Skip to content
    All stories
    Product Updates

    How to Rotate Your Nomba API Keys

    Learn how to rotate your Nomba API keys safely in just a few minutes. Follow this step-by-step guide to regenerate your test and live keys, update your systems, and keep your integration secure.

    Gloria Nnebedum
    6 August 20265 min read

    How to rotate your API keys

    Rotating your API keys on a regular schedule is one of the simplest ways to keep your Nomba integration secure. It limits how long any single credential stays in circulation, so if a key is ever exposed, the window of risk is small.

    This guide walks you through rotating your keys from start to finish. The whole process takes just a few minutes.

    Before you begin

    When you regenerate your API keys, your existing keys stop working immediately. This applies to both your test and live keys. Any system still using the old keys will start failing until you update it with the new ones.

    Because of this, a little preparation goes a long way:

    • Pick a quiet window. Rotate during a period of low traffic so fewer live requests are in flight while you swap keys over.
    • Know where your keys live. Make a quick list of every service, server, or environment that uses your Nomba keys so you can update them all without missing one.
    • Be ready to move. Have access to those systems open and ready before you regenerate, so you can drop in the new keys right away.

    Step 1: Log in to your dashboard

    Head to your Nomba dashboard and sign in with your usual credentials.

    Step 2: Open the API Keys section

    From the dashboard, navigate to the API Keys section in your settings.

    Step 3: Switch to your live keys

    By default you may be viewing your test keys. Use the toggle to switch over to your live keys.

    Step 4: Regenerate your keys

    Click Regenerate keys. A confirmation modal will appear, letting you know that your existing keys, both test and live, will become invalid once you continue.

    Read it over, and when you are ready, confirm to generate your new keys.

    Step 5: Update your systems

    Copy your new keys and update them everywhere your old keys were used. Work through the list you prepared earlier so nothing gets left behind.

    Step 6: Test and confirm

    Once everything is updated, run a few test transactions and check that your integration is behaving as expected. Confirm that payments, webhooks, and any other calls to Nomba are all going through smoothly.

    If anything looks off, double-check that every system is using the new key and that no old references were missed.

    You're all set

    That's it, your keys are rotated and your integration is running on fresh credentials. Make key rotation a regular habit, and consider doing it every three months to keep your account secure.

    If you run into any trouble, our team is always happy to help at support@nomba.com.

    Share this article

    Your business account is 3 minutes away

    Open a Nomba Business Account and take your business further.

    No setup fees • Free account • 24/7 support