Update: Scoped Personal Access Tokens is now available. Find out more at: https://www.storyblok.com/cl/scoped-personal-access-tokens.
Personal access tokens for the Management API now support granular scopes and space restrictions. When you create a token, you choose which scopes it can use (stories, assets, components, webhooks, and more) on a read-write-publish hierarchy, and whether it applies to all spaces or only specific ones. Endpoints outside the standard content scopes — organization management, billing, SSO, user management, and others — are blocked by default.
Until now, every personal access token had full read-write access to every space the user owned. A token built for a CI pipeline that publishes stories in one space could also delete components in any other space, change billing, or touch user management. The same risk applies to AI assistants calling the Management API through the Storyblok MCP server. Scoped tokens limit the blast radius of a compromised, leaked, or prompt-injected token. Existing unscoped tokens enter a six-month transition period and will be revoked on 30.11.2026.
Key Benefits:
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | API Performance Improvements | 0 | 11.73 | 26-05-2026 |
| 2 | App Store | 0 | 13.67 | 23-04-2019 |
| 3 | Type-Safe Schemas with @storyblok/schema | 0 | 14.84 | 27-07-2026 |
| 4 | Storyblok Native A/B Testing | 0 | 10.35 | 01-06-2026 |
| 5 | Webhooks in Basic | 0 | 11.73 | 16-07-2018 |
| 6 | AI Credits | 0 | 13.67 | 19-01-2026 |
| 7 | UI Accessibility Updates | 0 | 6.4 | 24-04-2026 |
| 8 | Backups on your S3 bucket | 0 | 9.31 | 31-10-2018 |
| 9 | Keyboard shortcuts for Visual Editor | 0 | 9.31 | 08-07-2026 |
| 10 | Security Fix: Webhook API Now Aligned with UI Access Controls | 0 | 3.85 | 08-04-2026 |