Learn how to change a Hashicorp Vault root token in a step-by-step manner. The process involves generating a new root token using Recovery Keys and revoking the existing (possibly compromised) root token to secure your Vault setup. The procedure emphasizes the importance of not deleting Recovery Keys and clarifies the distinct roles of Recovery and Unseal Keys.
Table of contents
How to change (rotate) a Hashicorp Vault root tokenInitialize the generation of a new tokenProvide a quorum of Recovery Keys to generate the new tokenGenerate the root tokenRevoke the old (compromised) root tokenSort: