Manage Credential Rotation And Delivery
Configure supported providers, send updated credentials to selected targets, and review each run. This repository includes a web control center and native Apple and Android clients; connector support varies by provider and platform.
The current iOS release is being prepared. The web control center and Android client can be built from source; see current app access for available downloads.
How A Rotation Works
A rotation coordinates these steps, with behavior depending on the connector and target.
- Lock Acquire a lock for the credential being rotated.
- Rotate Obtain a value through a supported provider API, local generator, or manual import.
- Push Deliver the value to configured targets, such as Infisical, a file, a native credential store, or an HTTPS webhook.
- Verify Check delivery where the connector supports verification.
- Commit Record the updated version after the required workflow steps succeed.
- Audit Append a run record to the hash-chained audit history.
Failed or partial delivery may need operator follow-up. Providers and targets do not share a universal rollback operation.
Where Credentials Can Go
Available targets include the following; support varies by client and connector.
- Infisical projects
- Configured files
- Apple Keychain
- Android Keystore
- Generic HTTPS webhooks
Credential Handling
Autorotate uses encrypted configuration and native credential stores where implemented. A configured file target writes a credential to that file, so its permissions and backups still matter. See the connector capability matrix for details.