If a unit's credential stops working — most often because it was deliberately rotated — the unit does not wipe itself and does not lose its connection. It keeps its network and asks to be re-adopted, and that request lands here.
- The unit appears in Device requests with its hardware id, firmware version and how long it has been silent.
- You check that it's the device you expect, then approve.
- The unit collects the approval the next time it asks and is issued a fresh credential automatically — nothing is typed anywhere.
- The unit comes back online, with its history intact. Nobody visits the store.
Several checks run before a request is ever shown to you, and a request that fails them is refused without troubling anyone — including a request from a unit that is currently reporting normally, which by definition cannot be the real device asking.
Read next: Device credentials, and what happens if one is lost →