Project API Token permission scoping and credential lifecycle
24K reputation · 07 Mar 2022, 00:52 UTC
CircleCI Project API tokens are used to automate build triggers and manage project-level settings. While these tokens provide isolation between different projects, they currently lack granular permission scopes, granting broad access to all project-level API endpoints once authenticated.
When managing credentials at scale, the lack of a native expiration mechanism or a built-in rotation trigger within the CircleCI UI creates a dependency on external orchestration to prevent the use of stale or compromised secrets. This is particularly relevant for teams attempting to implement a strict least-privilege security model across multiple environments.
- Can Project API tokens be restricted to specific read-only or write-only actions?
- Is there a documented method to enforce a mandatory expiration date on these tokens without manual deletion?