# Personal API Keys Retired — Changelog
[ 
Changelog
](/changelog) September 3, 2026 [ IAM ](/changelog?tag=IAM) 
# Personal API Keys Retired

Personal API keys and their creation UI are gone. Use scoped OAuth access tokens instead, which limit exactly what a token can do rather than acting with a user's full permissions. 

Personal API keys granted whatever access the creating user had, with no way to narrow that down. If a key leaked, so did everything that user could touch. Probo has removed the personal API key creation UI and its [GraphQL mutation](/docs/developers/graphql) for that reason.

[Scoped OAuth access tokens](/docs/developers/api-overview) are the replacement. They only carry the specific permissions you grant at creation, so a token built for reading documents can’t also delete users. Existing personal API keys keep working for now, but new integrations should use OAuth tokens going forward.

It’s a smaller surface to worry about if something goes wrong, and it matches how most API providers handle this today.
