L15 · IDENTITY AND TRUST
Rotate a signing key
Rotate your test tenant's signing key and watch verifiers keep working.
Planned
Steps
Rotate the signing key in your test tenant.
What the server will check: Your tenant's Audit shows the rotation.
Find the new key identifier in your tenant's published keys.
What the server will check: Nothing to check. The old key stays published while its tokens are still valid.
Submit tokens signed by the old key and the new key to the lab verifier.
What the server will check: Both tokens verified.
When it opens
This lab is planned. It opens when these are in place:
- Signing key rotation in tenant settings
- A lab token verifier
The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.