# Replace an alert hook's URL

URL: https://docs.fxapis.com/api-reference/alerts/replace-an-alert-hooks-url

> Replace an alert hook's URL. Issues a new secret URL and retires the old one at once: alerts still pointing at it are refused from now on.

`POST https://api.fxapis.com/v1/alert-hooks/{id}/rotate`

Issues a new secret URL and retires the old one at once: alerts still pointing at it are refused from now on. Update every TradingView alert that uses it. The new `url` is returned **once**.

Authentication: `Authorization: Bearer <API key>`.

#### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string (uuid) | yes |  |

#### Responses

- `200`
- `401`
- `403`
- `404`

Failures return `{ "error": { "code", "message" } }`; every code is listed at https://docs.fxapis.com/errors.

#### 200 response fields

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `data` | object | no |  |
| `data.id` | string (uuid) | no |  |
| `data.name` | string | no |  |
| `data.accountIds` | string (uuid)[] | no | One account places an ordinary order; several place a multi-account order. |
| `data.defaults` | object | no |  |
| `data.defaults.volume` | string | no | Lots, used when an alert does not send `volume`. Example: `"0.10"` |
| `data.defaults.deviationPoints` | null \| integer | no | Maximum slippage in points. Null leaves it to the terminal. Example: `20` |
| `data.defaults.symbolMap` | object | no | TradingView symbol (after the exchange prefix is removed) → your broker's symbol. Checked before the suffix. Example: `{"XAUUSD":"XAUUSD.a","US30":"DJ30"}` |
| `data.defaults.symbolSuffix` | string | no | Appended to symbols the map does not name — for brokers that decorate every symbol, like `EURUSD.a`. Example: `".a"` |
| `data.defaults.stripExchangePrefix` | boolean | no | Turn `OANDA:XAUUSD` into `XAUUSD`. On by default. |
| `data.defaults.allowClose` | boolean | no | Whether `close`, `flat` and `close_all` alerts are acted on. On by default. |
| `data.defaults.onlyTradingViewIps` | boolean | no | Refuse alerts that do not come from TradingView's published webhook addresses. On by default. |
| `data.enabled` | boolean | no |  |
| `data.urlHint` | string | no | The URL with its secret elided, for telling hooks apart. The full URL is returned only by create and rotate. Example: `"https://api.fxapis.com/hooks/tradingview/…Qx4w"` |
| `data.lastUsedAt` | null \| string (date-time) | no | When an alert last arrived, to the minute. |
| `data.createdAt` | string (date-time) | no |  |
| `data.url` | string | no | Paste this into the alert's Webhook URL. Shown here and never again — anyone holding it can trade the hook's accounts. Lost or leaked: rotate. Example: `"https://api.fxapis.com/hooks/tradingview/3q2-7ZkT0d8m1sQe9yVbW4nX6pLr5aHcUgJf0oKxQx4w"` |