Introducing Team Authorizations
- Last Updated: September 30, 2026
Team Authorizations let you create and manage API tokens and OAuth authorizations at the team and team’s resources level instead of tying them to one person’s account.
Until now, every API token belonged to an individual. When that person left the team, changed roles, or lost access, any integration, CI/CD pipeline, or automation built on their token could break without warning, and nobody else could easily see what was at risk.
Team Authorizations fixes that. Your integrations keep running no matter who’s on the team.
Two new ways to create team-level credentials
With Team Authorizations, team admins can now create two kinds of team-level credentials:
- Authorizations are long-lived API tokens created directly from the CLI or Dashboard, owned by the team instead of an individual.
- Authorized Applications are OAuth-based authorizations granted to third-party integrations, now assignable to a team during the authorization flow.
Both are managed from your Team Settings, where admins get a clear, centralized view of every token and OAuth grant tied to the team. No more hunting through individual accounts to figure out what’s connected to what.
Built for how teams actually work
Built-in continuity
Team-owned credentials aren’t tied to any one person, so your integrations keep running even as team membership changes.
Centralized visibility
Admins can see all team-owned tokens and authorized applications in one place, making audits and offboarding far simpler.
Security by default
Team tokens follow modern token best practices: a maximum one-year lifetime, and secrets are only ever shown once at creation time.
Get started with Team Authorizations
Team Authorizations are available now for every Heroku team. Learn more in our Dev Center documentation, or head to your Team Settings to create your first team-owned API token or authorized application.