Full Control Over Permissions, Welcome API Policy Tokens
Blog post from Qovery
Qovery has introduced API Policy Tokens, a new organization token type that uses Open Policy Agent and Rego policies to enforce fine-grained, request-level API authorization rather than relying on broader RBAC roles. Policies can assess the requested action, target resource, HTTP method, and request body, allowing teams to grant automated systems such as AI agents, Terraform runners, CI/CD pipelines, scripts, and CLI users only the capabilities they require. The feature addresses the risk of overprivileged automation by denying all actions by default and explicitly permitting specific operations, such as allowing a staging deployment-triage agent to redeploy or roll back an environment while preventing deletion. Policies are evaluated on every request, apply changes immediately, and provide distinct audit-log attribution for each token. Users can create a Policy API Token in Qovery’s organization settings, define a Rego policy from a provided template, securely save the token when it is displayed once, and use it through the standard Authorization header.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 2 | 5,780 | 1,243 | 245 | -15% |
| Platform Engineering | 2 | 1,191 | 259 | 79 | -17% |
| MCP | 1 | 8,729 | 854 | 211 | -20% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.