Managing, Rotating, and Renewing Your Key

Summary

Rotate a key, renew it before it expires, change your spend cap, and what to do if it is exposed.

Body

Your Cornell AI gateway key is not permanent. This article covers rotating its secret, renewing it before it expires, changing what it can spend, and what to do if the secret leaks.

🔌 Key management needs a wired connection or the VPN

Everything here starts at https://keys.ai.business.cornell.edu/, which is only reachable on a wired Cornell connection or the Cornell VPN.

Plan ahead if you travel. If your key expires while you're away and you can't get on the VPN, Claude stops working until you can renew it. Nothing is lost — the key is still there and still renewable — but you will be without it until you're back on a Cornell connection.


If Claude suddenly stops working

Two different things look similar, and neither announces itself clearly.

A spend-cap stop, dressed up as a server problem

This is what you see first. It blames the server and invites you to retry:

The error banner reading "Server is temporarily limiting requests — Too many requests right now, try again in a moment", with View details and Try again buttons

It is not a server problem, and Try again will not help. Click View details instead, and the real cause appears:

The same banner expanded to show the detail text: API Error: Request rejected (429), Budget has been exceeded, followed by the key's current cost and its maximum budget

Budget has been exceeded! — followed by the key's current cost and its maximum. That is your monthly spend cap, and no amount of waiting clears it. Either raise the cap (see Changing your spend cap below) or wait for the monthly reset.

⚠️ Always open View details before retrying. The summary line is worded the same way for genuine, temporary rate limiting — the detail text is the only thing that tells the two apart.

An expired key

If Claude reports an authorization problem, your key has probably expired. It is still renewable — see Renewing your key below.


Rotating your key

Rotate immediately if you think your secret has been seen by anyone else.

You do not need a new key. Rotating means generating a new secret on the key you already have. There is no form to fill in again — your spend cap, KFS account, delegates, and spend history all stay exactly as they are.

⚠️ Rotating does not buy you more time. Generating a new secret leaves the expiration date untouched. If your key is also close to expiring, renewing is a separate step — see Renewing your key below.

Step 1 — Generate a new secret in the portal

  1. Go to https://keys.ai.business.cornell.edu/.
  2. Find your existing key in the list and click its row to expand it.
  3. Click Generate Key.
  4. Copy the new secret.

The new secret replaces the old one, so anything still holding the previous secret stops working — including Claude on your own computer. That is why Step 2 is not optional.

Creating a genuinely separate key — for a different budget or KFS account — is a different job, covered in Getting Your Cornell AI Gateway Key.

Step 2 — Update Claude on your computer

Your computer is still holding the old secret, so you need to hand it the new one through the same catalog you installed from.

🪟 Windows

Open Software Center, find your MD – Cornell AI Gateway – Claude entry under Applications, and click Repair. Paste the new secret when prompted.

The application details page in Software Center, showing the Uninstall and Repair buttons

Repair, not Uninstall — you are re-applying settings with the new secret, not removing the app.

🍎 Mac

Open Self Service, find Cornell AI Gateway API Key Update, and click Update. Paste the new secret when prompted.

The Cornell AI Gateway API Key Update item in Self Service, with its Update button

This is a separate item from the one you installed Claude with — you are updating the secret, not reinstalling the app.

Restart Claude afterwards and ask it something simple to confirm it works.


Renewing your key

Keys currently expire at the end of the calendar quarter — March 31, June 30, September 30, December 31 — rather than a fixed number of days after they are issued. A key created in early July therefore runs until September 30.

Keys issued in the last couple of weeks of a quarter are the exception: they roll over to the end of the following quarter, so a key created on September 25 runs until December 31 rather than expiring days after you set it up. You are not penalised for getting a key at an awkward moment.

That is the current configuration and may change, so trust the expiration date shown on your own key rather than counting forward yourself.

When it comes up, the portal renews the key you already have — no new key and no form to fill in again. Your spend cap, KFS account, delegates, and spend history all carry over untouched.

⚠️ Renewing and rotating are two different jobs. Renewing moves the expiration date. Generating a new secret does not — rotation replaces the secret and leaves the expiry exactly where it was. A key rotated a week before it expires still expires on its original date. If you need both, do both.

What you need What to do Update your computer?
More time Renew — same secret, new expiration date No — nothing on your machine changes
A new secret, because the old one may have leaked Rotate — see Rotating your key above Yes — do Step 2 of Rotating your key
Both Do each in turn; neither does the other's job Yes — because the secret changed

Renewing is the quiet one: no trip to Software Center or Self Service, and Claude carries on uninterrupted, because the secret it holds hasn't changed.

An expired key is not a lost key. Renewal still works after the expiration date has passed. There is no window you can miss and nothing to re-request — renew whenever you next reach the portal, and Claude picks up where it left off.

Whichever you do, the expiration date shown on the key afterwards is the one that applies — check it before you rely on it.

Check your expiration date now and put a reminder in your calendar a couple of weeks ahead of it — particularly if you have travel planned.


Changing your spend cap

Your key's monthly spend cap is a ceiling on what it can spend each month. It resets to zero each month — the detail panel shows the exact reset date, along with your actual spend month-to-date and for last month. Read those figures as actuals, not as the cap: the cap is what you are allowed to spend, the actuals are what you have spent.

To change it: open your key's row in the portal, type a new figure under Adjust Monthly Spend Cap, and click Save. That's the whole job — you do not need to touch Software Center or Self Service, and you do not need to restart Claude.

There is no standard figure. If you are hitting your cap regularly and the work is legitimate, raise it — the cap is there to keep spending visible and attributable to your KFS account, not to ration your usage.

Don't set it enormous, though. Gateway usage cannot be refunded, so the cap is also your only backstop against a runaway job, a leaked secret, or misuse — see Getting Your Cornell AI Gateway Key. Adjust it as your work changes rather than picking a number high enough to never think about again.

Spend History at the bottom of the panel shows all-time and quarter-to-date usage if you need to justify a higher figure.


Changing the KFS account

You can update the KFS account number from the same panel.

⚠️ This only affects future usage. Billing is locked in at the moment each request is made, so changing the account here does not re-bill anything that already happened. Correcting past billing requires a finance journal transfer — email itrequests@business.cornell.edu if you need that.


If your secret is exposed

The secret is the part that can leak — a key holds exactly one secret at a time, and rotating replaces it. So if a secret has been emailed, pasted into a shared document, posted in Teams, or otherwise seen by anyone who shouldn't have it:

  1. Rotate it. Generate a new secret on the same key, following Rotating your key above. The moment the new secret exists, the exposed one is dead.
  2. Update Claude on your computer with the new secret.
  3. Email itrequests@business.cornell.edu to let us know.

That is the whole fix. You do not need to create a replacement key, and you do not need to wait for anyone.

⚠️ Disabling is a pause, not a fix. The Disable button next to a key's status stops all use of it immediately — useful if you want spending halted right now and can't get to your computer to finish the rotation. But disabling does not change the secret: re-enable the key later and the exposed secret works again. Always rotate before you turn it back on.


Still stuck?

See Claude on Cornell's Gateway — Troubleshooting, or email itrequests@business.cornell.edu with the error message you're seeing.

Details

Details

Article ID: 9034
Created
Tue 8/4/26 4:51 PM
Modified
Thu 8/13/26 5:12 PM

Related Articles

Related Articles (5)

Create a key in the JCB AI key portal and generate its secret. Requires Ethernet or VPN.
Install the Claude Desktop pilot from Self Service on a Cornell-managed Mac and connect it with your gateway key.
Install the Claude Desktop pilot from Software Center on a Cornell-managed PC and connect it with your gateway key.
What you need before you begin, and the order to do it in: request access, get a key, then install Claude Desktop.
Choosing a model and what each one costs, working with documents and your workspace folder, and the difference between skills, connectors, and capabilities.