2026.09.67 — 2026-09-30
Breaking
Rotate tokens, cap their lifetime, limit their requests (198cd5e3)
- Rotation:
POST /api/v1/tokens/{id}/rotatereturns a new secret, shown once. The old secret keeps working for the rotation overlap (24 hours by default), then is rejected, and a late use of it is audited asTOKEN_REJECTED. Rotation keeps the token's grants and expiry. - Lifetime cap: tokens now live at most 90 days from creation, set in Operational configuration (API token lifetime). The cap applies live: lowering it shortens every existing token at once.
- Request limits on token requests, MCP included: 600 a minute and 8 in flight per token, and 1200 a minute per user across their tokens. Every token response carries
RateLimit-Limit,RateLimit-RemainingandRateLimit-Reset; an excess request gets 429 withRetry-After. Browser sessions are not limited. - Usage:
GET /api/v1/tokens/{id}/usage?days=1|7|30summarises requests, denials, limits and errors per day. - Administrators with the new global permission "See and revoke every user's API tokens" (
token:admin) can list every token's metadata at/api/v1/admin/tokens, revoke any token, and see tokens unused for 30 days flagged as stale.
- Rotation:
Added
Keep API token usage under the data lifecycle (920a8c80)
The hourly usage counters behind each key's usage summary are a store on the Data page, "API token usage": kept 90 days by default, and never less than 30, the longest period a summary covers.
Rotate keys, see their usage, and manage every key as an administrator (3fd8ebe7)
- Account → API keys: a new key needs an expiry within the installation's maximum lifetime, picks its permissions from the grouped permission picker, and can be restricted to named MCP tools. Each key can be rotated (the new secret is shown once, with when the old one stops working), its usage shown per day, and revoked after typing its name.
- Admin → API keys lists every user's keys with their permissions, tools, expiry and last use, flags stale ones, shows usage, and revokes any key after typing its name. It needs the "See and revoke every user's API tokens" permission.
- Operational configuration shows on/off settings as switches that save when flipped.
Add an on/off setting kind (4fe6d455)
Operational configuration can now hold a switch as well as a duration, a number or a cron expression. Plugins that contribute settings can declare one with
SettingDef.Kind.BOOLEANand read it withSettingsService.bool(key).
Fixed
Keep key tables readable and cap expiries at the stated maximum (6f7e3ecc)
A key's status reads in words (Active, Revoked, Expired) instead of a badge that was cut off in the account table, the prefix sits under the name, and a load error says its cause and the next step on separate lines. A new key's expiry never goes past the maximum the server stated, and the maximum shows in whole days.
Security
Keys cannot manage keys, and the audit keeps argument values out (accdfdb9)
/api/v1/tokens(list, mint, rotate, usage, revoke) now answers 403 to a request authenticated by an API key. Keys are managed from a signed-in session only, so a key cannot mint a broader key, escape its MCP tool allow-list, or rotate its owner's other keys.- An
MCP_TOOL_CALLaudit row records only identifying arguments (cluster, queue, address, operation and the like) by value. Every other argument, such as broker XML, setting values or message content, is recorded by name only. - A request refused by the per-user limit no longer uses up the token's own allowance.
Restrict keys to named tools, add a read-only mode, audit every call (06e72f62)
- A key can be restricted to named MCP tools when it is minted. Other tools are neither listed nor described to it, and calling one answers exactly as a tool that does not exist.
studio_helpis always available.GET /api/v1/mcp/toolslists the tools to choose from. - Operational configuration → Agent surface → Read-only stops every key from running a mutating tool, dry run or not, and hides those tools from the listing.
- Every MCP tool call, reads included, is audited as
MCP_TOOL_CALL, naming the owner, key, tool, cluster and outcome. The rows a call's own work writes are attached to it. - The server instructions a client receives now name only the tools that key is offered.
- A key can be restricted to named MCP tools when it is minted. Other tools are neither listed nor described to it, and calling one answers exactly as a tool that does not exist.
Rotate tokens, cap their lifetime, limit their requests (198cd5e3)
- Rotation:
POST /api/v1/tokens/{id}/rotatereturns a new secret, shown once. The old secret keeps working for the rotation overlap (24 hours by default), then is rejected, and a late use of it is audited asTOKEN_REJECTED. Rotation keeps the token's grants and expiry. - Lifetime cap: tokens now live at most 90 days from creation, set in Operational configuration (API token lifetime). The cap applies live: lowering it shortens every existing token at once.
- Request limits on token requests, MCP included: 600 a minute and 8 in flight per token, and 1200 a minute per user across their tokens. Every token response carries
RateLimit-Limit,RateLimit-RemainingandRateLimit-Reset; an excess request gets 429 withRetry-After. Browser sessions are not limited. - Usage:
GET /api/v1/tokens/{id}/usage?days=1|7|30summarises requests, denials, limits and errors per day. - Administrators with the new global permission "See and revoke every user's API tokens" (
token:admin) can list every token's metadata at/api/v1/admin/tokens, revoke any token, and see tokens unused for 30 days flagged as stale.
- Rotation: