Credential rotation
Update a database password (or key) without breaking sessions or losing snippets.
Database credentials should be rotated regularly — when an engineer leaves, when a key is suspected of leaking, or just on a schedule. Cocobox makes this a one-step change.
Rotate from the app
- Open the connection → Settings → Edit credentials.
- Type the new password (or upload the new key file).
- Click Test & save.
Cocobox tests the new credential against the database before persisting it. If the test fails (wrong password, account locked, etc.) the change is rolled back — your existing credential continues to work.
When the test succeeds, Cocobox:
- Encrypts the new credential and writes it to storage.
- Drains the existing connection pool — open queries finish; new queries use the new credential.
- Logs a
connection.credentials_rotatedevent in the audit log with the actor, IP, and timestamp. The previous password is never logged.
Rotate via API
Available to admin-role users:
curl -X PATCH https://api.cocobox.io/connections/123/credentials \
-H "Authorization: Bearer $JWT" \
-H "Content-Type: application/json" \
-d '{ "password": "new-secret" }'
Returns 200 on success or the test-time error on failure.
When to rotate
- A teammate with
adminrole on a connection leaves. They saw the new credential when they last logged in to your DB UI — assume it’s compromised. Rotate. - An API key with write access is revoked. The DB password didn’t leak through Cocobox, but defense-in-depth is cheap.
- Quarterly hygiene. Rotate prod credentials at least every 90 days.
- After a security event. Anything suspicious — rotate everything.
Rotation runbook for managed DBs
Most clouds let you rotate the password in their console (or via Secrets Manager) without rebooting. After updating in the cloud:
- Update the connection in Cocobox immediately.
- Watch the Recent activity panel for any failed-auth bursts that might indicate an old credential is still hard-coded somewhere.
- If errors appear, find them in the audit log by filter
result = error,error_kind = auth.