Skip to main content

MAZENG-FT-5 · Issue and revoke personal access tokens

Feature intent

A user needs non-password credentials for CLI or API access.

Why it matters

A user needs non-password credentials for CLI or API access.

Expected outcome

Enables automation without exposing the interactive sign-in password.

In scope

  • List personal access tokens with their expiry state.
  • Create and copy a named personal access token.
  • Rename an existing personal access token.
  • Revoke an existing personal access token.
Delivery status
IN_BACKLOG
Owner
RootAtSkic (product lead)
Parent Epic
MAZENG-EP-1
Solution approval
PENDING

Acceptance

Acceptance outcomes

  1. 01

    A newly created token value is disclosed once for copying and the token appears in the user's list with its expiry.

  2. 02

    Renaming a token changes its displayed label without changing unrelated tokens.

  3. 03

    Revocation prevents further use and removes the token from the active-token list.

  4. 04

    Expired tokens are visibly distinguishable from active tokens.

Dependencies and risks

Dependencies

None recorded.

Risks

  • Token consumption by the CLI belongs to MAZENG-EP-15 and must not be duplicated in this Feature.
  • Token lifetime requires a Next Gen product and security decision; legacy tokens have a fixed 30-day lifetime.

Authoritative Architecture tasks

No authoritative Architecture tasks are linked.

Original source