Add ability to manually add API accounts when SSO is enabled.
Connor Blake
Would like the ability to create an API-only account when SSO is enforced
F
Finn Goodwin
Would be great to see some movement on this. As I see it there are two primary issues here:
- Lack of manageability/visibility for any API account that's used by an integration or shared with multiple users
- Security issues due to the key always having the same access as the user, so for instance as a full admin any API key I create will have that same access with no way to limit it. Being able to create API keys that are limited to a subset of the users permissions would be very helpful and seems like a basic best-practices item.
Mark Porter
Agreed, also the ability to adjust permissions in a more granular way. I believe currently that the API key takes on the same permissions as the user.