Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is no single safe rotation interval for every API key and service credential. Set schedules by credential type, privileges, exposure, available rotation methods, and the risk of disrupting dependent systems. Google Cloud recommends rotating user-managed service-account keys at least every 90 days; that is provider-specific guidance, not a universal rule. Rotate promptly if compromise is suspected, and replace credentials a departing person could access when their access is revoked.

Why there is no universal rotation schedule

Credentials differ in how long they remain valid, what they can access, where they are stored, and how easily they can be replaced. A persistent key with broad privileges and copies in multiple systems creates a different risk from a narrowly scoped, short-lived credential. The rotation process also matters: a schedule that cannot be completed safely can trade exposure risk for outage risk.

Choose a cadence for each credential class using its lifetime, privilege level and blast radius, exposure history, support for short-lived identity, application compatibility, monitoring, automation, and the operational cost of replacement. Document why a credential follows a particular schedule, especially when it differs from a provider recommendation or organizational requirement.

What provider guidance says about intervals

Google Cloud user-managed service-account keys

Google Cloud recommends rotating user-managed service-account keys at least every 90 days to reduce risk from leaked keys. This recommendation applies to those keys specifically; it does not establish a 90-day interval for every API key, token, certificate, or other service credential. See Google Cloud’s service-account key rotation guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

AWS Secrets Manager control default

AWS Security Hub’s Secrets Manager periodic-rotation control uses 90 days as its default maxDaysSinceRotation value. The control is configurable from 1 to 180 days, so its default is a check setting—not a general rule that every secret or API key should rotate every 90 days. See AWS Security Hub’s Secrets Manager controls.

API keys and other credentials

Google Cloud recommends periodically replacing API keys, updating applications to use the replacements, and deleting the old keys, but its API-key guidance does not specify a universal numerical interval. It also recommends considering more secure authorization approaches, such as IAM policies or short-lived service-account credentials where appropriate. See Google Cloud’s API key best practices.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

When to rotate immediately

  • Suspected compromise or leakage: Replace or revoke the affected credential promptly. Check repositories, configuration, and other locations where copies may exist, and identify dependent systems. Google Cloud specifically advises immediate rotation when a service-account key is suspected to be compromised. See Google Cloud’s rotation guidance.
  • Access is being revoked: Rotate project credentials—including API keys and OAuth client secrets—if a person whose access is being removed could access them. Revoking the person’s account alone does not address copies of shared credentials they may have obtained. See Google Cloud’s guidance on removing access.
  • Another exposure event: Treat unauthorized access or a staff or vendor access change as a trigger to assess affected credentials and replace those the person or event could have exposed.

How to build a workable rotation policy

  1. Inventory credentials. Record each credential’s type, owner, dependent workloads, permissions, storage locations, and available last-use evidence. Disable credentials that are no longer needed; delete them once they are confirmed unused. Google Cloud recommends removing unneeded service-account keys. See Google Cloud’s service-account key management best practices.
  2. Reduce persistent-key use. Where the platform and workload allow it, prefer identity-based access or short-lived credentials. Persistent user-managed keys need a clear owner, scheduled replacement, monitoring, and a revocation process. See Google Cloud’s key management best practices and API key best practices.
  3. Assign a cadence by credential class. Use applicable provider recommendations and organizational requirements as starting points. Account for privilege, exposure, compatibility, and outage risk; record the reason for exceptions. The available provider guidance does not identify one optimal interval for all credential types.
  4. Plan a staged replacement. Create the replacement, deploy it to every consumer, and verify successful use. Then disable the old credential, monitor for failures, and delete it after confirming the replacement works. Google Cloud’s key-rotation process follows this sequence. Keep overlap only as long as needed for a safe transition; do not leave old credentials active indefinitely.
  5. Test the full automation path. Confirm that automation updates consumers, detects failures, supports recovery, and verifies revocation of the old credential—not merely that it sends a reminder or creates a replacement.

What automation does—and does not—do

A secrets-management service can help manage credential lifecycles, but automation is effective only when it handles the steps your applications need. AWS Secrets Manager supports automatic rotation for supported secrets. Google Cloud Secret Manager can send scheduled rotation notifications based on a configured period or next rotation time; a notification can start a workflow, but does not by itself prove that credentials were replaced in every consumer. See AWS Secrets Manager rotation documentation and Google Cloud Secret Manager rotation notifications.

Before relying on an automated schedule, test consumer updates, failure alerts, recovery or rollback, and evidence that the old credential has been revoked. A periodic check or notification is not the same as end-to-end rotation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do service-account keys expire automatically?

Google Cloud user-managed service-account keys do not expire by default. Google cautions that expiry settings for production workloads can cause accidental outages; it recommends managing production key lifecycle through rotation and considering expiry for temporary uses when dependencies are understood. See Google Cloud’s service-account key management best practices and Google Cloud service-account credentials documentation.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.