
5/7/2026 · Nelly Vahab
What this post added
Introduced fine-grained Personal Access Tokens (PATs) as a beta feature. These tokens allow for scoping permissions to specific projects/groups and individual resource actions (Create, Read, Update, Delete) for resources like Issues, Merge Requests, Pipelines, Repositories, and Container Registry. This enhances security by implementing the principle of least privilege, reducing the impact of token leaks. The tokens table has been updated to display these granular scopes for auditing. Future roadmap includes expanding coverage to remaining REST API endpoints and adding GraphQL support.