Every unit authenticates with its own key, issued when it is provisioned (or, for a legacy Wi-Fi unit, when it pairs). We keep only a one-way hash of it — the key itself is never stored and cannot be shown to you again, including by us.
If a unit is stolen or you suspect its key is exposed, rotate it. The old key stops working immediately.
Rotating a key on a unit that's still installed does not require a site visit. The unit keeps its connection, notices the refusal, and asks to be re-adopted — you approve it from the dashboard and it comes back with its history intact.
Read next: Device requests →