> ## Documentation Index
> Fetch the complete documentation index at: https://docs.platform.chipper.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Get the signing secret

> Each endpoint has its own secret. Every delivery is signed per [Standard Webhooks](https://www.standardwebhooks.com): headers `webhook-id`, `webhook-timestamp` (unix seconds) and `webhook-signature` (`v1,<base64 HMAC-SHA256>` over `${id}.${timestamp}.${body}`, keyed with the base64-decoded bytes after `whsec_`). Any Standard Webhooks library verifies it out of the box.



## OpenAPI

````yaml /api-reference/openapi.json get /v1/webhooks/signing-secret/{endpointId}
openapi: 3.1.0
info:
  title: Chipper Platform API
  version: '2026-02-20'
  description: >-
    Payouts, collections, and FX across African rails — bank, mobile money, and
    stablecoins — through one API.
servers:
  - url: https://sandbox-api.platform.chipper.ai
    description: Sandbox (sk_test_ keys — simulated rails, no real money)
  - url: https://api.platform.chipper.ai
    description: Production (sk_live_ keys)
security:
  - bearerAuth: []
paths:
  /v1/webhooks/signing-secret/{endpointId}:
    get:
      tags:
        - Webhooks
      summary: Get the signing secret
      description: >-
        Each endpoint has its own secret. Every delivery is signed per [Standard
        Webhooks](https://www.standardwebhooks.com): headers `webhook-id`,
        `webhook-timestamp` (unix seconds) and `webhook-signature` (`v1,<base64
        HMAC-SHA256>` over `${id}.${timestamp}.${body}`, keyed with the
        base64-decoded bytes after `whsec_`). Any Standard Webhooks library
        verifies it out of the box.
      parameters:
        - schema:
            type: string
            description: Webhook endpoint id.
            example: whe_k3m9x2pq7vn4t8wz1bcd
          required: true
          name: endpointId
          in: path
      responses:
        '200':
          description: The current secret.
          content:
            application/json:
              schema:
                type: object
                properties:
                  signingSecret:
                    type: string
                    description: >-
                      Standard Webhooks secret. Base64-decode the part after
                      `whsec_` for the HMAC key (libraries do this for you).
                    example: whsec_Gq3n4yK8sZ2mV7xR1tL9wC5pB6hD0fJ4aE8uN2kM3oY=
                required:
                  - signingSecret
        '401':
          description: Missing or invalid API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: unauthorized
                message: Invalid API key
                requestId: req_q7vei435zifs51ia0lqr
        '404':
          description: No such resource in this organization.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: not_found
                message: Webhook endpoint not found
                requestId: req_q7vei435zifs51ia0lqr
      security:
        - bearerAuth: []
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
          description: Stable machine-readable code.
        message:
          type: string
          description: Human-readable explanation.
        requestId:
          type: string
          description: Echoed in the x-request-id response header — quote it to support.
      required:
        - error
        - message
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Your API key: `sk_test_…` (sandbox) or `sk_live_…` (production).'

````