Skip to main content

Rotating a secret

Replace a service account's secret to keep integrations secure and reduce the risk of misuse.

When to use this​

  • Use it on your organization's security schedule.
  • Use it when exposure is suspected.
  • Use it when people with access to the secret change function or leave.

Before you start​

  • Plan the change window with the automation's owner.
  • Confirm where the new secret will be stored.
  • Prepare the update in the system that uses the account.

Step by step​

  1. Open Service Accounts.
  2. Find the account.
  3. Choose the rotate secret action.
  4. Read the impact warning.
  5. Confirm the rotation.
  6. Copy the new secret at the moment it is shown.
  7. Update the automation and verify it works.

What happens next​

  • The previous secret stops being used, according to the behavior your organization configured.
  • The rotation is recorded in the audit trail.
  • The automation should be verified after the change.

Common errors​

  • Rotating without telling the automation's owner.
  • Not updating the consuming system.
  • Storing the new secret somewhere insecure.

Good practice​

  • Keep a rotation schedule.
  • Test the automation right after the change.
  • Revoke the account if it has no owner or current use.

Next steps​