Skip to content

Rotating credentials

Tested with: zb CLI 0.1 · API 1.0.0

Credentials are generated inside the cell and shown once. Rotation issues a new password (or token for libSQL) while the old one stays valid for a window you choose, up to 24 hours, so you can roll deployments without downtime.

  1. Start the rotation and capture the new secret. It is shown once.

    shell
    zb instances credentials rotate pg-demo --window 6h
    # new password: ******** (shown once) old password valid until 2026-09-27T20:14:00Z
  2. Update your secret store and roll your services. On Kubernetes with External Secrets this is a refreshInterval away; on Vercel and friends, update the environment variable and redeploy.

  3. Verify from the portal that connections have moved: Connect → Credentials shows connections per credential.

  4. Let the overlap window expire; the old credential stops working on its own.

  • Rotation is audited: who, when, from which IP, and when the old credential was revoked.
  • Read-only users (--role readonly) rotate independently.
  • The API surface is POST /v1/orgs/{org}/instances/{id}/credentials/actions/rotate (next API release); the CLI uses it under the hood.
  • If you suspect a leak, use --window 0 to revoke immediately, then rotate again once services are updated.