Support scoped API keys to suspend/restore access

XMLWordPrintable

    • 4

      Atlassian has released endpoints that allow customers to suspend or restore users' access to a given site, but these endpoints can currently only be called (successfully) when using an API key without scopes to authenticate:

      While this may be acceptable to some customers, it's a non-starter for more security-minded customers who want to avoid using API keys without scopes due to the massive set of permissions associated with them.

      • Specifically, many Enterprise customers are unwilling to use API keys without scopes due to the potential security implications in the event that such an API key is ever compromised.

      Please prioritize supporting scoped API tokens for these two endpoints ASAP to help unblock basic user management tasks at scale for Atlassian's Enterprise customers.

              Assignee:
              Unassigned
              Reporter:
              John A [Atlassian Support]
              Votes:
              3 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: