Rotate an API key
Replace a compromised or stale API key without downtime.
Prerequisites
- Security settings access in the Pam Pod
Steps
- Create a new API key in Security settings
- Update integrations with the new secret
- Verify traffic succeeds on the new key
- Revoke the old key from Security settings
Rotate keys on a predictable schedule and after personnel changes. Revoke unused keys promptly.
Expected result
All integrations use the new key and the old key returns 401.
If something goes wrong
Keep the old key active until all callers are updated. Document which systems hold each key.
