Autorotate

Manage Credential Rotation And Delivery

Configure supported providers, send updated credentials to selected targets, and review each run.  This repository includes a web control center and native Apple and Android clients; connector support varies by provider and platform.

The current iOS release is being prepared.  The web control center and Android client can be built from source; see current app access for available downloads.

How A Rotation Works

A rotation coordinates these steps, with behavior depending on the connector and target.

  1. Lock Acquire a lock for the credential being rotated.
  2. Rotate Obtain a value through a supported provider API, local generator, or manual import.
  3. Push Deliver the value to configured targets, such as Infisical, a file, a native credential store, or an HTTPS webhook.
  4. Verify Check delivery where the connector supports verification.
  5. Commit Record the updated version after the required workflow steps succeed.
  6. Audit Append a run record to the hash-chained audit history.

Failed or partial delivery may need operator follow-up.  Providers and targets do not share a universal rollback operation.

Where Credentials Can Go

Available targets include the following; support varies by client and connector.

Credential Handling

Autorotate uses encrypted configuration and native credential stores where implemented.  A configured file target writes a credential to that file, so its permissions and backups still matter.  See the connector capability matrix for details.