Rotate a key with no downtime
Rotate a key when its secret may have leaked, when someone leaves, or on a schedule. With an overlap, the old and new secrets both route until every environment has the new one, so no request fails during the change. The key keeps its ID, name, default profile, allowed profiles and usage history.1. Rotate with an overlap
Pick an overlap longer than your slowest deploy:previous_valid_until allows, retry RPC with
the new secret after Retry-After until it succeeds, and don’t rotate again.
2. Deploy the new secret
UpdateLASSO_RPC_URL and LASSO_WS_URL in every environment that uses this
key, and redeploy or restart. Both secrets route until
previous_valid_until.
3. Verify before the overlap ends
previous_valid_until.
4. Let the old secret expire
Atprevious_valid_until, requests with the old secret are refused, and
WebSocket connections opened with it close. Clients reconnect with the new
secret from their configuration.
Rotate immediately
If a secret leaked, rotate with no overlap, and the old secret stops within seconds:Limits
grace_secondsis at most 86,400 (24 hours).- Rotating a key doesn’t rotate your management token. An agent rotates its
own token with
POST /api/v1/agents/current/rotate, and the old token stops at once.
Next
- Keys, URLs and profiles: defaults and scoped keys.
- Accounts, people and agents: who can rotate and revoke.