Deprecated APIs around ingest, query, config, and other capabilities require migration to Latest Dynatrace equivalents. This stage audits which classic APIs are in use, maps them to their Latest Dynatrace equivalents, and migrates integrations to OAuth-based authentication.
Replacing classic API tokens with OAuth clients scoped to minimum required permissions reduces your attack surface, improves audit traceability, and positions integrations to use the Latest Dynatrace platform API endpoints that classic endpoints are being deprecated in favor of.
Start with the audit: do not revoke any tokens until all consumers are identified. Classic tokens used by undiscovered scripts or third-party tools break silently when revoked.
Upgrade remaining entities & metrics
| Role | Involvement | Responsibility |
|---|---|---|
Dynatrace Admin | Required | Audits tokens, creates OAuth clients, and coordinates decommission |
DevOps / Platform Eng. | Recommended | Owns CI/CD pipelines and automation scripts that consume Dynatrace APIs |
Application Team Leads | Recommended | Coordinate updates to third-party integrations and custom scripts using classic API tokens |
Security / Compliance | Optional | Reviews OAuth client scopes and approves token deprecation |
Identify all active tokens, their scopes, and which classic endpoints they call, then map each to the corresponding platform API and OAuth-based equivalent.
Verify: All active classic API tokens documented with their scopes, active endpoints, and Latest Dynatrace equivalents; no undocumented consumers.
Audit all API consumers before revoking tokens: classic tokens may be used by scripts, pipelines, or third-party tools that are not centrally tracked. Revoking tokens without full discovery breaks integrations silently. Use API access logs as a secondary signal during the audit step.
Prioritize APIs with known deprecation dates: Dynatrace may deprecate classic endpoints on a fixed schedule. Delayed migration puts you at risk of breaking changes. Prioritize classic endpoints with known deprecation dates first.
Set up OAuth clients with granular scopes and update CI/CD pipelines, monitoring scripts, and third-party tools to use new API endpoints and OAuth authentication.
Verify: Each OAuth client configured with minimum required scopes; all integrations updated to call Latest Dynatrace endpoints.
Initiate vendor coordination early: external teams or vendors owning integrations need time to update their code. This coordination extends the timeline beyond the Dynatrace admin's control. Initiate vendor requests early in the stage.
Scope OAuth clients precisely: overly broad or overly narrow OAuth client scopes lead to either security risks or broken integrations. Carefully map the minimum required scope per integration before creating OAuth clients.
Test each migrated integration to confirm expected behavior, then disable classic API tokens and document token ownership.
Verify: Target percentage of classic endpoints decommissioned; all integrations operating on Latest Dynatrace platform API with OAuth authentication.
Stage complete when:
With your API integrations and tokens migrated, you've completed the full upgrade journey and your environment is now running on the Latest Dynatrace platform. Return to the Wayfinder overview for post-upgrade guidance on attributing DPS consumption costs to teams and validating cost allocation reports.
The following resources support your work in this stage. Documentation covers platform concepts, configuration reference, and related guides; best practice cards provide implementation guidance from Dynatrace experts.
Reference for deprecated classic API endpoints and their Latest Dynatrace platform API equivalents.
Configure platform tokens and OAuth clients with granular scopes for Latest Dynatrace integrations.
Migrate OpenPipeline configurations to Settings API
Guide for migrating OpenPipeline configuration through the settings API.
Best practices for upgrading App Observability API endpoints
Audit classic API token usage, map endpoints to platform API equivalents, and migrate CI/CD pipelines to OAuth clients.
You've completed the full upgrade journey; all eleven stages are done and your environment is running on the Latest Dynatrace platform. Return to the Wayfinder overview for post-upgrade guidance on attributing DPS consumption costs to teams and validating cost allocation reports.