
dse7i (dse7i) asked a question.
We had 2 new permissions added to 2 of our roles.
- okta.users.apitokens.manage: Allows the admin to manage API tokens
- okta.users.apitokens.read: Allows the admin to view API tokens
Questions:
- Anyone know what these are for?
- Were they previously included in another permission?
- Which API tokens are these even referring to?

Hello @dse7i (dse7i) Thank you for posting on our Community page!
These roles allow Admins to view all API tokens and make changes to them, aka to revoke tokens or to create tokens. APi tokens are used SCIM applications/API calls/connect applications to Okta.
Please see our doc on Admin roles below and API tokens:
https://developer.okta.com/docs/api/openapi/okta-management/guides/roles/
https://developer.okta.com/docs/guides/create-an-api-token/main/
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.