24
Vent: API key rotation at 2am because of a stale cache
We run a small SaaS out of Denver and last Thursday I rotated our master key for a client integration, but their edge cache kept serving the old one for 6 more hours. By 3pm Friday, a bot hit our rate limit using that dead key and locked out the whole tenant, so I had to whitelist their IP manually just to keep their dashboard alive. Has anyone else dealt with a downstream cache holding onto revoked credentials, or is there a standard TTL you set for that kind of thing?
0 comments
Log in to join the discussion
Log In0 Comments
No comments yet
Be the first to share your thoughts on this discussion.