Skip to content

Rotate and revoke keys

  • Rotate: on the identity’s page, Rotate API Key issues a new key, shown once. The old key stops working at once and its cached session is dropped. Update the agent before or right after.
  • Revoke: disable the identity (the console, or PUT /api/identities/{id} with "enabled": false). The next request is refused, because every request is revalidated against the database.
  • Delete: removes the identity and its grants. Its audit rows keep its name, marked deleted.

Rotating the server-side API-key pepper invalidates every key at once; there is no dual-pepper transition. Treat it as a planned re-key of every agent.