API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-125 · Authentication & identity

Zendesk phases out API-token authentication for Support APIs

Zendesk is retiring API-token authentication for Support APIs through staged deactivation, deletion and creation restrictions ending with permanent deactivation of remaining tokens on 30 April 2027.

ZendeskSupport APIAPI tokenOAuthauthentication retirement

Previous state

Support API integrations could authenticate with account API tokens, including long-lived tokens that remained available unless manually revoked.

Current state

Zendesk is phasing out API-token authentication: inactive tokens are deactivated and later deleted, new accounts cannot use tokens, new token creation stops on 27 October 2026, and all remaining tokens are permanently deactivated on 30 April 2027.

Who needs to care

Zendesk Support API integrations using API tokens for Ticketing, Help Center or Voice API requests.

What to do

Inventory token-authenticated integrations, migrate them to OAuth, rotate or remove unused credentials and complete cutover before 30 April 2027.

What the source does not prove

The retirement is bounded to Zendesk Support APIs named by the source. It does not establish removal of every credential mechanism across every Zendesk product.

Lifecycle history

Dated event sequence

  1. Retirement schedule announced

    Zendesk published the staged removal schedule and OAuth replacement.

  2. Inactive-token enforcement begins

    Tokens unused for at least 30 days are deactivated; tokens deactivated for at least 60 days are deleted; new accounts cannot create or use API tokens.

  3. New token creation stops

    Existing accounts can no longer create API tokens.

  4. Permanent deactivation

    All remaining API tokens are permanently deactivated.

Evidence ledger

First-party sources

  1. 01
    Zendesk Support — Announcing the removal of API tokens as an authentication method for API requests

    Official authentication-retirement announcement · 2026-06-01

    Open official source ↗