Planned rotation
- Record the old key name, permissions, and known consumers without copying the secret into a ticket.
- Create a new key with the same or narrower required access.
- Update one environment at a time.
- Test an authenticated read and every required write operation.
- Revoke the old key after all consumers have moved.
- Confirm requests with the old key return an authentication error.

