Credential rotation

Update a database password (or key) without breaking sessions or losing snippets.

Last updated

Database credentials should be rotated regularly — when an engineer leaves, when a key is suspected of leaking, or just on a schedule. Cocobox makes this a one-step change.

Rotate from the app

  1. Open the connection → Settings → Edit credentials.
  2. Type the new password (or upload the new key file).
  3. Click Test & save.

Cocobox tests the new credential against the database before persisting it. If the test fails (wrong password, account locked, etc.) the change is rolled back — your existing credential continues to work.

When the test succeeds, Cocobox:

  1. Encrypts the new credential and writes it to storage.
  2. Drains the existing connection pool — open queries finish; new queries use the new credential.
  3. Logs a connection.credentials_rotated event in the audit log with the actor, IP, and timestamp. The previous password is never logged.

Rotate via API

Available to admin-role users:

curl -X PATCH https://api.cocobox.io/connections/123/credentials \
  -H "Authorization: Bearer $JWT" \
  -H "Content-Type: application/json" \
  -d '{ "password": "new-secret" }'

Returns 200 on success or the test-time error on failure.

When to rotate

  • A teammate with admin role on a connection leaves. They saw the new credential when they last logged in to your DB UI — assume it’s compromised. Rotate.
  • An API key with write access is revoked. The DB password didn’t leak through Cocobox, but defense-in-depth is cheap.
  • Quarterly hygiene. Rotate prod credentials at least every 90 days.
  • After a security event. Anything suspicious — rotate everything.

Rotation runbook for managed DBs

Most clouds let you rotate the password in their console (or via Secrets Manager) without rebooting. After updating in the cloud:

  1. Update the connection in Cocobox immediately.
  2. Watch the Recent activity panel for any failed-auth bursts that might indicate an old credential is still hard-coded somewhere.
  3. If errors appear, find them in the audit log by filter result = error, error_kind = auth.