API Key and Token Service  ·  View 19 of 22  ·  Act 6 · Operations

Credential Lifecycle

The loop every key travels, and the point at which a leak cuts into it.

Editable source SVG draw.io All views
Issued scoped, dated, attributed In use last_used_at observed Expiry warned 30 / 7 / 1 days Rotating successor live, 7-day overlap Revoked irreversible, propagated Retained in audit 400 days hot, 7 years cold Credential lifecycle first call approaching expiry developer acts predecessor dies trail survives the key lessons set the next scope Credential Lifecycle — the loop every key travels Application we own Decision point Security / platform Data store A leak enters this ring at Revoked, from any state. The loop closes because the audit record outlives the credential. v 1.0 · owner Security Platform Architecture · date 2026-09

Why it closes

  • The audit record outlives the credential by years, which is what turns a dead key into an answerable question rather than an absence.
  • Expiry is the default state of the ring. A non-expiring key is an explicit, attributable exemption with a review date — visible as an exception rather than as the norm.

The shortcut

  • A leak enters at Revoked from any state, skipping the warning and rotation arcs entirely. Every step around the top of the ring exists to make that shortcut rare; nothing makes it impossible.