Security teams everywhere are pushing for more frequent credential rotation – and for good reason. Long-lived API credentials increase risk, expand the window of exposure when secrets are compromised and often become difficult to track over time.
If you are an SRE or a team responsible for DNS, rotating credentials has traditionally come with a different concern – operational risk. DNS sits in front of every application transaction. When access to your DNS platform breaks, the impact is immediate, affecting the systems and processes organizations rely on every day and it is visible to everyone. Credential rotation must be implemented in a way that strengthens security without introducing the very kind of operational risk you are trying to prevent.
That is why IBM NS1 Connect now supports API key secret expiration and rotation – a product enhancement designed to help teams strengthen security while maintaining the reliability their operations demand.
Why this Matters
In most environments, API credentials quietly live longer than they should. They get embedded into scripts. They get passed between teams. They get baked into integrations, automation, pipelines and tooling that nobody wants to touch because “it’s been working for years.”
The problem isn’t that teams don’t want to rotate. The problem is that traditional rotation models treat the credential as a single thing — when in reality, it’s connected to a long tail of downstream systems that can’t all be updated at the same instant. If the old key has been cut off before everything has moved, now you’ve broken the very automation rotation was meant to protect. This new feature is designed specifically to avoid that trap.
What is New
In NS1 Connect, the API key and the API key secret are now treated as two separate objects. The API key defines the permissions. The API key secret is the token that authenticates requests. Expiration applies to the secret — not the key itself.
This separation enables a safer and more flexible rotation model. Teams can generate a new secret with a new expiration date before the existing one expires — without immediately invalidating the secret that’s still in use. A single API key can have two valid secrets at the same time, giving teams a real transition window to migrate applications, automation and integrations on their own schedule.
API keys created without expiration continue to function as they always have. However, rotation capabilities are available only for credentials participating in the expiration lifecycle, allowing organizations to adopt the feature where it delivers the most value.
Why this matters for platform and SRE teams
This isn’t just a security enhancement – it is a reliability feature.
DNS operations today depend heavily on automation. Pipelines push zone changes. Platform tooling depends on API access. Integrations rely on credentials that no human looks at on a regular basis. When those credentials are static and long-lived, you accumulate both security exposure and operational debt — and the day you finally try to rotate is the day you find out exactly where the dependencies are.
By supporting secret expiration and controlled rotation, NS1 Connect enables teams to modernize credential management without introducing unnecessary operational risk. New secrets can be deployed and validated while existing secrets remain active, giving teams time to update dependent systems and verify successful adoption.
Instead of a high-pressure credential cutover, rotation becomes a planned operational process—one that improves security while maintaining the reliability that DNS-dependent services require.
How to get started
Getting started is straightforward and you can roll it out incrementally.
1. Identify the workloads where credential rotation provides the greatest value. Start with the credentials used by automation, pipelines and integrations — the ones with the broadest radius.
2. Create new API keys with an expiration duration that aligns with your operational and security requirements.
3. Store each new secret securely when it is created. Secrets are displayed only once, so they should be written directly to your organization’s secrets management solution.
4. Rotate before expiration. Generate the new secret while the old one is still valid, update dependent systems and verify the new secret is in use before the old one expires.
5. Retire the old secret intentionally. Let it expire on schedule or disable it once you’ve confirmed nothing depends on it.
By introducing rotation gradually, organizations can improve security without disrupting production operations.
Security without compromise
The most effective security controls are the ones that teams can implement consistently and confidently.
Credential rotation should not require emergency maintenance windows, risky migrations or last-minute troubleshooting. It should be a routine operational practice that improves security while preserving reliability.
With API key secret expiration and rotation, IBM NS1 Connect provides a practical way to modernize credential management for DNS automation. Teams can reduce reliance on long-lived credential, support compliance initiatives and maintain the operational stability their business depends on.
API key secret expiration and rotation is available now in IBM NS1 Connect.

Learn more
#Technical
#TechnicalBlog
#ProductUpdates/Announcements
#BestPractices