Rotate credentials without downtime
Create the replacement credential before revoking the current one. Clients can continue using the existing credential during the configured overlap window.
Deploy the new value to each environment, confirm successful requests, and only then complete revocation.
