# Tokenization Decisioning HMAC Secret

## Response Codes

### 200 OK

- **secret**: string  
  The new Tokenization Decisioning HMAC secret

### 401 Unauthorized

| Code | Message | Description |
| --- | --- | --- |
| User has not been authenticated | Invalid or missing API key |
| API key is not active | The API key used is no longer active |
| Could not find API key | The API key provided is not associated with any user |
| Please provide API key in Authorization header | The Authorization header is not in the request |
| Please provide API key in the form Authorization: [api-key] | The Authorization header is not formatted properly |
| Insufficient privileges. Issuing API key required | Write access requires an Issuing API key. Reach out at [lithic.com/contact](/content/contact/index.html) |
| Insufficient privileges to create virtual cards. | Creating virtual cards requires an additional privilege |

### 429 Too Many Requests

Client has exceeded the number of allowed requests in a given time period.

| Code | Message | Description |
| --- | --- | --- |
| Rate limited, too many requests per second | User has exceeded their per second rate limit |
| Rate limited, reached daily limit | User has exceeded their daily rate limit |
| Rate limited, too many keys tried | One IP has queried too many different API keys |

## Example Request

```shell
curl --request POST \
     --url https://sandbox.lithic.com/v1/tokenization_decisioning/secret/rotate \
     --header 'accept: application/json'
```

## Example Response

```json
{
  "secret": "whsec_1NDsYinMGr951KuDEaj78VtWzlyPaOnwUVagFiWIPJs="
}
```
