ST-2026-125 · Authentication & identity
Zendesk phases out API-token authentication for Support APIs
Zendesk is retiring API-token authentication for Support APIs through staged deactivation, deletion and creation restrictions ending with permanent deactivation of remaining tokens on 30 April 2027.
Previous state
Support API integrations could authenticate with account API tokens, including long-lived tokens that remained available unless manually revoked.
Current state
Zendesk is phasing out API-token authentication: inactive tokens are deactivated and later deleted, new accounts cannot use tokens, new token creation stops on 27 October 2026, and all remaining tokens are permanently deactivated on 30 April 2027.
Affected users
Who needs to care
Zendesk Support API integrations using API tokens for Ticketing, Help Center or Voice API requests.
Required response
What to do
Inventory token-authenticated integrations, migrate them to OAuth, rotate or remove unused credentials and complete cutover before 30 April 2027.
Evidence boundary
What the source does not prove
The retirement is bounded to Zendesk Support APIs named by the source. It does not establish removal of every credential mechanism across every Zendesk product.
Lifecycle history
Dated event sequence
- Retirement schedule announced
Zendesk published the staged removal schedule and OAuth replacement.
- Inactive-token enforcement begins
Tokens unused for at least 30 days are deactivated; tokens deactivated for at least 60 days are deleted; new accounts cannot create or use API tokens.
- New token creation stops
Existing accounts can no longer create API tokens.
- Permanent deactivation
All remaining API tokens are permanently deactivated.
Evidence ledger
First-party sources
- 01Zendesk Support — Announcing the removal of API tokens as an authentication method for API requests
Official authentication-retirement announcement · 2026-06-01
Open official source ↗