Chose between 90 day API keys or weekly rotation, and I picked wrong
Last week our team had to pick between two options for a partner integration: give their devs a 90 day API key or force a weekly key rotation through our gateway. I pushed hard for the 90 day key because the weekly rotation meant extra work for me, and it shipped Friday. By Monday morning someone had scraped the key off a public GitHub gist and racked up 40,000 calls before we caught it at 2am. Now I'm the guy who gets to explain to my boss why the lazy option cost us a weekend of sleep and a full key revoke scramble. How do you all handle long lived keys for third parties who won't do proper rotation?