so/v2/organizations/webhook/secret")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```