Rotation Type: Dual-PhaseThis rotation maintains two active credential sets with overlapping validity, ensuring zero-downtime during rotation cycles.
- The generated value is a restricted key (
rk_...), never a secret key (sk_...). If anything downstream checks the credential’s prefix, check it againstrk_. - Infisical never touches the key you already have. Rotation only creates and retires the keys it generates itself. Your original Stripe key keeps working until you manually delete it in the Stripe dashboard, once you’ve confirmed your applications are reading the rotated secret.
- Retiring a key doesn’t kill it instantly. When a key is due for retirement, Infisical expires it through Stripe, but Stripe decides when that expiration takes effect. A retired key can keep authenticating requests for a short window afterward, so don’t build anything that assumes the old key stops working the moment rotation runs.
Prerequisites
- Create a Stripe Connection. That connection is used to create and expire restricted API keys on your behalf during rotation.
Create a Stripe API key rotation in Infisical
- Infisical UI
- API
-
Navigate to your Secrets Manager Project’s Dashboard and select Add Secret Rotation from the actions dropdown.
-
Select the Stripe API Key option.
- Configure the rotation behavior, then select Continue.
- Environment - The environment the rotated secret is stored in.
- Stripe Connection - The connection that will create and expire restricted API keys during rotation.
- Rotation Interval - The interval, in days, after which a rotation is triggered.
- Rotate At - The local time of day when rotation runs once the interval has elapsed.
-
Auto-Rotation Enabled - Whether to rotate automatically on the interval. Turn off to rotate only manually or pause rotation.
- Set the Stripe API key parameters, then select Continue.
-
Key Name (optional) - The name of each key the rotation creates, as it appears in the Stripe dashboard. Infisical adds a timestamp to each name, so the old and new key stay distinct while both are valid. If you leave it empty, the name is
infisical-managed. -
Permissions - The access the generated key has to each Stripe resource. Set a resource to None, Read, or Write. Write includes read access. Stripe has no wildcard for “all access”, so grant only the resources your application uses. Use Set all to give one access level to every resource that matches your search.
- Specify the secret name that the rotated API key will be mapped to. Then select Continue.
-
API Key - The name of the secret in Infisical where the generated restricted key’s value will be stored.
- Give your rotation a name and description (optional). Then select Continue.
- Name - A slug-friendly name for this rotation configuration.
-
Description (optional) - Notes about this rotation.
-
Review your configuration, then select Create secret rotation.
- Your Stripe API Key rotation is created. The current restricted key is available as a secret at the mapped path. Each rotation creates a new key, expires the key from two rotations ago, then switches the active secret to the new key, so two keys are always valid at once for zero-downtime rotation.
Infisical only ever expires the keys it created. Your account’s existing keys,
including any key you were using before you set up this rotation, are left
alone.