Pulumi Cloud now lets organization admins enforce a maximum expiry cap (in days) on personal, organization, and team access tokens. Tokens without an expiration or with remaining lifetime exceeding the cap are rejected with a 403 error. The policy applies to existing tokens based on remaining lifetime rather than original creation date. A preview tool shows which tokens would be affected before the policy is saved, enabling safe rollouts. Web console sessions and OIDC-issued short-lived tokens are exempt.
121 Impressions