Rotate an API credential

Generate a replacement, deploy it, confirm it works, then revoke the old one.

Updated September 14, 2026 · 1 min read

  1. Generate a new API key from your Developer Dashboard, without deleting the current one yet.
  2. Deploy the new key to your application's environment variables (e.g. PTERI_API_KEY) rather than hardcoding it — see creating your first API key.
  3. Validate that requests using the new key succeed — check the successful field per understanding the API response envelope, not just the HTTP status.
  4. Revoke the old key — see revoking an API credential — once you've confirmed nothing is still using it.

Rotate on a regular schedule as a matter of hygiene, and immediately any time a key may have been exposed — see responding to a suspected compromised account.

Still stuck?

Ask Kai about this article, or open a ticket with our team.

Submit a ticket