Setting the file. One moment. Rotation Monitoring · Mapbox Token Security · mapbox/mapbox-agent-skills · Skills Docs
- Token exposed in public repository
- Team member leaves with token access
- Suspected compromise or breach
- Service decommissioning
- Compliance requirements
- Every 90 days (recommended for production)
- Every 30 days (high-security environments)
- After major deployments
- During security audits
- Create new token with same scopes
- Deploy new token to canary/staging environment
- Verify functionality with new token
- Gradually roll out to production
- Monitor for issues for 24-48 hours
- Revoke old token after confirmation
- Update documentation with rotation date
- Immediately revoke compromised token
- Create replacement token
- Deploy emergency update to all services
- Notify team of incident
- Investigate how compromise occurred
- Update procedures to prevent recurrence
- API request volume per token
- Geographic distribution of requests
- Error rates by token
- Unexpected spike patterns
- Requests from unauthorized domains
- Usage from unexpected IPs/regions
- Sudden traffic spikes (>200% normal)
- High error rates (>10%)
- Requests outside allowed URLs
- Off-hours access patterns
- Not done: Review all active tokens
- Not done: Verify token scopes are still appropriate
- Not done: Check for unused tokens (revoke if inactive >30 days)
- Not done: Confirm URL restrictions are current
- Not done: Review team member access
- Not done: Check for tokens in public repositories (GitHub scan)
- Not done: Verify documentation is up-to-date
- Not done: Rotate production tokens
- Not done: Full token inventory
- Not done: Access control review
- Not done: Update incident response procedures
- Not done: Security training for team
references/rotation-monitoring.md