Skip to main content

Rotate a key with no downtime

Rotate a key when its secret may have leaked, when someone leaves, or on a schedule. With an overlap, the old and new secrets both route until every environment has the new one, so no request fails during the change. The key keeps its ID, name, default profile, allowed profiles and usage history.

1. Rotate with an overlap

Pick an overlap longer than your slowest deploy:
Store the new values straight into the secret store. Don’t print them. A 202 means the rotation is done but the new secret isn’t serving everywhere yet: keep the old secret in use while previous_valid_until allows, retry RPC with the new secret after Retry-After until it succeeds, and don’t rotate again.

2. Deploy the new secret

Update LASSO_RPC_URL and LASSO_WS_URL in every environment that uses this key, and redeploy or restart. Both secrets route until previous_valid_until.

3. Verify before the overlap ends

Check that each environment sends traffic with the new secret, for example by confirming its deployed configuration, before previous_valid_until.

4. Let the old secret expire

At previous_valid_until, requests with the old secret are refused, and WebSocket connections opened with it close. Clients reconnect with the new secret from their configuration.

Rotate immediately

If a secret leaked, rotate with no overlap, and the old secret stops within seconds:

Limits

  • grace_seconds is at most 86,400 (24 hours).
  • Rotating a key doesn’t rotate your management token. An agent rotates its own token with POST /api/v1/agents/current/rotate, and the old token stops at once.

Next