X-Auth Token Deprecation Frequently Asked Questions (FAQs)
This help topic describes some common questions about the X-Auth token authentication changes for the Megaport Portal.
In November 2022, Megaport released API keys to facilitate generation of authentication tokens for machine to machine communication to the Megaport API, removing the reliance on non-expiring X-Auth tokens. This has improved our security posture giving customer company admins and IT infosec managers additional control over access to Megaport’s API.
The benefits of API keys are a controlled authentication process, no need to embed usernames and passwords when accessing the API, and the ability to create a company admin or read only API key.
Megaport will be phasing out the use of X-Auth tokens starting July 2023. Those accounts that have authenticated using X-Auth tokens with existing API integrations will be whitelisted so X-Auth tokens continue to function until 30 September 2023.
All accounts that have not previously accessed the API using X-Auth tokens must use API keys. On 1 October 2023, any existing X-Auth tokens will no longer be able to access the Megaport API. From this date, all customers must use API Keys to authenticate against the Megaport API.
This topic describes some of the changes and commonly asked questions relating to the X-Auth token authentication changes.
Last modified on August 21, 2026
Was this page helpful?