How to rotate alert destination credentials
Last updated: July 8, 2026
Slack / Slack Bot
Bot token: Slack app → OAuth & Permissions → Revoke All OAuth Tokens, then reinstall the app to your workspace to issue a new token.
Signing secret: Slack app → Basic Information → App Credentials → Signing Secret → Regenerate.
Client secret: Slack app → Basic Information → App Credentials → Client Secret → Regenerate.
Update your Panther Slack destination with the new credentials.
Re-invite the Panther app to the channel: /remove @panther then /invite @panther.
Jira Cloud
Revoke the token:
Cloud: revoke the API token at id.atlassian.com → Account settings → Security → API tokens, then create a new one.
Data Center: revoke the personal access token under your Profile → Personal access tokens, then create a new one.
Update the Panther Jira destination with the new token.
Asana
In Asana, go to your profile → My Settings → Apps → Manage Developer Apps to open the developer console; deauthorize the existing personal access token and create a new one.
Update the Panther Asana destination with the new token.
Opsgenie
Open the Panther API integration (Settings → Integrations, or your team's Integrations page) and regenerate its API key. For account-level keys, use Settings → App Settings → API Key Management → Regenerate.
Update the Panther Opsgenie destination with the new key.
PagerDuty
Services → Service Directory → select the Panther-connected service → Integrations tab → Edit Integration → Generate a new integration key → Save.
Update the Panther PagerDuty destination with the new integration (routing) key.
Discord
Server Settings → Integrations → Webhooks → delete the Panther webhook and recreate it to issue a new URL (this invalidates the old token).
Update the Panther Discord destination with the new webhook URL.
GCP Pub/Sub
IAM & Admin → Service Accounts → select the service account → Keys → Add Key → Create new key (JSON).
Update the Panther Pub/Sub destination with the new key, confirm delivery, then delete the old key.
Microsoft Teams
In Power Automate, go to My flows -> select your existing flow -> click ··· -> choose Save As to create a duplicate.
Open the new copy's trigger step ("When a Teams webhook request is received") -> copy the new HTTP POST URL.
In Panther, edit your existing Microsoft Teams destination (Configure -> Alert Destinations) and replace the Webhook URL field with the new URL. This preserves your existing Severity, Alert Types, and Log Type configuration.
Once confirmed, delete the original Power Automate flow so the previous webhook URL is no longer active.
Custom / third-party webhooks
Rotate the bearer token, basic-auth credential, and/or signing secret at the receiving system.
Update the corresponding secret (and URL, if changed) in the Panther destination.