Rotate your keys
Rotate the organization key if your widget is loading somewhere it shouldn't, and the signing secret if it leaked. Each one breaks something different.
Settings → Keys holds two keys. Only owners can rotate them, and each rotation breaks something until you update it.
| Organization key | Signing secret | |
|---|---|---|
| Starts with | pk_ |
sk_ |
| Lives in | Your page's HTML. It's public | Your server. It's private |
| Who can see it | Everyone on your team | Owners only |
| Rotate it when | Someone is loading your widget on a site you don't want | It leaked into a repository, a log or a browser |
| What breaks | Every install still using the old key stops loading at once | Every signature made with the old secret stops verifying |
| What to update | data-organization in your script tag, everywhere it's installed |
The secret in your server's configuration |
Rotating the organization key
Press Rotate beside it and confirm. Your widget is down from that moment until the new key is deployed, so have the change ready first.
Owners can also rotate it with POST /api/v1/organization/public-key/rotate, so a deploy script can rotate and ship the new key in one go.
Rotating the signing secret
Press Rotate beside it and confirm. This one only works from the dashboard.
Until your server has the new secret, new visitors arrive as self-declared instead of verified. Nothing errors and nobody is locked out. They lose the check mark until your server signs with the new secret. Anyone already verified in the browser they're using stays verified.
Neither one is an agent key
Agents use their own access keys from Settings → API & MCP. If one of those leaks, revoke that agent there. The two keys on this screen can't read your inbox.