Enable PAT-less authentication to the Harness API (either direct integration or through MCP) that supports On-Behalf-Of (OBO) so downstream API calls preserve the end-user identity, entitlements, and audit context. The current service account approach is not acceptable due to permissioning, auditability, and operational risk.
Problem:
Today, accessing Harness programmatically typically relies on:
Personal Access Tokens (PATs), which introduce token lifecycle/rotation risks and are not ideal for enterprise controls; or Service accounts, which collapse user context and can lead to over-privilege, weaker auditing, and governance friction.
We need a solution where:
  • Calls to Harness are performed without PATs, and
  • Each request is executed in the context of the initiating user (OBO), so authorization reflects that user’s permissions and is audit-friendly.
Goals
  • Provide a PAT-less authentication mechanism for Harness API calls
  • Support OBO / delegated authorization so Harness actions reflect the real user
  • Improve audit trail fidelity (who did what) and reduce over-privileged service accounts
  • Enable integration via MCP (or equivalent broker) with standardized auth propagation
Created by Gino Orvieto
·