Why rotation matters
Keys leak in ways you never notice. Rotating on a schedule — and immediately after any suspected leak — turns a leaked key into a short-lived inconvenience instead of a breach.
Rotate at the provider
- Create a new key at the provider.
- Copy it once.
- Do not delete the old key until the new one is confirmed working.
Update the vault
- In the console, open Settings → API keys.
- Paste the new key over the old one.
- Save. The vault now uses the new key.
- Delete the old key at the provider.
Why devices need no change
Devices hold tokens, not keys. When the vault key changes, the next request simply uses the new one — there is nothing to edit on any machine.
Test after rotating
$ remoteagent chat "ping"