Event-Driven Secret Refresh
You can configure Delinea Credentials Cache to use an event-driven approach to synchronize secrets in near real time. This method uses Event Pipelines in Secret Server or the Delinea Platform to notify the cache whenever a secret password changes. Rather than waiting for the time-to-live (TTL) to expire, the cache is refreshed immediately after each change.
For more information about Event Pipelines themselves, see the Secret Server documentation.
Problem Context
By default, a cached secret is served until its TTL expires (10 minutes unless you change it). If a password is rotated inside that window, applications receive the previous value until the next refresh. In some environments, background RPC processing can also experience intermittent failures, delays in secret synchronization, and limited visibility into execution status. Together these can cause Delinea Credentials Cache to operate with outdated credentials, which affects downstream integrations and applications.
Solution
To address this, Delinea provides an event-driven approach that eliminates reliance on background RPC execution. An Event Pipeline Policy watches for the Secret Password Change event and runs a PowerShell script on a Distributed Engine. The script authenticates to the cache, then calls the /api/secretchanged endpoint with the ID of the secret that changed. The cache fetches the updated secret from the vault and replaces the cached value.
Key benefits:
-
Secret updates are triggered immediately after a password change (near real-time synchronization).
-
Cache synchronization is more reliable and transparent than TTL-based expiration alone.
-
No dependency on background RPC jobs.
-
Execution status and failures are visible through Event Pipeline monitoring, which makes troubleshooting easier.
-
Scalable: every deployed cache instance can be notified independently.
How It Works
A secret password changes in Secret Server or the Delinea Platform; the configured Event Pipeline triggers automatically; a Distributed Engine executes the PowerShell script; the script calls /api/secretchanged; and the cache fetches and stores the new value. The step-by-step flow and the diagram are in Architecture.
The /api/secretchanged endpoint is part of the Credentials Cache API. When the Event Pipeline triggers, it passes the secretId through the PowerShell script to this endpoint, which then fetches and caches the updated secret. For the request and response format, see API Reference.
If Delinea Credentials Cache is deployed as several instances, each instance must be notified. Each instance then independently fetches and caches the updated secret; there is no synchronization between instances. See Architecture.
Before You Begin
Event-driven refresh requires a Distributed Engine, vault permissions to create scripts and Event Pipeline policies, and the Secret Server advanced setting that allows confidential secret fields to be used in scripts. All of these are listed in Prerequisites.
Configuration Topics
Follow the topic that matches your vault:
After configuration, confirm that the pipeline runs and the cache is updated as described in Verifying the Deployment.