Rotate an API credential
Generate a replacement, deploy it, confirm it works, then revoke the old one.
- Generate a new API key from your Developer Dashboard, without deleting the current one yet.
- Deploy the new key to your application's environment variables (e.g.
PTERI_API_KEY) rather than hardcoding it — see creating your first API key. - Validate that requests using the new key succeed — check the
successfulfield per understanding the API response envelope, not just the HTTP status. - Revoke the old key — see revoking an API credential — once you've confirmed nothing is still using it.
Rotate on a regular schedule as a matter of hygiene, and immediately any time a key may have been exposed — see responding to a suspected compromised account.