| Create | Create a named integration in the COPE dashboard and copy the secret immediately. |
| Store | Store the full token in a server-side secret manager. Do not expose secret keys in browsers or mobile apps. |
| Rotate | Create a replacement key, deploy it, confirm traffic, then deactivate the previous key. |
| Deactivate | Deactivated keys stop authenticating within 60 seconds. Activate the key again to restore it. |
| Delete | Delete keys that are no longer needed after confirming no clients use them. A deleted key stops authenticating within 60 seconds and cannot be restored. |