Home / Home / Templates / Agent API Key Rotation Policy

Agent API Key Rotation Policy

Keys age into risk. Rotation on a schedule — with scoping and a compromise path — keeps credentials fresh.

The policy

1. Cadence: keys rotate every 90 days (30 for high-risk agents).

2. Scoping: one key per agent, minimum permissions.

3. Rotation process: issue new key, migrate, revoke old, verify in the log.

4. Compromise path: kill switch on the agent, revoke key, audit the window.

5. Inventory: a quarterly list of every key and its agent.

FAQ

How often is enough?

90 days standard; 30 for anything touching payments.

What's the compromise first step?

Kill the agent's spending, then revoke the key — in that order.

Related

Stop the next $12,400 night.

One API call (or MCP tool) in front of every agent transaction — APPROVED, BLOCKED, or FLAGGED, deterministic, ~5 ms, fully logged.

See plans — from $99/mo Try a live check