Skip to content

A collector token leaked — what to do

Each collector has its own token, scoped to that one box. If a collector is compromised, lost, or you can no longer reach it, you don't need to disturb the rest of the fleet — revoke just that collector.

Revoke one collector

On Collectors, open the collector and Revoke it (or use Bulk revoke offline to clear several dead ones at once). Revocation is immediate: that collector's token stops working for ingest and status right away, and it can't inspect traffic anymore.

To bring a replacement online, add a fresh collector (Collectors → Add collector) and run the installer on the host — see Install a collector. The new box enrolls with its own token and lands in pending approval.

What's not affected

Revoking a collector leaves your policy rules, identity mappings, and audit history untouched — they live in the cloud, not on the collector.

Bigger compromise

If you believe your whole workspace is compromised (not just one collector), contact Kilasec — full tenant-token rotation is handled on the Kilasec side so it can be coordinated with re-enrolling every collector without a silent outage.

→ For a collector that's merely unreachable rather than compromised, start with Collector is offline.

Documentation for kilasec — the AI Agent Firewall.