## How do I rotate or revoke my Dwolla API key and secret?

- Jul 22, 2025
- Knowledge

### Information

A Dwolla API key and secret are required for generating a secure token that is used to authenticate requests to the Dwolla API from your application.

Developers may need to periodically rotate their Dwolla API key and secret as a security best practice or generate a new API key and secret if their current credentials become compromised.

To rotate your API key and secret, navigate to [https://dashboard.dwolla.com/applications-legacy](https://dashboard.dwolla.com/applications-legacy) and click the button to create a new application.

- Once created, notify Dwolla support to activate new credentials for production use.
- [Create a new webhook subscription](https://docs.dwolla.com/#create-a-webhook-subscription) for the new application.
- Immediately [delete](https://docs.dwolla.com/#delete-a-webhook-subscription) [webhook subscription](https://docs.dwolla.com/#delete-a-webhook-subscription) from your old application using previously issued API key and secret.
- Notify Dwolla to suspend old application credentials or delete the old application within the Dwolla Dashboard.

URL Name

How-do-I-rotate-or-revoke-my-Dwolla-API-key-and-secret
