Zendesk is introducing a granular "Manage APIs" permission for Enterprise plan administrators, enabling technical teams to create, edit, and delete API tokens and OAuth clients without requiring full admin access. Previously, delegating API management necessitated granting developers and technical leads complete administrative privileges—a security violation that exposed sensitive areas like billing, subscription management, and user administration to personnel who had no legitimate need for such broad capabilities. The new permission implements proper role-based access control by allowing admins to carve out API management as a discrete responsibility, complete with read-only access to API analytics and full audit logging of all credential operations. This addresses a fundamental operational friction point: the manual privilege escalation workflows that organisations previously relied upon to balance developer autonomy with security governance.
The implications for CX teams centre on reducing both security risk and administrative overhead. For organisations running multi-team support operations with dedicated integration specialists or technical operations staff, this permission eliminates the need to temporarily elevate these individuals to admin status—a practice that creates audit complications and extends access windows beyond what's operationally necessary. The automatic logging of all API operations by user identity, role, and timestamp strengthens compliance posture, particularly valuable for teams subject to regulatory scrutiny. However, the permission's default-disabled status means adoption requires deliberate configuration; teams must actively review their current API access patterns and assign the permission to relevant custom roles. For smaller CX operations or those without dedicated technical teams, this change may have limited immediate impact, though it signals Zendesk's commitment to departmental access controls that could expand into other administrative functions. The announcement also hints at future "department-scoped API token management capabilities," suggesting Zendesk is building infrastructure for more sophisticated permission hierarchies—a development worth monitoring as organisations increasingly distribute technical responsibilities across support and operations teams.
Announced on Rollout starts Rollout ends August 10, 2026 August 11, 2026 August 21, 2026 Zendesk is introducing a new granular permission that allows Enterprise plan admins to delegate API and OAuth client management to developers and technical teams without granting full admin access. The "Manage A