Blog

New Capability: Personal Access Token Management for Admins

Author

  • Sesche2

    SailPoint

This new capability is brought to you by Aha! Idea GOV-I-3838

Description

To further improve security around personal access tokens (PATs), we have added the ability for admins to see and manage all of the PATs in their environment, not just ones they have created. Admins can view tokens, edit them, and change their expiration dates. Tokens can be modified individually, or in bulk.

Problem

Before this release, admins could only view and manage personal access tokens they created. This left them unable to see any integrations or API access client IDs being created by another user and when making a change to a token they did not create, required them to identify the user, contact that user, and walk them through the required changes. This opened potential security risks, and made it impossible for admins to completely manage all aspects of their environment.

Solution

With this release, we have added a new screen under Admin → Security Settings → Personal Access Tokens to let admins see all of the tokens in their environment. They can also edit them, and change expiration dates. Changes can be made on individual tokens, or on several tokens at once. A new API, Bulk update PAT expiration API has also been added to let admins manage PATs programmatically as well.

Who is affected?

ISC Admins.

Action required

IMPORTANT: To further improve security, with this release any Personal Access Tokens created before we released the PAT expiry support on February 5, 2026, that has not had an expiration date added or removed, will automatically be assigned an expiration date 6 months (180 days) from the release date of this new admin management feature. Admins can use the new feature to edit or remove (not recommended) those new expiration dates. Any tokens created after February 5, 2026 will not be changed.

Important dates

Sandbox availability: 7/21/2026
Production rollout: 7/28/2026

To ask questions and learn more please visit the Developer Community.