← Files AkinatorARCHIVED FILE

evals/results/workspaces/2026-08-26-02-repeated-question/ops/playbooks/rotate-the-signing-key.md

631 Bytes · Oct 5, 2026 · 18:32 UTC

↓ Download file

# Rotate the signing key

## When

Quarterly, or immediately on suspected compromise.

## Steps

1. Generate the new key: `python scripts/gen_key.py > keys/next.pem`
2. Publish it alongside the current key so both verify:
   `docker compose restart api`
3. Wait for the longest token lifetime - 24 hours - before removing the old key.
   Removing it early invalidates every live session.
4. Promote and remove: `mv keys/next.pem keys/current.pem && docker compose restart api`

## Rollback

Before step 4, restore `keys/current.pem` from the backup and restart. After
step 4 the old key is gone; issued tokens cannot be recovered.

SHA-256: a7a34a173ae03d38505c8a1989c1f02d5c117c0647abf9e54f943ee5ea460afd