To ensure your applications remain secure, you can periodically rotate the Client secret stored in the Kinde-side application.
You can only do this for back-end and machine-to-machine applications.
Note that you can only rotate a client secret by completely deactivating the old one. So you must update any dependent apps, connections, and services with the new secret ASAP.
- In Kinde, go to Settings > Applications.
- Select View details on the relevant application.
- Scroll to the Admin actions section.
- If you have previously retained a Client secret you’ll need to delete the previous secret first:
- Take a copy of the previous secret if you want to.
- Select Delete previous client secret.
- Select Rotate. A confirmation window opens.
- If you want, opt in to rotate the client secret and retain the old secret. You may need to upgrade plans to do this.
- If you don’t want to retain the previous secret, or you don’t want to upgrade, leave the switch off.
- Select Rotate client secret.
- Update any dependent apps, connections, and services with the new secret.