ST-2026-151 · Authentication & identity
Atlassian adds OAuth 2.0 two-legged credentials for service accounts
Atlassian Administration adds OAuth 2-Legged credentials as a service-account authentication option alongside API tokens in a combined credential menu.
Previous state
The service-account credential workflow exposed API-token credentials without the new OAuth 2LO option in the combined menu.
Current state
Administrators can select OAuth 2.0 or API token when creating credentials for a service account.
Affected users
Who needs to care
Atlassian Cloud organization administrators and integrations that authenticate through service accounts.
Required response
What to do
Evaluate OAuth 2LO for new or rotating service-account credentials and retain existing API-token handling unless a separately evidenced migration is chosen.
Evidence boundary
What the source does not prove
The source adds an authentication option; it does not state that existing API tokens migrate, expire, revoke or become deprecated.
Lifecycle history
Dated event sequence
- OAuth 2LO option documented
Atlassian listed OAuth 2.0 and API tokens in the combined service-account credential menu.
Evidence ledger
First-party sources
- 01Atlassian — Atlassian Cloud changes Jun 1 to Jun 8, 2026
Official Atlassian Cloud change notice · 2026-06-08
Open official source ↗