Infrastructure

Credential rotation

The credential rotation card provides a complete history of credential changes across your fleet. It tracks API key rotations, OAuth2 configuration updates, and time-scoped credential modifications so you can audit when and how credentials were changed.

API key changes

Every API key rotation is recorded with the timestamp, the agent affected, and who initiated the rotation. The actual key values are never stored in the audit log — only the fact that a rotation occurred is tracked.

This card tracks endpoint credential events — the credentials Tragentics injects into forwarded calls — plus MCP Connector token issuance, which is recorded as a credential event. The platform agent token (tk_...) never appears here: it is minted once at registration and cannot be rotated — its only replacement path is deleting the agent and registering a new one.

OAuth2 configuration updates

Changes to OAuth2 credentials are tracked including updates to the client ID, client secret, token URL, and scope fields. As with API keys, the actual secret values are masked — the log records that a change was made, not what the new values are.

Time-scoped credential modifications

Time-scoped access has two modes — business hours (selected days of the week with start and end hours, evaluated in a chosen timezone) and scheduled only (a window in seconds around a schedule trigger). Changes to this configuration are recorded as credential events, so the log shows when time-scoping was configured, updated, or removed on an agent — never the credential values themselves.

Outside a configured time-scope window, proxy calls to the agent are rejected before credential injection. Use this log to confirm when a window configuration changed if calls start failing unexpectedly at certain hours.

Per-agent rotation timeline

The per-agent view shows a timeline of all credential changes for a specific agent. Each credential type (API key, OAuth2, time-scoped) is shown on its own row with markers at each rotation event. This makes it easy to see the rotation frequency and identify agents that have not rotated credentials recently.

Rotation event details

FieldDescription
TimestampWhen the credential was rotated
AgentAgent name and permanent ID
Credential typeAPI key, OAuth2, or time-scoped
ActionThe recorded credential event — a credential or credential configuration was stored or updated
Rotated byUser who initiated the rotation (or "system" for automatic expirations)

Regular credential rotation is a security best practice. Use this card to audit rotation frequency and ensure no agent is using stale credentials. Agents that have not rotated credentials in an extended period may need attention.

Next

Learn how to configure protocol routing for your agents. See Configuring protocols →