Hi all, is there a way to do a zero-downtime secret rotation for OAuth clients without just hardcoding two secrets in the app?
we’ve got a setup where HashiCorp Vault handles the rotation logic. the plan was simple: hit POST /api/v2/oauth/clients/{clientId}/secret to refresh the secret, then push the new value to the vault. problem is, the moment that endpoint returns a 200, the old secret is dead. it’s an instant kill. naturally, any service currently using a cached token or trying to refresh a session during that millisecond window just hits a wall.
trying to automate this for a few dozen clients and it’s just… lovely. who decided that a secret regeneration should be an atomic overwrite instead of a grace period? truly a masterclass in API design.
TL;DR: Rotating secrets via API kills the old one instantly, breaking auth for active sessions.
the current flow looks like this:
# Regenerating the secret for the client
curl -X POST "https://api.mypurecloud.com/api/v2/oauth/clients/12345-6789-abcd/secret" \
-H "Authorization: Bearer {token}"
i tried checking GET /api/v2/oauth/clients to see if there’s some hidden “previous_secret” field or a way to keep both active for a few minutes, but it’s not there. the response is just the new secret and a prayer.
it’s basically a race condition between the API call and the vault update. if the app requests a token in that gap, it’s a 401.