API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-070 · Enforcement & amendments

Atlassian extends PAT migration where platform capability is missing

Existing Marketplace apps blocked by missing platform capability can use an ECOHELP-managed extension beyond the Q2 2026 PAT deadline, while new submissions must comply.

Atlassian Marketplacepersonal access tokenssecurity policyextension

Previous state

Existing apps were expected to stop collecting, transmitting or storing Atlassian user PATs by the end of Q2 2026.

Current state

Accepted capability blockers extend the migration window through ECOHELP while Atlassian completes the missing platform work.

Who needs to care

Existing Marketplace apps whose required capability remains available only through PAT.

What to do

Document the blocker, engage through ECOHELP and maintain a migration plan; new submissions must already comply.

What the source does not prove

The extension is not a blanket waiver and is bounded to accepted apps, blockers and dates.

Lifecycle history

Dated event sequence

  1. Original Q2 boundary

    Conditional extensions apply where Atlassian accepts a missing-capability blocker.

Evidence ledger

First-party sources

  1. 01
    Atlassian Developer — Marketplace security enforcement policy

    Official Marketplace policy · 2026-06-30

    Open official source ↗