HomeGlossaryAPI key rotation
← All glossary terms
Developer API · Distribution Hub Glossary

API key rotation

Replacing an existing API credential with a fresh credential to limit risk or recover from possible exposure.

Safe rotation requires updating the backend secret store, testing authentication and retiring the previous key without disrupting orders. A public frontend should never receive the new secret. Keep a secure record of which service uses each credential and monitor authorization failures after changes.

Key facts

  • Rotate after suspected leakage
  • Update server configuration before retiring old keys where supported
  • Do not copy secret values into support screenshots
This glossary explains general industry concepts and supported Distribution Hub workflows. Review individual product restrictions, current rates and official API documentation before ordering.