Hello,
A 401 after webhook secret rotation usually means the sender and receiver are not using the same secret. Verify that your application is validating against the new secret and, during the transition, consider accepting signatures generated by both the old and new secrets.
Also ensure the HMAC SHA256 is calculated from the raw request body exactly as received, since any payload modification can cause a signature mismatch.
I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!
Domic Vo.