Connector Token Security and Operations
Use this guide for secure production connector credential practices.
Security Defaults
- Use service accounts for production connectors.
- Avoid personal tokens for long-lived integrations.
- Grant least privilege required for each connector.
- Store tokens in secure secret stores and rotate on schedule.
- Monitor token usage and revoke on suspicion or personnel change.
- Scope tokens by operation, environment, and resource where the provider supports it.
- Do not give agent-accessible connectors root, owner, tenant-wide, or account-wide destructive permissions when narrower scopes exist.
- Use separate credentials for read-only, write, admin/RBAC, and destructive tool groups.
- Prefer just-in-time or short-lived credentials for production write or destructive workflows.
- Require an external approval or policy gate before issuing or using credentials that can delete, reset, rotate, migrate, transfer, or overwrite production resources.
PagerDuty Token Pattern
Preferred model:
- dedicated PagerDuty service account
- role scoped to required operations (Responder/Observer style)
- user API token format in connector auth (
Token @@CONNECTOR_TOKEN@@)
Do not use account-level API key where user token is required by MCP server.
Azure Managed Grafana Token Pattern
Preferred model:
- Grafana service account token for persistent agent connectivity
- Viewer role by default
- elevate to Editor/Admin only when required
Alternative:
- Entra ID token for managed identity/service principal, with role assignment.
- Treat Entra token flow as short-lived and refresh-aware.
Dynatrace Token Pattern
Use platform token with minimum scopes:
- MCP gateway invoke/read scopes
- add only required query/problem/security scopes for enabled workflows
Keep scoped token per environment (dev/stage/prod), not global.
Rotation and Ownership
Set a default connector token policy:
- owner: team mailbox + on-call group, not individual user
- rotation cadence: 30-90 days based on risk
- immediate rotation triggers:
- role change/offboarding
- credential leak suspicion
- failed audit
Validation After Rotation
After each credential rotation:
- verify connector state is Connected
- run one read-only tool test
- run one workflow test (if applicable)
- confirm no degraded automations
Incident Response for Token Failures
When status flips to Failed:
- check auth header format
- verify endpoint URL and region
- verify token scopes/roles
- rotate token if uncertain
- retest and document recovery
Sources
- Official plugin repository: https://github.com/Azure/sre-agent-plugins
- PagerDuty plugin docs: https://github.com/Azure/sre-agent-plugins/tree/main/plugins/pager-duty
- Dynatrace plugin docs: https://github.com/Azure/sre-agent-plugins/tree/main/plugins/dynatrace
- Azure Managed Grafana plugin docs: https://github.com/Azure/sre-agent-plugins/tree/main/plugins/azure-managed-grafana
Bundle Mapping
Connector templates live in: