Rotate or disable API credentials
Protect, rotate, and revoke integration secrets safely.
Last reviewed: 2026-08-25
Protect the secret
Copy a newly generated API secret into the integration’s secure secret manager. Do not put it in source control, screenshots, tickets, chat messages, or browser-side code.
Rotate a credential
- Open the integration in API access settings and choose Rotate key.
- Store the replacement secret securely.
- Update the integration and confirm successful requests.
- Remove the retired secret from every system that stored it.
Disable access
Disable the integration immediately when it is compromised, no longer trusted, or no longer needed. Confirm that subsequent requests fail and review recent integration activity.