All articles Product

Why keys expire every thirty days

Not to annoy you. A key with no expiry is a key you can never really lose.

Photo: ArnoldReinhold (CC BY-SA 4.0) / Wikimedia Commons

Every key issued by BuildAPI runs in a thirty-day window. On a live subscription that window rolls forward automatically and you will never notice. So why have it at all?

Because a permanent credential cannot be lost safely

If a key never expires, then a key that leaks is compromised forever, or until somebody notices and rotates it. Given how keys leak — a repository made public, a screenshot in a support ticket, a log file shipped to a third party — "until somebody notices" can be a very long time.

The window puts a ceiling on that. A key that escapes has, at worst, thirty days of life. That is the worst case, not the expected one: you can revoke immediately, and revocation is instant. The window is what happens when nobody is watching.

Because it makes lapse coherent

A subscription ending has to mean something.

If keys were permanent, ending a subscription would either kill keys instantly — cutting off a customer mid-request over a card that expired — or not at all, in which case the subscription was decorative. Neither is acceptable.

The window gives a natural, gentle boundary. The current period plays out. Dunning gets its chance: we retry, we email, we wait. Only then does the key stop, at a boundary that was always going to arrive rather than at an arbitrary moment.

Why yearly plans still use thirty-day windows

This one surprises people. If you pay for a year, why does your key run thirty days?

Because the window is a safety property, not a billing one. It rolls automatically for as long as the subscription is live. A yearly subscriber's keys roll twelve times over the year and they see nothing — but if the account is closed in month three, the exposure is still bounded by a month rather than by nine.

We got this wrong at first. Rolling was tied to the billing period, so a yearly subscriber's keys stopped on day thirty of a year they had paid for. That was a bug, and a good illustration of why these two ideas have to stay separate in the code as well as in the explanation.

What you should do about it

Nothing, if your subscription is live.

If you see expired on a key, check billing before you check anything else. The window rolls on its own; the usual cause of a key stopping is a subscription that lapsed, and the usual cause of that is a card that expired while the dunning emails went to an address nobody reads.

Which is its own lesson: keep the billing contact current. It is the address we use when something is about to break.

Start building

Lock a key to your domain in about five minutes.

Get started