Werk #22270: View and revoke OAuth access tokens
| Component | Setup | ||||
| Title | View and revoke OAuth access tokens | ||||
| Date | Sep 24, 2026 | ||||
| Level | Prominent Change | ||||
| Class | New Feature | ||||
| Compatibility | Compatible - no manual interaction needed | ||||
| Checkmk versions & editions |
|
Checkmk now lets you review and revoke OAuth access tokens directly in the GUI.
Every user can see and revoke their own tokens under User > OAuth access tokens, next to Two-factor authentication. This lists every application currently authorized to access the API on the user's behalf.
Administrators (Pro edition and above) additionally get Setup > General > OAuth access tokens, which lists every token issued to any user on the site. Client IDs resolve to the registered application's name, and known resources such as MCP get a friendly label instead of the raw URL.
Revoking a token takes effect immediately, the application holding it must re-authorize before it can access the API again.