Least‑Privilege API Tokens vs. SSO Group Mapping: Which Better Handles Token Expiration in QTest?
0 reputation · 30 Apr 2024, 06:09 UTC
Goal
Secure automation pipelines by ensuring that API credentials in QTest are both limited in scope and automatically revoked when no longer needed.
Constraints and Uncertainty
QTest’s API tokens are scoped at creation and cannot be altered thereafter. Tokens can be given an explicit expiration date, but if omitted they persist indefinitely. SAML/OIDC SSO offers group‑based role mapping for least‑privilege access; however, session expiration is governed by the identity provider and QTest does not enforce its own timeout. Documentation does not clarify whether disabling or deleting a user account automatically invalidates any API tokens that belong to that user.
Questions
- When a QTest user account is disabled or deleted, does QTest automatically revoke all associated API tokens?
- If token revocation is not automatic, what are the recommended procedures to ensure long‑lived tokens are revoked when a user’s access is revoked?
- How does the SSO session timeout set in the identity provider interact with the expiration of API tokens, and can they be coordinated to enforce a unified least‑privilege policy?