On October 22nd, 2025 at approximately 18:51 UTC, Akamai became aware of API tokens missing from some customer accounts. This caused a widespread occurrence of HTTP 401s (unauthorized) being returned for many API calls.
During the investigation, it was determined that a change made at 15:20 UTC (October 22nd) to archive a small set of API tokens had incorrectly archived multiple tokens that the change was not intended for. This resulted in the API errors that were being returned.
In order to mitigate the issue, we stopped the archival service and restored the missing tokens. All of the missing tokens were restored by 21:10 UTC.
To prevent this from occurring in the future, measures have been put in place to ensure the change containing the bug won't be used again and is disabled. We have also instituted more rigorous review, testing, and validation processes and procedures for any future services which affect production data.
This summary provides an overview of our current understanding of the incident given the information available. Our investigation is ongoing and any information herein is subject to change.