Try it free

Upgrade your API integrations and tokens

  • Latest Dynatrace
  • Upgrade guide
  • Published Jul 24, 2026

Deprecated APIs around ingest, query, config, and other capabilities require migration to Latest Dynatrace equivalents. This stage audits which classic APIs are in use, maps them to their Latest Dynatrace equivalents, and migrates integrations to OAuth-based authentication.

Why upgrade?

Replacing classic API tokens with OAuth clients scoped to minimum required permissions reduces your attack surface, improves audit traceability, and positions integrations to use the Latest Dynatrace platform API endpoints that classic endpoints are being deprecated in favor of.

  • Capability-based, granular token scoping: more precise access control reducing over-permissioning through OAuth clients and the platform API

What will you do?

Start with the audit: do not revoke any tokens until all consumers are identified. Classic tokens used by undiscovered scripts or third-party tools break silently when revoked.

  1. Audit all active classic API tokens and map their endpoints to Latest Dynatrace equivalents
  2. Create OAuth clients with granular scopes and update integrations to use new endpoints
  3. Validate migrated integrations and decommission classic tokens

Before you begin

At a glance

  • Estimated effort: 3–10 days
  • Estimated timeline: 1–4 weeks

Prerequisites

Upgrade remaining entities & metrics

Key stakeholders

RoleInvolvementResponsibility

Dynatrace Admin

Required

Audits tokens, creates OAuth clients, and coordinates decommission

DevOps / Platform Eng.

Recommended

Owns CI/CD pipelines and automation scripts that consume Dynatrace APIs

Application Team Leads

Recommended

Coordinate updates to third-party integrations and custom scripts using classic API tokens

Security / Compliance

Optional

Reviews OAuth client scopes and approves token deprecation

Upgrade your API integrations and tokens

1. Audit classic API usage and map to latest equivalents

Identify all active tokens, their scopes, and which classic endpoints they call, then map each to the corresponding platform API and OAuth-based equivalent.

  1. Pull the list of all active classic API tokens from Dynatrace token management.
  2. For each token, document the assigned scopes and the owner or integration using it.
  3. Review API access logs to identify which classic endpoints are actively called by each token.
  4. Map each classic endpoint to its Latest Dynatrace platform API equivalent.
  5. Flag classic endpoints with no Latest Dynatrace equivalent; document these as requiring alternative solutions or accepted risk.
  6. Build a migration list: token → endpoint → latest equivalent → responsible team.

Verify: All active classic API tokens documented with their scopes, active endpoints, and Latest Dynatrace equivalents; no undocumented consumers.

Audit all API consumers before revoking tokens: classic tokens may be used by scripts, pipelines, or third-party tools that are not centrally tracked. Revoking tokens without full discovery breaks integrations silently. Use API access logs as a secondary signal during the audit step.

Prioritize APIs with known deprecation dates: Dynatrace may deprecate classic endpoints on a fixed schedule. Delayed migration puts you at risk of breaking changes. Prioritize classic endpoints with known deprecation dates first.

2. Create OAuth clients and update integrations

Set up OAuth clients with granular scopes and update CI/CD pipelines, monitoring scripts, and third-party tools to use new API endpoints and OAuth authentication.

  1. Create an OAuth client in Dynatrace Account Management for each integration or team.
  2. Assign the minimum required scopes based on the endpoint mapping from the previous step.
  3. Update CI/CD pipeline scripts to use the new platform API endpoint URLs and OAuth token exchange.
  4. Update monitoring scripts and automation to authenticate via OAuth and call Latest Dynatrace platform API endpoints.
  5. Coordinate with third-party tool owners or vendors to update their Dynatrace integration configuration.

Verify: Each OAuth client configured with minimum required scopes; all integrations updated to call Latest Dynatrace endpoints.

Initiate vendor coordination early: external teams or vendors owning integrations need time to update their code. This coordination extends the timeline beyond the Dynatrace admin's control. Initiate vendor requests early in the stage.

Scope OAuth clients precisely: overly broad or overly narrow OAuth client scopes lead to either security risks or broken integrations. Carefully map the minimum required scope per integration before creating OAuth clients.

3. Validate and decommission classic tokens

Test each migrated integration to confirm expected behavior, then disable classic API tokens and document token ownership.

  1. Run each updated integration in a test or staging context and verify expected API responses.
  2. Monitor API access logs to confirm that traffic has shifted from classic endpoints to Latest Dynatrace platform API endpoints.
  3. Once an integration is confirmed, disable the corresponding classic API token.
  4. Maintain a current token inventory with clear ownership for all active OAuth clients.
  5. Track the ratio of classic vs. Latest Dynatrace API endpoints in active use until target decommission is reached.

Verify: Target percentage of classic endpoints decommissioned; all integrations operating on Latest Dynatrace platform API with OAuth authentication.

Stage complete when:

  • All active classic API tokens are documented with their scopes, active endpoints, and Latest Dynatrace equivalents
  • Each OAuth client is configured with minimum required scopes and all integrations are updated to call Latest Dynatrace endpoints
  • Target percentage of classic API endpoints are decommissioned and all integrations operate on Latest Dynatrace platform API with OAuth authentication

With your API integrations and tokens migrated, you've completed the full upgrade journey and your environment is now running on the Latest Dynatrace platform. Return to the Wayfinder overview for post-upgrade guidance on attributing DPS consumption costs to teams and validating cost allocation reports.

Documentation and best practices

The following resources support your work in this stage. Documentation covers platform concepts, configuration reference, and related guides; best practice cards provide implementation guidance from Dynatrace experts.

  • Deprecated APIs

    Reference for deprecated classic API endpoints and their Latest Dynatrace platform API equivalents.

  • Platform tokens

    Configure platform tokens and OAuth clients with granular scopes for Latest Dynatrace integrations.

  • Migrate OpenPipeline configurations to Settings API

    Guide for migrating OpenPipeline configuration through the settings API.

  • Best practices for upgrading App Observability API endpoints

    Audit classic API token usage, map endpoints to platform API equivalents, and migrate CI/CD pipelines to OAuth clients.

Ready for more?

You've completed the full upgrade journey; all eleven stages are done and your environment is running on the Latest Dynatrace platform. Return to the Wayfinder overview for post-upgrade guidance on attributing DPS consumption costs to teams and validating cost allocation reports.

Related tags
Dynatrace Platform