Microsoft Reduces NuGet API Key Lifetime to Enhance Security

Microsoft Reduces NuGet API Key Lifetime to Enhance Security

First seen 4 Aug 2026, 20:26 UTC Feeds2.FeedburnerCybersecuritynews 93% similarity 39.8

Article Content

Browse articles
ThreatCluster

Microsoft is implementing a significant change to the NuGet.org API key policy, reducing the validity of new API keys from 365 days to 30 days, effective August 17, 2026. This decision aims to enhance supply chain security and mitigate the risk of credential theft that could lead to the publication of malicious .NET packages. Existing API keys created before this date will remain valid until November 1, 2026, after which developers must generate new keys or utilize NuGet Trusted Publishing. While this change addresses some security concerns, it does not completely eliminate the risks associated with API keys. Developers are encouraged to adapt to the new policy to maintain the integrity of their packages and protect against potential threats.

Key Points: • NuGet.org API key lifetime reduced from 365 days to 30 days starting August 17, 2026. • Existing API keys will remain valid until November 1, 2026, requiring developers to update their keys. • The change aims to reduce the risk of credential theft and malicious package publication.

ThreatCluster AI How this analysis works

Timeline

2026-08-04
Announcement of API key lifetime reduction
Microsoft announced the reduction of NuGet.org API key lifetime to enhance security, effective August 17, 2026.
Feeds2.Feedburner
2026-08-04
Details on existing API key validity
Developers were informed that existing API keys will remain valid until November 1, 2026, after which new keys must be generated.
Cybersecuritynews

Community

Browse all →