RIPE NCC is replacing RPKI API keys with SSO-based credentials
RIPE NCC's Q4 2026 plan says work has started to replace RPKI API keys with OIDC-based keys. No migration deadline has been published; timelines are due at RIPE 93.
RIPE NCC's RPKI quarterly planning page, last updated on 17 September, says work has started to replace the current RPKI API keys with keys based on OpenID Connect and integrated with RIPE NCC Access. If you automate ROA management for your own address space against that API, this is a credential change to put on the roadmap, not a task with a date attached.
What changed
The Q4 2026 plan lists the work as in progress. Two related pieces are described: the RPKI Dashboard is being updated to use OpenID Connect provided by the RIPE NCC single sign-on system, and the existing API keys are to be replaced with OIDC-based keys tied to that same system. RIPE NCC also plans to add a dashboard section so those keys can be managed in an RPKI context rather than elsewhere in its account tooling.
The organisation says it will present more detail on implementation and timelines at the coming RIPE Meeting. That is RIPE 93, in Sofia from 26 to 30 October 2026.
What has not been announced
The planning page is a statement of intent, and it is worth being precise about its limits.
No migration deadline has been published. No retirement date for existing API keys has been published. The page carries a last-updated stamp rather than a dated announcement, and an update to a living planning page is not the same thing as a launch notice. Nothing here requires action against a clock today.
Treating this as a scheduled deprecation would be reading more into the source than it supports. The useful response is to know which of your systems would be affected, so that when a timeline does appear you are costing a change you already understand.
Why it matters for BYOIP
Bringing your own address space means owning the RPKI side of it. A ROA authorising your provider's AS to originate your prefix is something you create and maintain, usually through a registry portal or its API, and teams operating at any scale automate it rather than clicking through a dashboard for every change. Our RPKI and ROA guide covers where that responsibility sits.
A credential model change affects that automation specifically. Scripts and IPAM integrations holding a long-lived API key will need to obtain and refresh tokens through single sign-on instead, which is a different failure mode as well as a different setup: an expired or misscoped token fails differently from a static key, and it fails at the moment you are trying to publish a ROA.
There is a second item on the same page worth noting for BYOIP teams. Support for RPKI Signed Checklists, defined in RFC 9323, remains at planned status and is explicitly dependent on spare capacity after the other work. An RSC lets a resource holder sign an attestation that can be validated against the number resources they hold, and the RFC's own introduction names automated BYOIP onboarding as an expected use case for exactly that kind of proof. If it ships, it is a candidate replacement for the letter-of-authorisation paperwork that onboarding still relies on. It has not shipped, and RIPE NCC has not committed to when it will.
What to check
- Inventory what holds a RIPE NCC RPKI API key today: ROA automation, IPAM integrations, monitoring, and anything a supplier runs on your behalf.
- Establish who owns each of those credentials internally. Credential migrations tend to surface keys created years ago by someone who has since moved on.
- Confirm your tooling can handle token-based authentication with refresh, rather than assuming a static secret that never expires.
- Follow RIPE 93 in late October for the implementation detail and timelines, and revisit this once an actual schedule exists.
- Do not schedule a migration against a deadline that has not been published. Prepare the inventory now; plan the cutover when RIPE NCC dates it.
Sources and further reading
The quarterly planning page establishes the intent and the in-progress status; it does not establish a schedule. For background on ROAs and the responsibilities that come with announcing your own prefix, see our RPKI and ROA guide.
Sources
- RPKI Quarterly Planning, Q4 2026
RIPE NCC · checked 21 Sept 2026
- RIPE 93
RIPE NCC · checked 21 Sept 2026
- RFC 9323 - A Profile for RPKI Signed Checklists (RSCs)
IETF · checked 21 Sept 2026