API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-018 · Authentication & identity

Atlassian SCIM API keys move from indefinite lifetime to scheduled expiry

Atlassian states that newly created or regenerated SCIM API keys expire after one year, while older keys generated before 1 January 2025 are being assigned expiries between 1 May 2026 and 1 May 2027.

Atlassian SCIMidentity provisioningAPI keyskey rotationGuard Standard

Previous state

SCIM provisioning keys could have an indefinite lifetime, including keys already used by identity providers to provision and de-provision Atlassian managed accounts.

Current state

New or regenerated SCIM keys expire after one year, and Atlassian is assigning the pre-2025 key cohort expiration dates across a May 2026 to May 2027 window.

Who needs to care

Atlassian Guard Standard organisations using SCIM provisioning, except the legacy-key rollout exclusions stated for Google Workspace and Microsoft Azure AD nested-group providers.

What to do

Check the provisioning page for each directory’s key expiry, schedule overlap rotation before the displayed date, update the identity provider immediately after regeneration, test provisioning and de-provisioning, and securely retire the old key.

What the source does not prove

The one-year rule applies when setting up provisioning or regenerating a key. Existing pre-2025 keys receive organisation-specific dates within the published window, not one universal deadline. The older-key rollout excludes Google Workspace and Microsoft Azure AD nested-group providers as stated by Atlassian.

Lifecycle history

Dated event sequence

  1. Legacy expiry rollout documented

    Atlassian described assigning pre-2025 keys expiry dates between May 2026 and May 2027.

  2. One-year lifetime active for new keys

    Atlassian’s current guidance states new and regenerated SCIM keys expire one year after creation.

  3. Legacy expiry window opened

    The earliest assigned expiry date for existing keys arrived.

  4. Legacy expiry window closes

    The latest published boundary for assigned existing-key expiries.

Evidence ledger

First-party sources

  1. 01
    Atlassian Support — Manage API key expiration for SCIM

    Current official SCIM key-expiration guidance observed · 2026-07-29

    Open official source ↗
  2. 02
    Atlassian Documentation — Atlassian Cloud changes Mar 31 to Apr 7, 2025

    Official dated rollout notice for existing keys · 2025-04-07

    Open official source ↗