A discussion started when @Susan Hauth _Jira Queen_ raised a challenge many administrators are beginning to face:
Our developers keep asking for API tokens because they're hitting limitations with MCP and AI tools. We don't allow personal API tokens. What are others doing?
The responses quickly moved beyond MCP and into a broader conversation about security, governance, and how organizations should manage machine-to-machine access in the age of AI.
Many organizations are moving away from personal API tokens and toward service accounts with governed token management. While this introduces additional administrative overhead, it provides stronger security controls, better auditing, and clearer ownership.
Historically, developers often created personal API tokens to connect applications, scripts, and integrations. The challenge is that personal tokens:
For organizations operating in regulated industries such as finance, healthcare, and government, these concerns are increasingly driving policy decisions. As Susan explained, the issue wasn't technical capability—it was meeting security requirements.
The reality is that developers often encounter limitations with newer authentication methods. Examples raised during the discussion included:
When teams encounter those limitations, the immediate response is often:
Can I just get an API token?
From a developer's perspective, that's understandable. From a governance perspective, it's rarely the preferred solution.
Several Champions pointed to Atlassian Service Accounts as a practical middle ground. Instead of granting personal tokens, organizations can:
This creates a much cleaner security model than relying on personal credentials.
One interesting part of the discussion was how different organizations are handling scale. A common pattern emerged:
Champions mentioned tools such as:
Notably, nobody recommended storing actual tokens in Jira, Assets, or documentation systems. Instead, organizations are storing references to where credentials are managed.
The biggest concern wasn't security. It was administration.
As Susan pointed out:
The more service accounts and tokens you create, the more maintenance you inherit.
Organizations must track:
Without a governance process, service accounts can quickly become as difficult to manage as personal tokens.
Several Champions discussed using Assets to track:
Combined with automation and Rovo, organizations could potentially surface:
AI doesn't solve governance by itself, but it can help make governance more manageable.
This discussion highlighted a trend that's becoming increasingly common across enterprises - organizations aren't trying to eliminate API access. They're trying to govern it.
For many teams, the question is no longer:
Should developers have API tokens?
Instead it's:
How do we provide the access they need while maintaining security, compliance, and accountability?
Right now, service accounts paired with strong credential management practices appear to be the most common answer.
Dr Valeri Colon _Connect Centric_
1 comment