
Rotate API Tokens Safely
An API token that never changes is a growing risk. If it leaks from a log, a laptop or a third-party service, the leak stays valid forever. Regular rotation shrinks that window to days instead of months.

Pick a rotation schedule 📅
Most teams rotate secrets every 30 to 90 days. Choose a cadence that balances security with how painful rotation is for your codebase — if it is fully automated, rotate more often.
| Cadence | Risk level | Best for |
|---|---|---|
| 30 days | Lowest | Automated pipelines |
| 60 days | Low | Most production teams |
| 90 days | Medium | Small internal tools |
Rotate without downtime 🛠️
- Create the new token in the panel while the old one still works
- Update your environment variable or secrets store
- Deploy the change and watch a few requests succeed
- Revoke the old token from the panel
Because new and old tokens can overlap for a short window, this hand-over gives you zero-downtime rotation every single time.
Automate it in CI ⚙️
If you deploy from a CI system, generate the new token in a build step and push it to your secrets manager automatically. Never paste tokens into chat or commit them to a repository.
Frequently asked questions ❓
What happens to the old token during rotation?
It keeps working until you revoke it, so your integration never goes dark during the switch.
Can I have more than one token at once?
Yes. You can create multiple tokens and rotate between them freely.
How do I know a token leaked?
Check the usage panel for requests from IPs or user agents you do not recognise, then rotate immediately.
Do rotated tokens lose their spend history?
No. Usage and billing stay attached to your account, not to a specific token.
Comments (0)