Granular API key permissions for password and OTP visibility

API keys currently only offer a single "view passwords" permission, which also grants access to OTPs. There's no way to grant access to one without the other.

Request

Split this into two separate permissions on API keys:

View passwords – grants access to stored passwords only

View OTPs – grants access to OTP codes only

This lets admins scope API keys more tightly, for example, issuing a key that can pull passwords for an integration without also exposing OTPS.

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board

Core Web App

Tags

Security & credentials

Subscribe to request

Get notified by email when there are changes.