Rotating credentials
Tested with: zb CLI 0.1 · API 1.0.0
Credentials are generated inside the cell and shown once. Rotation issues a new password (or token for libSQL) while the old one stays valid for a window you choose, up to 24 hours, so you can roll deployments without downtime.
-
Start the rotation and capture the new secret. It is shown once.
shell zb instances credentials rotate pg-demo --window 6h# new password: ******** (shown once) old password valid until 2026-09-27T20:14:00Z -
Update your secret store and roll your services. On Kubernetes with External Secrets this is a
refreshIntervalaway; on Vercel and friends, update the environment variable and redeploy. -
Verify from the portal that connections have moved: Connect → Credentials shows connections per credential.
-
Let the overlap window expire; the old credential stops working on its own.
- Rotation is audited: who, when, from which IP, and when the old credential was revoked.
- Read-only users (
--role readonly) rotate independently. - The API surface is
POST /v1/orgs/{org}/instances/{id}/credentials/actions/rotate(next API release); the CLI uses it under the hood. - If you suspect a leak, use
--window 0to revoke immediately, then rotate again once services are updated.