L34 · OAUTH 2.0
Rotate a client secret
Get a token with a client secret, rotate it, and see the old secret stop working while the new one takes over.
Planned
Steps
Request a token with the current client secret.
What the server will check: A successful token request for your client.
Rotate the client secret in your tenant and copy the new value.
What the server will check: Your tenant recorded the secret rotation.
The new secret is shown once and stored only as a hash.
Try the old secret again.
What the server will check: The token endpoint rejected the old secret.
Your tenant replaces the secret at once, with no overlap, so every copy of the old secret stops working immediately.
Request a token with the new secret.
What the server will check: A successful token request with the new secret.
When it opens
This lab is planned. It opens when these are in place:
- Lab setup and cleanup in your test tenant
The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.