- Purpose
- Ensure no credential outlives its purpose or its owner.
- Prerequisites
- Secret manager
- Architecture
- One client per environment per integration; never shared across customers.
Configuration
| Rotation | Every 90 days with dual-accept window |
Implementation steps
- 01Issue per environment
- 02Store server-side only
- 03Rotate on schedule and on personnel change
- 04Revoke immediately on suspicion
Testing procedure
- Rotate in the sandbox with zero downtime
Troubleshooting
Outage during rotation
Dual-accept window was too short or the cache was not refreshed.