A SECRET_KEY change would invalidate all API tokens as it will not be possible to decrypt them. We need a script which goes through all API tokens and reencrypt them.
This ticket becomes invalid if inveniosoftware/invenio-base#105 is implemented before.