-
Suggestion
-
Resolution: Unresolved
-
None
-
None
-
1
-
3
-
Summary
Provide an option for global administrators to allow the creation of "Never Expire" (Eternal) Personal Access Tokens (PATs) for specific users or tokens, even when the global setting to disable such tokens is applied to the rest of the users.
Expected Results
Global administrators should have the ability to designate certain users who can create "Never Expire" tokens, ensuring that applications relying on these tokens can function without disruption while maintaining overall security and control over token generation for the rest of the user base.
Ideally it would be possible for the admin to set specific tokens non-expiry via the Administering personal access tokens page.
That is including the scenario where the following property is set to false:
-Datlassian.pats.eternal.tokens.enabled |
Rationale
By implementing this feature, Jira can maintain a balance between security and user needs. Some users or applications may have legitimate use cases for needing tokens that do not expire, and allowing administrators to selectively enable this feature would prevent misuse while supporting essential integrations.
- is related to
-
JRASERVER-71850 Fine grained permissions for Personal Access Tokens
- Gathering Interest
-
JRASERVER-71852 Better control who can generate Personal Access Tokens
- Gathering Interest
-
JRASERVER-77688 As a Jira administrator I would like to configure which paths are allowed to be accessed with personal access tokens
- Gathering Interest