# MCP tool reference

1 callable tools.

Use tools/call at https://mcp.schedulerzero.com/mcp with the exact tool name and arguments below. The /tools/ paths in this view are documentation identifiers, not HTTP endpoints. Request execution is disabled for this reference.

Inputs are shown for personal API keys (bound) and for OAuth/delegated agents. Output schemas describe MCP structuredContent: native objects pass through; arrays, scalars and null use a data wrapper. Text content retains the native JSON result.

[Connect a client](/mcp/connect) · [Authentication and authorization](/authentication) · [Generated auth guide](/auth.md) · [Download tool catalog](/mcp-catalog.json) · [Agent documentation](/llms.txt)

## rotate_webhook_secret

Rotate an owned webhook signing secret and return its replacement once.

Rotate when the receiver is ready to install the replacement; requires explicit confirmation.

Never place the returned secret in logs or saved conversation artifacts.

Obtain the user's explicit authorization before invoking a write or destructive action. This is a client interaction requirement, not a server-issued approval token.

Scopes: webhook:update

Risk: security_admin; confirmation: explicit; idempotency: supported.

### Input schema (personal API key)

```json
{
  "type": "object",
  "properties": {
    "workspaceId": {
      "type": "string",
      "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|[fF]{8}-[fF]{4}-[fF]{4}-[fF]{4}-[fF]{12})$",
      "format": "uuid"
    },
    "webhookId": {
      "type": "string",
      "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|[fF]{8}-[fF]{4}-[fF]{4}-[fF]{4}-[fF]{12})$",
      "format": "uuid"
    }
  },
  "required": [
    "workspaceId",
    "webhookId"
  ],
  "patternProperties": {
    "^(?!(?:workspaceId|webhookId)$)[\\s\\S]*$": false
  },
  "additionalProperties": true,
  "propertyNames": {
    "type": "string",
    "enum": [
      "workspaceId",
      "webhookId"
    ]
  }
}
```

### Input schema (OAuth / delegated agent)

```json
{
  "type": "object",
  "properties": {
    "workspaceId": {
      "type": "string",
      "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|[fF]{8}-[fF]{4}-[fF]{4}-[fF]{4}-[fF]{12})$",
      "format": "uuid"
    },
    "webhookId": {
      "type": "string",
      "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|[fF]{8}-[fF]{4}-[fF]{4}-[fF]{4}-[fF]{12})$",
      "format": "uuid"
    }
  },
  "required": [
    "workspaceId",
    "webhookId"
  ],
  "patternProperties": {
    "^(?!(?:workspaceId|webhookId)$)[\\s\\S]*$": false
  },
  "additionalProperties": true,
  "propertyNames": {
    "type": "string",
    "enum": [
      "workspaceId",
      "webhookId"
    ]
  }
}
```

### Output schema (structuredContent)

```json
{
  "type": "object",
  "properties": {
    "webhookId": {
      "type": "string",
      "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|[fF]{8}-[fF]{4}-[fF]{4}-[fF]{4}-[fF]{12})$",
      "format": "uuid"
    },
    "signingSecret": {
      "$ref": "#/$defs/NonEmptyString"
    },
    "fingerprint": {
      "$ref": "#/$defs/NonEmptyString"
    },
    "rotatedAt": {
      "$ref": "#/$defs/UtcDateTimeEncoded"
    }
  },
  "required": [
    "webhookId",
    "signingSecret",
    "fingerprint",
    "rotatedAt"
  ],
  "patternProperties": {
    "^(?!(?:webhookId|signingSecret|fingerprint|rotatedAt)$)[\\s\\S]*$": false
  },
  "additionalProperties": true,
  "propertyNames": {
    "type": "string",
    "enum": [
      "webhookId",
      "signingSecret",
      "fingerprint",
      "rotatedAt"
    ]
  },
  "$defs": {
    "NonEmptyString": {
      "type": "string",
      "minLength": 1,
      "maxLength": 4096
    },
    "UtcDateTimeEncoded": {
      "type": "string",
      "pattern": "^\\d{4}-\\d{2}-\\d{2}T\\d{2}:\\d{2}:\\d{2}\\.\\d{3}Z$"
    }
  }
}
```

### Underlying API operations

- `webhooks.rotateSecret`: `POST /v1/workspaces/:workspaceId/webhooks/:webhookId/secret-rotation`

