All guides

Rotate and Retire Keys Without Surprises

A routine for provider credentials, virtual keys, telemetry keys, and edge tokens: what to rotate, in what order, and how to cut off a leak.

8 min read Updated October 2026LLM FinOps
On this page
  1. 01What you'll set up
  2. 02What can be rotated
  3. 03Rotate a provider credential
  4. 04Rotate a virtual key
  5. 05Telemetry keys and edge tokens
  6. 06If you suspect a leak
  7. 07Set expiries
  8. 08What revoking affects
  9. 09A rotation calendar
  10. 10Rotation as code
  11. 11A quarterly review
  12. 12If something goes wrong

01

What you'll set up

Keys age, people move on, and secrets leak. In about eight minutes you will set a rotation routine for every kind of key and learn the order for an emergency.

  • A list of what can be rotated and how
  • A calendar routine for each
  • An incident order for a suspected leak
  • A quarterly review

02

What can be rotated

Four kinds of secret are involved. Each has its own control.

SecretWhereRotateRevoke
Provider credentialProvider Credentials cardRotate with a replacement keyRevoke
Virtual keyVirtual Keys cardRotate issues a new secretRevoke
Telemetry keyTelemetry Keys cardCreate a new key, then revoke the oldRevoke
Edge tokenEdge Instances cardRegister again, then revoke the oldRevoke
Access tokenOrganization settings → Personal Access TokensCreate a new token, then revoke the oldRevoke

03

Rotate a provider credential

Provider credentials rotate without touching your apps.

  1. 1

    Create the replacement at the provider

    Keep the old key live.

  2. 2

    Choose Rotate in Cloptima

    Enter the replacement key.

  3. 3

    Test

    Confirm the credential passes.

  4. 4

    Delete the old key at the provider

    Last.

04

Rotate a virtual key

A virtual key's old secret stops working as soon as you rotate, so order matters.

A safe key swap
  1. 1Open your secret manager

    Ready to store the new secret

  2. 2Rotate the key

    Copy the new secret

  3. 3Store and deploy

    Update the app

  4. 4Confirm traffic

    Check the Explorer

For a key that must never fail, create a second key with the same labels, move the app to it, then revoke the first. There is no gap that way.

05

Telemetry keys and edge tokens

These do not rotate in place. Create the replacement first.

  1. 1

    Create the new key or register the edge again

    Copy the new secret or token.

  2. 2

    Switch the SDK or the edge to it

    Redeploy.

  3. 3

    Check that data flows

    Usage events and heartbeats arrive.

  4. 4

    Revoke the old one

    It stops working at once.

06

If you suspect a leak

Work from the widest exposure to the narrowest. Cut off first, investigate after.

  1. 1

    Revoke the exposed virtual key

    Requests with it stop at once.

  2. 2

    Rotate or revoke the provider credential if it was exposed

    Revoke makes bound requests fail, so you notice.

  3. 3

    Revoke the telemetry key or edge token if exposed

    Then replace them.

  4. 4

    Check the Explorer for the key

    Group by Virtual Key and look at the hours around the exposure.

  5. 5

    Open the Audit tab

    Review changes made around the same time.

  6. 6

    Replace and redeploy

    Create the new key with the same labels.

07

Set expiries

A key that expires cannot be forgotten.

KeyA reasonable lifetime
Virtual key for a production app90 to 365 days, rotated on a schedule
Virtual key for a pilot30 days
Telemetry key365 days
Access token for a person or scriptAs short as you can manage

The console starts virtual keys at 3,650 days. Choose a shorter lifetime when you create the key.

08

What revoking affects

Know the reach of each revoke before you press it.

You revokeStopsLeaves alone
A virtual keyRequests from the apps that use that keyOther keys, credentials, and policies
A provider credentialRequests bound to it, and its provider for model-name choiceVirtual keys, which can use another credential
A telemetry keyUsage events sent with itGateway traffic
An edge tokenThat edge instance's connection to CloptimaYour provider keys, which never left your hosts

09

A rotation calendar

Put the dates where a person will see them.

WhenWhat
MonthlyRead the Virtual Key grouping in the Explorer; revoke keys with no use
QuarterlyTest All credentials; review who may create keys and tokens
Every 90 to 365 daysRotate production virtual keys
When a provider asks, and once a year at leastRotate provider credentials
When a person with access leavesRotate what they could see, and revoke their tokens

10

Rotation as code

Virtual keys can be managed in Terraform. Changing a key's lifetime replaces the key, which mints a new secret, so a rotation is a reviewed change.

main.tf
resource "cloptima_llm_virtual_key" "support_chatbot" {
  name            = "support-chatbot-prod"
  expires_in_days = 180
  team_id         = "support"
  app_id          = "support-chatbot"
  environment     = "production"

  lifecycle {
    create_before_destroy = true
  }
}

create_before_destroy issues the new key first, so you can store its secret and deploy before the old one is retired. The secret is a sensitive output; write it to your secret manager and nowhere else.

11

A quarterly review

A short routine keeps the list honest.

  1. 1

    List active keys

    Open each card and read the last-used time.

  2. 2

    Revoke the unused

    Anything with no recent use is a risk.

  3. 3

    Check labels

    Every key has a team and an app.

  4. 4

    Retest credentials

    Use Test All.

12

If something goes wrong

Most surprises come from order.

What you seeLikely causeFix
An app fails right after a rotationThe old secret was retired before the app had the new oneUpdate the app, or create a second key next time
Requests are refused after a revokeThe key or credential was revoked on purposeCreate a replacement and update the app
A credential test fails after a rotationThe replacement key lacks accessFix the key at the provider and rotate again

Put This Guide Into Practice

Cloptima automates the strategies described in this guide.

No credit card required
5-minute setup
Free trial