Credential lifecycle
Understand active versions, renewal, overlap, replacement, reconnect, disable, and permanent revocation.
A Credential is stable while its encrypted material changes through versions. Consumers bind the stable CRN. Constal orders lifecycle changes and exposes metadata, never plaintext.
Version states
| State | Meaning |
|---|---|
| Scheduled | Material exists but is not injected |
| Active | Current material for authorized use |
| Retiring | Prior active material remains usable during overlap |
| Retired | Normal lifecycle ended and material is no longer injectable |
| Revoked | Permanently unusable; destruction is scheduled or complete |
At most one version is active. Activation moves the prior active version into retiring or retired state according to overlap policy.
Automatic renewal
A managed provider returns expiry information and defines when renewal should begin. Constal invokes the pinned provider, stores candidate material as a new version, verifies it when supported, then activates it. Provider-private refresh state advances atomically with the version.
An uncertain result is handled according to the provider's recovery contract. Single-use refresh protocols must not be blindly retried; they normally require reconnect when the outcome cannot be proven.
Confirm lifecycle changes
Activation, rotation, and revocation are complete only when the Credential's live state confirms the receipt. An activation must name the selected version as active. A revocation must show every selected version as revoked and expose the resulting active version, if one remains.
A Provider rotation may continue asynchronously. Its receipt identifies a durable rotation job; inspect that exact job until it completes, then confirm that the job's target version is active. Do not treat another rotation, an older active pointer, or a successful request alone as confirmation. Credential reads expose fingerprints, provenance, version timestamps, and job state, but never material or Provider-private refresh state.
Manual replacement
Imported Credentials use Add version. The new version starts scheduled. Activate it only after the external system accepts the value. Retire or revoke the old value according to the service's rollover behavior.
Reconnect
Interactive Credentials can start a fresh provider interaction when their grant expires, authorization changes, or refresh cannot safely continue. Reauthentication advances the same stable Credential CRN with a newly verified active version. Existing scoped bindings remain intact; changing providers or external accounts is the separate operation that may require a different Credential and an explicit binding promotion.
For a provider-managed integration, choose Manage access / Reauthorize from the connected account or reopen its setup workflow. Constal resumes an existing interaction owned by the same user, or starts a new one when no interaction is active. The old version remains usable until it expires or is explicitly revoked.
Disable versus revoke
- Disable a scoped binding to pause who can reach the Credential without destroying it.
- Disable a Resource when every invocation through that Resource must stop.
- Revoke one version when only that material is compromised.
- Revoke the entire Credential for an irreversible emergency stop.
Prefer reversible binding controls for operational pauses. Use revocation when the external authority must be invalidated permanently.
Audit and visibility
The Credential view shows status, creation method, last use, next renewal, consumers, recent use, and collapsed version history. Fingerprints correlate versions without revealing material. Lifecycle events and use records are bounded and access-controlled.