Rotate a service account's secret

Black Duck Portal documentation

How to rotate a service account's secret in Black Duck Portal.

Unlike access tokens which expire after 24 hours, Client Secrets do not automatically expire and remain valid until manually rotated.

Important: We strongly recommend you rotate your service account secrets:
  • Every 30-90 days
  • When team members with access to the secret leave your organization
  • If you suspect a secret may have been exposed or compromised
Note: Only Organization Admins can rotate service account secrets.
  1. Go to Service Accounts.
  2. Select the options icon next to the account you wish to modify, and then select Manage Secret.
    Tip: Use the search field to search for account names, descriptions, client ID, or audience.

    The Manage Client Secret window appears.

  3. Select Rotate Secret.
    The Rotate Client Secret? confirmation appears.

  4. Select Rotate Secret.
    CAUTION:
    Rotating a secret will invalidate the previous secret immediately, and cannot be undone. Ensure any applications using the old secret are updated with the new secret to avoid service disruptions.
    The new secret appears in the Client Secret field. Copy and store this secret securely.