Skip to content

Rotating and security

Your stream key is a password. Whoever has it can broadcast in your place, and what they broadcast goes out on your channel as if you’d put it there yourself. Treat it the same way you treat your Twitch key.

Rotate without thinking twice if:

  • The key or the publish URL has been on screen, even for a second.
  • You’ve shared the playback URL of an RTMP key (in RTMP, playback and publish are the same URL).
  • You gave it to an editor, a moderator or a mate and you don’t work together any more.
  • It’s turned up in a chat, an email, a screenshot or a shared document.
  • You see signal coming in when you aren’t broadcasting.

There’s no need to rotate “for hygiene” every week: you gain nothing and you risk going out with a misconfigured encoder.

  1. Go to Stream Keys and hit Rotate on the row.
  2. Confirm. The dashboard warns you: This action will generate a new key and the old one will no longer be valid.
  3. You’ll see Stream key rotated and the row already shows the new value.

From that moment:

  • The previous key is worthless, and it’s immediate. There’s no grace period and no overlap between the old one and the new one.
  • Your publish URL is a different one. Copy it with Publish and paste it into the encoder, or you won’t be broadcasting again (The publish URL).
  • Your playback URL is a different one too. Update it wherever you have it: your own OBS, your moderator, a player (The playback URL).
  1. Rotate the key. That’s first, and it cuts access instantly.
  2. Update your devices. Encoder, backup phone, the OBS that reads the signal.
  3. Check your control widget links. A widget link gives full control of an OBS — scenes, starting and stopping the stream, audio — without logging in. If you shared any, go to Account → Security and hit Revoke links: they stop working immediately on all your servers (The widget for your moderator).
  4. Check your platform. If what leaked was your Twitch, Kick or YouTube stream key, that one is changed in their dashboard, not here.

In the dashboard, the value of the key is blurred until you hit Show key. That protection is against the camera and against whoever is looking over your shoulder, so use it:

  • Don’t leave the Stream Keys screen shared on stream, neither with the key revealed nor with the publish URL copied and visible in a text field.
  • Be careful setting the encoder up on camera: the publish URL carries the key inside.
  • Go back over your VODs and clips before you publish them. A VOD stays there forever and the key showing up in it keeps working until you rotate it.
  • If you broadcast your desktop, don’t leave the dashboard open in a background window.