Not completely. A help center has one shared secret at a time, so the moment you save a new one, tokens signed with the old secret stop working.
You can keep the gap to a few moments:
Pick a quiet time for your readers.
Prepare the new secret. Either click Regenerate in Settings → Single sign-on, confirm the warning and copy the value, or create your own of at least 64 characters. The new secret doesn't take effect until you save.
Put the new secret in your server's configuration, ready to deploy.
Click Save JWT settings and deploy the new secret at the same time.
Saving a new secret signs out every reader who is signed in to the help center. On their next visit they go through your Login URL again, which is also how you end every open reader sign-in at once if a secret leaks. Sign-ins and widget requests during the gap fail, and work again as soon as your server signs with the new secret. A reader caught in the middle only needs to try again. See Troubleshoot single sign-on on the developer portal.
Comments
Be the first to comment.