API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-009 · API endpoints & versions

Google SecOps starts one-year retirement window for legacy SIEM APIs

Google Security Operations deprecated the legacy Backstory API, Customer Management API and Ingestion API on 20 July 2026, blocks legacy calls for newly provisioned instances from 26 October 2026 and will shut the endpoints down for existing instances on 20 July 2027.

Google SecOpsBackstory APIIngestion APIChronicle APIshutdown

Previous state

Custom scripts, integrations, SOAR connectors and ingestion feeds could call legacy Backstory, Customer Management and Ingestion API endpoints.

Current state

Programmatic workloads must move to Chronicle API endpoints and Google Cloud authentication; new instances lose legacy API support in October 2026 and all remaining calls fail in July 2027.

Who needs to care

Google SecOps SIEM customers, MSSPs and integration vendors using Backstory API, Customer Management API or Ingestion API calls outside the product UI.

What to do

Audit legacy endpoint use, enable and authenticate to Chronicle API, map each programmatic call to its modern equivalent, test custom integrations and feeds, and complete migration before the applicable instance cutoff.

What the source does not prove

The retirement applies to programmatic legacy SIEM API use. Google states that UI actions already use the modern Chronicle API; this record does not imply a user-interface migration or the separate SOAR Stage 2 deadline.

Lifecycle history

Dated event sequence

  1. Legacy SIEM APIs deprecated

    Google deprecated Backstory API, Customer Management API and Ingestion API in favor of Chronicle API.

  2. New-instance enforcement

    Google SecOps instances provisioned from this date no longer support legacy API calls.

  3. Full shutdown

    All requests to legacy endpoints for existing instances are scheduled to fail.

Evidence ledger

First-party sources

  1. 01
    Google Cloud Documentation — Migrate from legacy SIEM API to Chronicle API

    Official migration documentation · 2026-07-20

    Open official source ↗
  2. 02
    Google Cloud Documentation — Google Security Operations SIEM release notes

    Official deprecation release note · 2026-07-20

    Open official source ↗