← Back to parent Epic
MAZENG-FT-5 · Issue and revoke personal access tokens
Why it matters
A user needs non-password credentials for CLI or API access.
Expected outcome
Enables automation without exposing the interactive sign-in password.
In scope
- List personal access tokens with their expiry state.
- Create and copy a named personal access token.
- Rename an existing personal access token.
- Revoke an existing personal access token.
- Delivery status
IN_BACKLOG- Owner
- RootAtSkic (product lead)
- Solution approval
- PENDING
Acceptance
Acceptance outcomes
- 01
A newly created token value is disclosed once for copying and the token appears in the user's list with its expiry.
- 02
Renaming a token changes its displayed label without changing unrelated tokens.
- 03
Revocation prevents further use and removes the token from the active-token list.
- 04
Expired tokens are visibly distinguishable from active tokens.
Dependencies and risks
Dependencies
None recorded.
Risks
- Token consumption by the CLI belongs to MAZENG-EP-15 and must not be duplicated in this Feature.
- Token lifetime requires a Next Gen product and security decision; legacy tokens have a fixed 30-day lifetime.
Authoritative Architecture tasks
No authoritative Architecture tasks are linked.