-
Type:
Suggestion
-
Resolution: Unresolved
-
Component/s: Product - API
-
None
User Problem
Trello Workspace administrators (non-Enterprise) have no ability to control, restrict, or audit API token creation by workspace members. With the growing adoption of AI agents and automated integrations, any workspace member can independently create API credentials and connect external systems to Trello — potentially exposing organizational data without admin knowledge or approval.
Suggested Solutions
Workspace administrators should have the ability to:
- Disable API key/token creation for workspace members by default
- Explicitly allow API access only for selected members
- View which members have created or are actively using API credentials
- Revoke API tokens centrally when necessary
- Audit API activity associated with workspace members
This functionality currently exists at the Enterprise level (Enterprise admins can disable token creation for managed members), but is not available for Standard or Premium Workspace admins.
Current Workarounds
Currently there is no known workaround for this behavior at the Workspace (non-Enterprise) level. Upgrading to Trello Enterprise provides the ability to disable API token creation for all managed members, but this is an all-or-nothing control and does not offer per-member allowlisting, token visibility, or activity auditing.