AAC Docs

aac tenant api-key

AAC CLI 0.2.8MarkdownDocs 6b7d8268ba78

Plan a zero-downtime tenant API-key rotation.

Synopsis

aac tenant api-key [-h] <command> [<args>]

Commands

Command Description
aac tenant api-key list List the complete at-most-two ACTIVE key metadata set.
aac tenant api-key issue Issue and stage a second ACTIVE API key exactly once.
aac tenant api-key retire Terminally retire one exact ACTIVE key after client migration.

Arguments

Argument Type Required Default Description
-h, --help flag no — show this help message and exit

Notes

This is the planned two-ACTIVE ceremony: list the exact key ids, issue one staged second key, migrate clients, then terminally retire the chosen old key. Lost or compromised-key recovery stays aac tenant reissue-api-key.