Short answer: use two narrowly scoped API keys, switch traffic with an explicit activation step, and revoke the old key only after logs and live requests prove the cutover. For a property-management service, that sequence rotates a production credential without taking rent, work-order, or tenant...
Source: [Dev.to](https://dev.to/judsonrhodes1569/production-api-key-rotation-explained-6-least-privilege-checks-for-nodejs-github-actions-58oc)