If I make API calls out from Jira in Atlassian Government Cloud to an external app (like Okta), does that violate FedRAMP Moderate?
Jira AGC can't talk to Bitbucket DC or Confluence commercial, but it is allowed to talk to Okta as an IdP (afaik). So are non-authentication-related API calls allowed to Okta? Use case is collecting user information beyond the basics.
I know there isn't a lot of information out there about AGC, but I'm hoping that someone has implemented Jira and knows first-hand. Or someone from Atlassian, I'm not particular ;-)
Please take a look on this doc - https://developer.atlassian.com/platform/framework/agc/agc-security-requirements/?utm_source=chatgpt.com
As I understand outbound API calls to external systems are supported primarily through Forge apps and approved integrations. Forge apps can call external HTTPS APIs using outbound fetch/egress capabilities.
Regards,
Seba
Thanks, @Sebastian Krzewiński. Looks like API calls are ok as long as they adhere to these requirements, which would include using Forge. I appreciate the help!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.