The practice of periodically replacing API keys or signing keys with new ones. Regular key rotation limits the damage from a compromised credential. Nomotic supports key rotation without downtime — create a new key, update your integration, then revoke the old one.