Rotate a license key safely
Rotation replaces your POM AI key with a new one and invalidates the old one immediately, everywhere. It is the correct response to a key you believe has been exposed — and it is disruptive by design, so it is worth preparing before you press the button.
When to rotate
Rotate when the key may be in hands that should not have it:
- it was pasted into a ticket, chat, email or shared document;
- a contractor or employee with access to it has left;
- a site holding the key was compromised, or handed to someone else without unlinking;
- a domain you do not recognise appears in your authorized domain list;
- the usage log shows consumption you cannot account for.
Do not rotate for routine hygiene on a schedule. Every rotation means visiting every site that holds the key, and a rushed rotation leaves sites broken.
What rotation does
- A new key is generated for the same license.
- The previous key stops working immediately, on every site at once.
- Your subscription, plan, credit balance and authorized domains are unchanged.
- The new key is shown once, on screen, so you can copy it.
Rotation is not a way to remove a domain's authorization. The authorized domains survive; only the credential changes. To stop a specific site, remove its domain as well — see Remove an authorized domain.
Prepare first
- List every site holding the key. The authorized domain list in My Account → POM AI Management is the best starting point, but check it against your own records: a site can hold the key without currently being authorized.
- Confirm you can administer each one. A site you cannot reach will stop working and stay stopped.
- Check nothing long-running is in progress. Finish or postpone bulk translations and bulk metadata runs.
- Choose a quiet window. Every site is without AI between the rotation and its own update.
- Decide where the new key will live. Ideally a password manager, and nowhere else.
Rotate
- Sign in to account.pom.es as the license owner.
- Open My Account → Licenses & Downloads.
- On the POM AI card, select Rotate key.
- Read the confirmation — it warns that rotating generates a new key and immediately invalidates the current one on all your sites — and accept.
The new key is then displayed in full with a Copy button, and a notice confirms that the previous key stopped working immediately and that you should update it on your sites.
Copy it now. Once you leave the page it returns to masked form, and you would need Reveal key to see it again.
Update every site
For each site, in whatever order suits you:
- Open Settings → POM AI → License.
- Paste the new key.
- Select Replace and validate.
- Confirm the panel shows a valid status and the site's own host on the Domain line.
The new key is validated before it replaces the stored one, so a paste error produces an error message rather than a worse state.
On multisite, remember that each subsite holds its own copy. The network key on the main site and every subsite key that used the rotated license all need updating. See Configure POM AI on WordPress multisite.
While the rotation is in progress
Sites that have not yet been updated will fail authorization. Expect:
- AI operations refused;
- the credit balance failing to load on the License tab;
- a license warning in the administration of affected sites.
None of this damages anything. The sites recover as soon as they hold the new key. Content already generated is unaffected throughout.
Afterwards
- Verify every site. Run one small AI operation on each, and check the balance moves.
- Check updates still work. On multisite, confirm the main site's network key was updated, or updates will stop for the whole network. See Understand the network license used for updates.
- Review the authorized domains. Rotation is the natural moment to remove hosts that should no longer be there.
- Review the usage log for the period before rotation, so you know what the exposed key was used for.
- Delete the old key from wherever you found it exposed. It no longer works, but it should not linger in a document either.
Reducing the need to rotate
- Send keys through a password manager rather than email or chat.
- Give client sites their own subscriptions instead of sharing yours.
- Unlink a site's license when you hand it over, rather than leaving your key on it.
- Never store the key in version control, a deployment script or a shared spreadsheet.
The key is a spending credential. Treat it the way you would treat one.