09. API Key Management

Chapter 9 of 24 · 15 min
EXERCISE

Implement key rotation with a grace period. When a user requests rotation, generate a new key and mark the old key as "rotating." During the rotation period (configurable, default 24 hours), accept both keys. After the grace period, automatically deactivate the old key.