FeatureFuel
0

Provide a way to revoke leaked personal auth tokens during offboarding

Source: getsentry/sentry#126854 · opened by @sentry-junior[bot]
Problem Statement When an organization removes a member (including through SCIM), the member's personal auth tokens remain valid. The token no longer accesses that organization's data, but it can still access the account owner's profile. If a token is known to be leaked and the former member is unreachable, the organization has no way to revoke it. This came up in an enterprise offboarding report. No customer data exposure was identified. The underlying distinction is expected today: Sentry accounts and personal tokens belong to individuals, who may belong to multiple organizations. Related: #47474 (previously closed as expected behavior) and #119786 (configurable token expiration/TTL). Request Please consider a safe way to report and revoke a known-leaked personal token without requiring the account holder to be available, while preserving the separation between an individual's Sentry account and an organization's membership. Longer term, org-managed acc…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests