Enable API Token Generation for Non-Admin Users in Web App Scanning (F5 Distributed Cloud)

Description:

Currently, only users with full admin rights in F5 Distributed Cloud can generate API tokens for the Web App Scanning service. Non-admin users, even with user-level access to Web App Scanning, do not have the ability to generate API tokens. This limitation prevents organizations from delegating token management to non-admin users and restricts automation or integration workflows for those users.

Customer Impact:

Non-admin users are unable to generate API tokens, limiting their ability to use Web App Scanning APIs for automation or integration.
The customer’s access level cannot be changed to admin due to internal policy, so the current workaround is not feasible.
The customer has requested this feature to be considered for future releases to improve usability and flexibility for non-admin users.

Request:

Please consider enhancing the Web App Scanning RBAC model to allow non-admin users (with appropriate permissions) to generate API tokens, or provide a configurable option for administrators to delegate this capability.

  • Guest
  • Jun 12 2026
  • Attach files