Zero-downtime OAuth secret rotation for Genesys Cloud

Looking to rotate the client secret for our integration without dropping active sessions. The goal is to have the new secret live before the old one expires.

Plan:

  1. Regenerate the secret via POST /api/v2/oauth/clients/{clientId}/secret
  2. Update our app config to use the new secret
  3. The old secret is invalidated by the regeneration, so there is no separate revocation step.

The issue is the timing. If I regenerate immediately, any long-running processes that cached the old token will fail on refresh. The docs say tokens are valid for 1 hour by default.

Is there a way to keep both secrets active simultaneously for a transition window? Or do I just have to wait out the token lifespan before regenerating?

Getting a 200 on the regeneration call. Not sure if the old secret stays valid automatically or if I need to set a specific expiry. Need to avoid 401 errors in our batch jobs.