API tokens will now have a maximum one‑year expiry

I got an email.

 

We're contacting you about an upcoming change to the API token default expiry duration. Currently, an API token has an infinite duration when created. To increase admin control over token management and your organization's security posture, all new API tokens will have a default one‑year expiry from the date of creation.

 

 

What's changing?

 

 

From December 15, 2024, new API tokens created by users will have a configurable duration of up to one year.

 

 

*Note: This does not affect existing API tokens. 

 

What do you think, will there be any impacts of this change with respect to where you have integrations built using API tokens.

 

Vijay

9 comments

Yatish Madhav
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 26, 2024

Thanks for the article @Vijay Dadi 

I looked at the documentation link in the email - https://support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/ - and it does not look to have been updated yet it seems. I would expect it to mention this deadline and the change on there.

My first thoughts are that that is great - it instils better security in many peoples minds. I am also happy about the "Note: This does not affect existing API tokens" as we have about between 5 to 10 that are setup already.

What we do is we create recurring tasks for cases like this for me and our admins to manage so that we do not hit expiry unexpectedly.

Thanks again

Vijay Dadi
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 26, 2024

@Yatish Madhav ,

I agree, me myself built many automations/integrations with API tokens using service accounts. But I am happy that it will not affect existing tokens. This will new annual task for the admins.

Vj

Like Yatish Madhav likes this
Michael Aglas
Contributor
December 2, 2024

this is a nightmare

Jakub Wagner January 27, 2025

OMG. Why?!

Andrew Daniels
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
February 16, 2025

 

For such API keys in scope that this applies to, can they be renewed before the expiration date to avoid disruption\?

Alin Faur
Contributor
February 18, 2025

It looks like Atlassian have reviewed this change and are extending it to all existing tokens that don't yet have an expiry date.

However we only got this notification via e-mail and I was not able to find a related announcement article on Atlassian's website.

This will be hard on the service accounts that we currently use :-(

Like Yatish Madhav likes this
Mark B Wager
Contributor
February 18, 2025

Respectfully,

This is REALLY going to IMPACT us.  We have many service accounts used in various systems throughout our company to allow input/output to Jira. This introduces a LOT of overhead.

Making them EXPIRE in ONE YEAR is NO BUENO!  

At the very least, we should have the ability to REVIEW and EXTEND the tokens for our accounts WITHOUT having to REPLACE them. 

As an admin, I have no way to know who is using tokens and where. So, I have no way to keep our specific users informed.

MAKING ATLASSIAN PRODUCTS HARDER TO USE/MAINTAIN IS NOT A GREAT ADOPTION/RETENTION MOVE.

Please reconsider.

Thanks,

Mark

Like Alin Faur likes this
Lizeo IT
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
February 18, 2025

Hi,
Is there a workaround or a way to get notified when a token is about to expire?
Manually checking the dashboard is a bit inconvenient. It would be great if this feature could be implemented.
Thanks!

Like # people like this
David Bakkers
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
February 24, 2025

This is great news!

Competent Sys Admins will finally be able to create limited lifespan service account tokens for third parties to use for performing work for short durations, secure in knowing the token becomes useless at the end of the period.

This will also bolster basic security principles, as every moderately competent Sys Admin knows to NEVER create service accounts that have immutable, permanent passwords, as that goes against many well known security principles.

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events