Scoped credential
A key issued for one job, with only the access that job needs, that can be revoked on its own.
The alternative is a personal token, which carries everything the person can do and cannot be withdrawn from one piece of software without withdrawing it from all of them.
A scoped credential also makes the audit answerable: when something happens, you can tell which integration did it, because each one signs with something different.
Revocation is the only permission control that works after you have changed your mind, and it only works if the credential was separable in the first place.
Issuing one and never rotating it. A scoped credential left live after the software was uninstalled is a permission you believe you removed.
Related terms
See Scoped credential on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue