Skip to Help Center content

Step-by-step guide

Rotate or disable API credentials

Protect, rotate, and revoke API application secrets safely.

Sensitive cap-table action

Verify permissions, source documents, amounts, dates, affected stakeholders, and the recovery path before changing recorded ownership.

In this article
  1. Protect the secret
  2. Rotate a credential
  3. Disable access
  4. Respond to suspected exposure

Protect the secret

Copy a newly generated API secret into the application’s secure secret manager. Do not put it in source control, screenshots, tickets, chat messages, or browser-side code.

Rotate a credential

  1. Open the application in API access settings and choose Rotate key.
  2. Store the replacement secret securely.
  3. Update the application and confirm successful requests.
  4. Remove the retired secret from every system that stored it.

Disable access

Disable the application immediately when it is compromised, no longer trusted, or no longer needed. Confirm that subsequent requests fail and review recent application activity.

Respond to suspected exposure

  1. Disable or rotate the affected credential before investigating through the compromised system.
  2. Record the application name, affected companies and scopes, and the suspected exposure period.
  3. Review available audit evidence for unexpected operations.
  4. Correct affected business data through its supported workflow and contact Eqdeal when unauthorized activity is possible.
Rotation does not reduce permissions

A replacement secret normally retains the application’s configured companies and scopes. Review and narrow those grants separately when the application needs less access.