Heroku Blog
- News
- Last Updated: September 30, 2026
- Alberto Sigismondi
Team Authorizations let you create and manage API tokens and OAuth authorizations at the team and team’s resources level instead of tying them to one person’s account.
Until now, every API token belonged to an individual. When that person left the team, changed roles, or lost access, any integration, CI/CD pipeline, or automation built on their token could break without warning, and nobody else could easily see what was at risk. Team Authorizations fixes that. Your integrations keep running no matter who's on the team.
- Ecosystem
- Last Updated: August 25, 2026
- Andy Smith
- News
- Last Updated: August 21, 2026
- Alberto Sigismondi
Fine-Grained Access Controls is now available to all Heroku customers. Heroku’s legacy system gave you predefined roles like admin, member, or collaborator, each with a fixed bundle of permissions. It replaces that system with fine-grained roles like view, deploy, operate, and manage, with specific capability sets. Access control is managed at an app-specific layer, giving your team the capability to tune individual access for each of your apps.
- Engineering
- Last Updated: July 16, 2026
- Andy Smith
- Engineering
- Last Updated: July 01, 2026
- Katy Bowman
Beginning in version 11.8.0, we will be improving the security of the Heroku CLI by storing authentication credentials in your system keychain by default. The Heroku credential manager makes use of OS-native secure storage tools with interfaces designed for sensitive data while maintaining compatibility with existing developer workflows.
- Engineering
- Last Updated: June 24, 2026
- Nick Prey, Andy Smith
Subscribe to the full-text feed.