API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-016 · Authentication & identity

Atlassian account API tokens move to bounded expiration and older tokens age out

Atlassian now gives newly created account API tokens a one-year default lifetime and assigned expiry dates to tokens created before 15 December 2024, with that older cohort expiring between 14 March and 12 May 2026.

Atlassian CloudAPI tokenstoken expirycredential rotationREST API

Previous state

Atlassian account API tokens could remain valid without the bounded default expiry now applied to newly created tokens, including a legacy cohort created before 15 December 2024.

Current state

New tokens default to a one-year expiry and can be configured for one to 365 days; Atlassian assigned the older token cohort expiry dates that fell between 14 March and 12 May 2026.

Who needs to care

Scripts and integrations authenticating to Atlassian Cloud APIs with account API tokens, especially tokens created before 15 December 2024.

What to do

Inventory account API tokens, identify scripts still using expired or near-expiry credentials, create scoped replacement tokens with an appropriate lifetime, update secret stores, test integrations and revoke replaced credentials.

What the source does not prove

The official support page defines the default and selectable lifetime for account API tokens and the expiry window assigned to the older cohort. Organisation authentication policies can impose additional token controls, so this record does not claim every customer has an identical effective lifetime.

Lifecycle history

Dated event sequence

  1. New-token policy changed

    New account API tokens began receiving a one-year default expiry.

  2. Legacy cohort assigned expiries

    Atlassian set pre-15 December 2024 tokens to expire one year later.

  3. Legacy expiry window opened

    The earliest assigned legacy-token expiry dates took effect.

  4. Legacy expiry window ended

    The latest stated expiry date for the older token cohort passed.

Evidence ledger

First-party sources

  1. 01
    Atlassian Support — Manage API tokens for your Atlassian account

    Current official account-token policy observed · 2026-07-29

    Open official source ↗