---
title: Rotate a key
description: Create a new key for a site in Settings and confirm. The old key stops working right away, so add the new key to your integration straight after.
canonical_url: https://rebilder.com/help/api-keys/rotate-a-key
---

# [Rotate a key](https://rebilder.com/help/api-keys/rotate-a-key)

- **Summary:** Create a new key for a site in Settings and confirm. The old key stops working right away, so add the new key to your integration straight after.

Rotate a key when it may have leaked, when someone who had it leaves, or as routine upkeep. Each site has its own key, and any member of your organization can rotate it in Settings.



## The steps

1. Open Console → Settings and find the site’s card under Sites.
2. Click “Create a new key”. A note replaces the button to remind you that the current key stops working right away.
3. Click “Create new key” to confirm, or Cancel to keep the current key.
4. Copy the new key from the panel that appears. It is shown only once, because we keep only its hash.
5. Replace the key wherever your integration stores it, usually an environment variable in your deployment, and redeploy.

## What happens to the old key

We create the new key before we revoke the old one, so your site always has a working API key. The old key stops working as soon as the new one exists.

Events sent with the old key are rejected (HTTP 401) and not recorded. Your website is not affected: event reporting runs in the background, so a revoked key never slows down or breaks a page. Until you deploy the new key, AI visits has a gap.