# Can I rotate the SSO shared secret without downtime?

_Category: Domain, access and SEO_

Not completely. A help center has one shared secret at a time, so the moment you save a new one, tokens signed with the old secret stop working.

You can keep the gap to a few moments:

1. Pick a quiet time for your readers.
2. Prepare the new secret. Either click **Regenerate** in **Settings** → **Single sign-on**, confirm the warning and copy the value, or create your own of at least 64 characters. The new secret doesn't take effect until you save.
3. Put the new secret in your server's configuration, ready to deploy.
4. Click **Save JWT settings** and deploy the new secret at the same time.

Saving a new secret signs out every reader who is signed in to the help center. On their next visit they go through your Login URL again, which is also how you end every open reader sign-in at once if a secret leaks. Sign-ins and widget requests during the gap fail, and work again as soon as your server signs with the new secret. A reader caught in the middle only needs to try again. See [Troubleshoot single sign-on](https://developers.helpcenter.io/content/troubleshoot-sso) on the developer portal.

## Related articles

- [Sign readers in with your own login (JWT SSO)](https://self.helpcenter.io/content/jwt-sso)
