Agent API Key Rotation Policy
Keys age into risk. Rotation on a schedule — with scoping and a compromise path — keeps credentials fresh.
The policy
1. Cadence: keys rotate every 90 days (30 for high-risk agents).
2. Scoping: one key per agent, minimum permissions.
3. Rotation process: issue new key, migrate, revoke old, verify in the log.
4. Compromise path: kill switch on the agent, revoke key, audit the window.
5. Inventory: a quarterly list of every key and its agent.
FAQ
How often is enough?
90 days standard; 30 for anything touching payments.
What's the compromise first step?
Kill the agent's spending, then revoke the key — in that order.
Related
Stop the next $12,400 night.
One API call (or MCP tool) in front of every agent transaction — APPROVED, BLOCKED, or FLAGGED, deterministic, ~5 ms, fully logged.
See plans — from $99/mo Try a live check