You can change an application’s using the or the Auth0 . When you rotate a client secret, you must update any authorized applications with the new value.
New secrets may be delayed up to thirty seconds while rotating. To minimize downtime, we suggest you store the new client secret in your application’s code/system configuration as a fallback to the previous secret. This way, if the client application request doesn’t work with the old secret, your app will use the new secret.Secrets can be stored in a list (or similar structure) until they’re no longer needed. Once you’re sure that an old secret is obsolete, you can remove its value from your app’s code.
Call the Management API Rotate a client secret endpoint. Replace the YOUR_CLIENT_ID and MGMT_API_ACCESS_TOKEN placeholder values with your client ID and Management API access token, respectively.
You can use the Management API Update a client endpoint to to set a client secret manually instead of requesting a rotation to an automatically generated secret. Your application is configured with the future secret as a fallback ahead of the actual rotation.