Scope access tokens to specific servers and applications
Right now, Access Tokens can be limited to specific API endpoint groups or individual operations using Limited Access. However, tokens are still account-level and cannot be restricted to a single server.
It would be very useful if tokens could be scoped to a specific server. This would allow integrations, automation tools, and scripts to operate only on one server instead of having access to all servers in the account.
Example use cases:
- Monitoring tools that only need access to one production server
- Deployment scripts tied to a single staging server
- Third-party integrations that manage only one environment
Server-scoped tokens would improve security by reducing the blast radius of a token and better align with the principle of least privilege.