Generate a cryptographically signed Revocation Certificate for any token — useful for compliance audits. Includes token metadata, termination reason, and the identity of who revoked it.
Rotate your workspace’s signing key from Settings → Security → Signing Keys. Existing tokens remain valid until they expire — only new tokens use the new key.If a key is ever compromised, use Emergency Compromise to immediately revoke all tokens signed with that key.