API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-127 · API endpoints & versions

Contentful CMA restricts user data returned to non-admin roles

Contentful will enforce role-based CMA user responses on 14 August 2026: administrators retain full responses while non-admin users receive reduced information from the space-users and space-members endpoints.

ContentfulCMAusersspace membersrole-based response

Previous state

The affected CMA user-list endpoints returned a broader user-data response without the new role-based reduction.

Current state

Administrators continue to receive full responses while non-admin users receive limited user information from Get all users in a space and Get all Space Members.

Who needs to care

Contentful CMA integrations using tokens associated with non-admin users to fetch users or space members.

What to do

Test affected integrations with non-admin credentials, remove assumptions about unavailable fields and update response handling before enforcement.

What the source does not prove

The change applies to the two named CMA endpoints and role boundary. It does not establish that all CMA user surfaces return the same reduced payload.

Lifecycle history

Dated event sequence

  1. Breaking change published

    Contentful announced role-based user-data responses.

  2. Enforcement begins

    Non-admin users receive reduced information on the two affected endpoints.

Evidence ledger

First-party sources

  1. 01
    Contentful — Role-based changes to user data responses in the CMA

    Official API-change notice · 2026-04-13

    Open official source ↗