Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Rotate the credential that was exposed, using the system that issued it: revoke a Zammad personal API token in the user profile, an internal RSS link in its RSS dialog, and an OAuth client secret at the identity provider. Passwords and browser sessions are separate access paths, so address them separately if they may also be compromised. Do not paste a suspected secret into a ticket, chat, shell history, or public issue tracker.

Identify the exposed credential and who controls it

Start with where the value came from and what it grants access to. Zammad credentials do not share one universal rotation control: a profile token, sign-in password, device session, RSS URL, and provider-issued OAuth secret each have a different owner and replacement process.

Credential What it grants Where to revoke or replace it What else may need updating
Zammad personal API token API access as the user who generated it User profile: Profile > Token Access The connected application’s stored token
Local Zammad password Account sign-in Profile > Password & Authentication, when self-service changes are enabled Sign-in workflows using that password
Browser or device session Continued access through an existing session Profile > Devices; revoke affected sessions Users may need to sign in again on affected devices
Internal knowledge-base RSS URL Access to the internal feed through a URL containing a personal access token The RSS dialog’s revoke-and-renew control Each legitimate feed subscriber’s saved URL
OAuth client secret Authentication for a registered third-party application The identity provider’s application-registration controls; then update Zammad’s configured value The provider integration and its authentication flow

If Zammad uses an external identity provider for sign-in, that provider—not a local Zammad password field—may control the password. Confirm the configured authentication source before changing it. Zammad’s Microsoft sign-in example creates the client secret in Microsoft Entra ID and stores its value in Zammad’s third-party application settings.

Revoke and replace a Zammad personal API token

  1. Open the token owner’s profile: go to Profile > Token Access and identify the token used by the affected integration.
  2. Revoke the affected token: use the available token-management control in the deployed version. Button wording and deletion details can vary by release; follow the interface shown in your instance.
  3. Create a replacement for that application only: Zammad recommends a distinct token for each connected application so one integration can be cut off without disabling the others. See Zammad’s User Menu & Profile Settings documentation.
  4. Update the integration’s secure configuration: place the new token in the intended application’s protected secret store, not in a ticket, chat, or public issue.
  5. Verify its required API function: confirm the integration works with the intended account and permissions. A generated token cannot have more permissions than its user, so do not broaden the user’s role simply to make the replacement work; review Zammad’s permissions documentation.

Revoking a personal API token does not itself change the user’s password or end every browser/device session. Treat each path as a separate control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Change a password or end suspicious sessions when relevant

For an exposed local password

Use Profile > Password & Authentication if the instance allows users to change their own passwords. Administrators can disable that self-service option, in which case the administrator must handle the change. If authentication is delegated to an external identity provider, change the password there instead.

For a suspicious or stale device session

Open Profile > Devices, review the listed sessions, and revoke the affected ones. A password change and a session revocation address different access paths; do not assume one automatically does the other.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Reset an exposed internal RSS URL

An internal knowledge-base RSS URL contains a personal access token and functions as a credential. If it has been exposed, do not forward or paste it while troubleshooting. Open the RSS dialog, use its revoke-and-renew control, and replace the old URL in each legitimate subscriber. Zammad’s Knowledge Base documentation warns against sharing internal RSS URLs. The warning concerns internal feeds; a public knowledge-base feed is a separate option.

Rotate an OAuth client secret with its provider

A secret stored in Zammad may still be issued and revoked by another system. First identify the provider and application registration. In Zammad’s Microsoft example, create the replacement in Microsoft Entra ID, then configure its secret value in Zammad under Settings > Security > Third-party Applications, in the App Secret field. See Zammad’s Microsoft integration documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  1. Use the provider’s current controls to create or rotate the application secret and, as appropriate, revoke the exposed value.
  2. Enter the valid replacement value in the corresponding Zammad integration setting.
  3. Verify that authentication succeeds and that the integration performs its expected function.

The precise order, any overlap window, and rollback options depend on the provider’s lifecycle controls and the deployed Zammad integration. Zammad’s documentation does not prescribe a universal no-downtime cutover sequence. Follow the provider’s current instructions rather than assuming every provider supports overlapping secrets or that rotation happens inside Zammad.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Strengthen sign-in protection and review related access

Where enabled, users can configure an authenticator app or security key in Profile > Password & Authentication. Administrators can require selected roles to set up two-factor authentication after enabling at least one method. Recovery codes are one-time-use backups; regenerating them invalidates the previous set. See Zammad’s user two-factor authentication documentation and its administrator guidance for version 6.1.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Two-factor authentication adds protection to sign-in; it does not revoke an exposed API token, RSS URL, password, or OAuth secret. Administrators with the necessary permissions can also review available audit entries and manage sessions. Zammad’s permissions documentation identifies relevant controls, including audit-log access, session administration, API administration, and user password controls. It does not establish which audit events are recorded for every credential action, so do not assume a particular rotation or revocation will have a specific audit record.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.