Blog

Update: Search API Access for Help Desk Users

Author

  • Sesche2

    SailPoint

What is Changing

We have updated API enforcement to ensure Help Desk users do not have access to the Search API. This matches our published User Level Access guidance: Help Desk is intended for operational tasks (for example, finding identities to support account resets), not for broad Search API use.

Why We Made This Change

This update closes a rare gap between documented access and actual API behavior and strengthens least-privilege access in line with our security and compliance practices.

When This Applies

The change was deployed in stages: staging on March 26 and production on March 30, 2026. Integrations or scripts that call Search using Help Desk credentials may stop working or return authorization errors from that date forward in production.

Who May Be Affected

You may be impacted if your integration uses a Help Desk user token to call the Search API (for example, to look up identities or attributes). Configurations that already follow the documented paths below are unaffected in intent; those that relied on Search under Help Desk may need a small change.

What You Should Do — Supported Options

Use one of these approaches, depending on your needs:

  1. Identities API (recommended for listing/searching identities within documented Help Desk access) - Use the List Identities API as documented:
    list-identities | SailPoint Developer Community
  2. Admin UI - Help Desk users can locate identities via Admin → Identities → Human Identities (including the search capability in that experience), consistent with prior guidance.
  3. Personal Access Token (PAT) with Search read scope - If your automation must use the Search API, use a token that is explicitly authorized for that scope—for example, a PAT that includes sp:search:read—and update your integration to use that token instead of Help Desk credentials for Search.
  4. API client with Search read scope - Alternatively, configure an API client with sp:search:read (and any other scopes your integration requires). Obtain access tokens using that client (for example client credentials or refresh token, depending on your setup; authorization code is also supported where applicable).

Documentation

We are updating developer documentation to reflect that Help Desk users no longer have access to the Search API; the live developer site will be updated when that publish completes.

To ask questions and learn more please visit the Developer Community.