NuGet.org is reducing API key maximum lifetime to 30 days starting August 17, 2026, with all keys created before that date expiring on November 1, 2026. The change is motivated by supply chain attacks where long-lived credentials were stolen and used to publish malicious packages. The recommended alternative is NuGet Trusted Publishing, which uses OIDC to issue short-lived, automatically expiring credentials without requiring stored secrets in CI/CD systems. For those who must continue using API keys, best practices include narrowing package scope, never committing keys to source control, and planning rotation workflows.
Table of contents
Why are we making this change? Copy linkAPI Key Reduction Plan Copy linkRecommended: Move to Trusted Publishing Copy linkIf you continue using API keys Copy linkTake action now Copy link115 Impressions