Datadog is replacing its legacy application key authentication model with four purpose-specific credential types: Personal Access Tokens (PATs) for developers, Service Access Tokens (SATs) for automation and AI agents, Workload Identity Federation for AWS-native workloads, and OAuth clients for delegated or temporary access. Each credential type is scoped, identity-aware, and supports configurable TTLs. Application keys will remain functional after Q3 2026 but are considered legacy with no new features planned. A decision guide helps teams choose the right credential based on who is authenticating, how long access is needed, and what environment the workload runs in.

7m read timeFrom datadoghq.com
Post cover image
Table of contents
Why Datadog is updating its API authenticationIntroducing Datadog’s new API authentication modelWhat happens to application keys?How to choose the right credential for your use caseModernize Datadog API authentication
189 Impressions