API tokens
Which accounts hold API tokens, which tokens have sat unused for months, and revocation one click away.
What this tab is for. API tokens are credentials that outlive intentions: created for a script years ago, never expiring, still valid after their owner changed teams. Atlassian shows them one account at a time; this tab sweeps every managed account and lists what it finds in one table.
The sweep
Atlassian publishes no organisation-wide token listing, so the sweep asks one account at a time, through the organisation API key, as a background job you can watch — on a large organisation it takes a while, and the table says when its rows were read, because every “unused for N days” is relative to that moment. Accounts Atlassian refuses to reveal tokens for are counted and said, not silently skipped.
- Filter to the tokens that matter: unused for 90+ days, no expiry date, or sitting on a disabled account.
- Each row carries the owner, the token's label — the owner's own words for what it is for — when it was created, last used, and when it expires.
- Revoke ends the token immediately. The owner keeps their account; the credential dies. Every revocation lands in the audit log.