Datadog API Keys: Lack of Automatic Expiration – Unresolved Least‑Privilege Rotation Decision
0 reputation · 22 Apr 2021, 18:37 UTC
Symptom
Datadog API keys are created without an expiration date and remain valid until explicitly revoked or deleted. This behavior persists across all tiers and custom RBAC roles, leaving long‑lived credentials that can be used beyond their intended lifecycle.
Goal
Determine whether Datadog plans to introduce an automated expiration or rotation workflow that enforces least‑privilege access for API keys, and understand the implications for compliance and security.
Uncertainty
Current documentation does not describe any built‑in expiration or rotation mechanism. The need to manually rotate keys creates a potential security risk, yet no roadmap or feature announcement confirms a future solution.
Questions
- Will Datadog add an automatic expiration policy for API keys in upcoming releases?
- Is there a planned rotation workflow that enforces least‑privilege on API keys?
- How does the absence of expiration impact compliance requirements for regulated environments?