Security

Rotate a server API key

Issue a new RESTRICTED KEY or SECRET KEY, deploy it, then revoke the old key.

Create the replacement key

Choose the least access required. RESTRICTED KEYS use explicit scopes; SECRET KEYS include every current and future eligible server scope for that environment.

Deploy before revoking

Update your secret store and running services. Veltor shows each server key only once at creation.

Revoke the old key

Revoke in Developers when traffic no longer uses the old verifier.

Related guides

Documentation