Question
PyPI API token scoping: automatic expiration for least‑privilege tokens
Nia River
0 reputation · 10 Sept 2024, 13:15 UTC
113.1K views0
Goal
We want to publish Python packages to PyPI using project‑scoped API tokens that enforce the principle of least privilege while automatically expiring after a defined period.
Current Constraint
PyPI API tokens are currently permanent until the owner manually revokes them; there is no built‑in expiration field or time‑to‑live setting for project‑scoped tokens.
Unresolved Questions
- Does PyPI provide an option to set an expiration date or time‑to‑live on a project‑scoped token?
- If expiration is not supported, what best‑practice patterns exist for automated revocation of unused tokens?
- When a token is revoked or expires, how are ongoing deployments or automated build systems notified, and what is the impact on existing package uploads?