Rotating and revoking keys
Because both keys work until you revoke the old one, rotation needs no maintenance window:
- Mint the replacement in the portal, with the same scopes as the key it replaces. Copy the secret, which is shown exactly once.
- Deploy it. Update the environment variable or secret and roll your workers. Both keys are valid at this point, so a half-rolled fleet is fine.
- Check the old key has gone quiet. The portal’s key list shows when each key was last used. When that stops advancing, nothing is still holding it.
- Revoke the old key in the portal, or with
DELETE /api/v1/api-keys/{id}from a signed-in browser session.
Revocation is immediate
Section titled “Revocation is immediate”Every request is checked against the stored hash on each call, with no caching layer to wait out. A revoked key stops working on the next request. There is no grace period, which is exactly what you want when you are revoking because something leaked.
An expired key is rejected the same way. Setting an expiry at creation time means a credential issued for a short-lived job stops mattering even if the cleanup step never runs.
When to rotate
Section titled “When to rotate”Rotate on suspicion, not on schedule alone. Revoking is instant and creating a replacement takes a moment, so there is no reason to wait for proof.
Related
Section titled “Related”- Authentication & API keys.
- Best practices: where a key should live in the first place.
- Revoke API key.