Looking to rotate the client secret for our integration without dropping active sessions. The goal is to have the new secret live before the old one expires.
Plan:
- Regenerate the secret via POST /api/v2/oauth/clients/{clientId}/secret
- Update our app config to use the new secret
- The old secret is invalidated by the regeneration, so there is no separate revocation step.
The issue is the timing. If I regenerate immediately, any long-running processes that cached the old token will fail on refresh. The docs say tokens are valid for 1 hour by default.
Is there a way to keep both secrets active simultaneously for a transition window? Or do I just have to wait out the token lifespan before regenerating?
Getting a 200 on the regeneration call. Not sure if the old secret stays valid automatically or if I need to set a specific expiry. Need to avoid 401 errors in our batch jobs.