ST-2026-127 · API endpoints & versions
Contentful CMA restricts user data returned to non-admin roles
Contentful will enforce role-based CMA user responses on 14 August 2026: administrators retain full responses while non-admin users receive reduced information from the space-users and space-members endpoints.
Previous state
The affected CMA user-list endpoints returned a broader user-data response without the new role-based reduction.
Current state
Administrators continue to receive full responses while non-admin users receive limited user information from Get all users in a space and Get all Space Members.
Affected users
Who needs to care
Contentful CMA integrations using tokens associated with non-admin users to fetch users or space members.
Required response
What to do
Test affected integrations with non-admin credentials, remove assumptions about unavailable fields and update response handling before enforcement.
Evidence boundary
What the source does not prove
The change applies to the two named CMA endpoints and role boundary. It does not establish that all CMA user surfaces return the same reduced payload.
Lifecycle history
Dated event sequence
- Breaking change published
Contentful announced role-based user-data responses.
- Enforcement begins
Non-admin users receive reduced information on the two affected endpoints.
Evidence ledger
First-party sources
- 01Contentful — Role-based changes to user data responses in the CMA
Official API-change notice · 2026-04-13
Open official source ↗