Use Lockers
Rotate or revoke an API key
Replace a key on a schedule, cut one off when it leaks, and know what stops a key working.
The short version
- Rotate issues a new key and lets the old one keep working for up to 24 hours, so the connected tool does not break the moment you switch.
- Revoke stops a key at once, and it still works on a Locker that has left Pro.
- A key can also stop on its own: it expires, the admin who created it loses admin access, or the Locker leaves Pro.
Before you start
Keys live under Customer API keys on the Integrations page, under Admin, then Settings, and owners and admins of a Pro Locker manage them. Creating and rotating keys requires an active Pro plan. On a Locker without Pro, the page says so directly: Creating and rotating keys requires an active Pro plan. Existing keys are inactive while integrations are unavailable, and you can revoke them at any time.
A community can hold at most ten active keys, and every key expires after the number of days chosen when it was made, up to 90. Both numbers are worth knowing before you rotate, because retiring a connection you no longer use is usually better than adding another key to the list.
Rotate a key
The overlap is what makes a rotation calm. Both keys work until the window closes, so the other system can be updated on its own schedule instead of during an outage. When the window ends, the old key stops.
If you close the screen without copying the new key, Lockers cannot show it again. Rotate once more and copy it that time. Keep the key out of source control, URLs, logs, and anything that runs in a browser.
- 1
Find the key
Open Admin, then Settings, then Integrations, and find the key under Customer API keys.
- 2
Select Rotate
Select Rotate on that key's row.
- 3
Choose the overlap
Choose how long the old key keeps working: Revoke old key immediately, 1 hour, 4 hours, 12 hours, or 24 hours.
- 4
Copy the new key
Lockers shows the new key once. Copy it straight into a secret manager or an environment variable before you leave the screen. It starts with cs_live_.
- 5
Test it
Paste it into the connected tool, then select Test the connection under Connection check to confirm the new key reaches your community.
Choosing the overlap
- Revoke old key immediately when the key may have leaked, or when you can paste the new one into the tool in the same sitting.
- 1 hour or 4 hours when you control the other system and will make the change today.
- 12 hours or 24 hours when someone else has to make the change, or the tool only picks up new settings on a release.
Revoke a key
Select Revoke on the key's row. Lockers asks you to confirm that the named key should be revoked immediately, and warns that requests using it will stop. Confirm, and requests carrying that key fail from that point.
Revoke rather than rotate when a connection is finished for good, or when you believe the key is in the wrong hands. Revocation stays available even after a Locker leaves Pro, so losing Pro never traps an old key in place.
What stops a key working
Every request rechecks the key before answering, which is why a connection can stop without anyone touching the Integrations page. Four things end a key's access:
- The key reaches its expiry date. Keys last for the number of days set at creation, 90 at most.
- You revoke it, or rotate it and let the overlap run out.
- The admin who created the key loses admin access to the community. The integration stops with it.
- The Locker leaves Pro. Existing keys go inactive while integrations are unavailable.
What survives a rotation
Rotating changes the credential and leaves the connection itself in place. Drafts, invitations, and webhook endpoints created through that connection stay attributed to it, so a webhook endpoint bound to a named connection keeps delivering across the change.
Test the connection is the fastest confirmation. It reports the connection's name, environment, permissions, restrictions, expiry, and quota windows, so one press tells you whether the new key is live and what it can still do. To change what the key is allowed to reach, see Choose API permissions, and for setting up a new connection from scratch, see Connect another tool to your Locker.
Build the smallest useful version of your community.
Start with a feed, classroom, calendar, messages, and member list. No card required.
Start a community