just wondering what the difference is between the 2 solutions and why the old solution (which itself was the replacement for an earlier solution) was being discontinued.
the atlassian alert addressed the "when" but not the "where", "why", "how" etc
API tokens provide more granular control over the access that is granted (scoped on a per-product basis with a larger breakdown of areas to grant access in that product). They align with our other products, which use API tokens rather than App Passwords for authentication. They can also be expired, whereas our App Password implementation could not (which allows for greater control over rotation requirements).
Please let me know if you require further information.
Cheers!
- Ben (Bitbucket Cloud Support)
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.