T
24

Vent: API key rotation at 2am because of a stale cache

We run a small SaaS out of Denver and last Thursday I rotated our master key for a client integration, but their edge cache kept serving the old one for 6 more hours. By 3pm Friday, a bot hit our rate limit using that dead key and locked out the whole tenant, so I had to whitelist their IP manually just to keep their dashboard alive. Has anyone else dealt with a downstream cache holding onto revoked credentials, or is there a standard TTL you set for that kind of thing?
0 comments

Log in to join the discussion

Log In
0 Comments

No comments yet

Be the first to share your thoughts on this discussion.