ST-2026-018 · Authentication & identity
Atlassian SCIM API keys move from indefinite lifetime to scheduled expiry
Atlassian states that newly created or regenerated SCIM API keys expire after one year, while older keys generated before 1 January 2025 are being assigned expiries between 1 May 2026 and 1 May 2027.
Previous state
SCIM provisioning keys could have an indefinite lifetime, including keys already used by identity providers to provision and de-provision Atlassian managed accounts.
Current state
New or regenerated SCIM keys expire after one year, and Atlassian is assigning the pre-2025 key cohort expiration dates across a May 2026 to May 2027 window.
Affected users
Who needs to care
Atlassian Guard Standard organisations using SCIM provisioning, except the legacy-key rollout exclusions stated for Google Workspace and Microsoft Azure AD nested-group providers.
Required response
What to do
Check the provisioning page for each directory’s key expiry, schedule overlap rotation before the displayed date, update the identity provider immediately after regeneration, test provisioning and de-provisioning, and securely retire the old key.
Evidence boundary
What the source does not prove
The one-year rule applies when setting up provisioning or regenerating a key. Existing pre-2025 keys receive organisation-specific dates within the published window, not one universal deadline. The older-key rollout excludes Google Workspace and Microsoft Azure AD nested-group providers as stated by Atlassian.
Lifecycle history
Dated event sequence
- Legacy expiry rollout documented
Atlassian described assigning pre-2025 keys expiry dates between May 2026 and May 2027.
- One-year lifetime active for new keys
Atlassian’s current guidance states new and regenerated SCIM keys expire one year after creation.
- Legacy expiry window opened
The earliest assigned expiry date for existing keys arrived.
- Legacy expiry window closes
The latest published boundary for assigned existing-key expiries.
Evidence ledger
First-party sources
- 01Atlassian Support — Manage API key expiration for SCIM
Current official SCIM key-expiration guidance observed · 2026-07-29
Open official source ↗ - 02Atlassian Documentation — Atlassian Cloud changes Mar 31 to Apr 7, 2025
Official dated rollout notice for existing keys · 2025-04-07
Open official source ↗