The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Exclude API access from 2FA login?

Daniël Rouw
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 4, 2021

In our JIRA server (on-premise) we have the Secure Login Plugin installed (2FA). We want to grant access to an external application which connects to the JIRA API (/rest/api/2/issue/).

We tested by adding the relative path of the API to the 2FA URL Filter in the Context Whitelist and this works for us.

We wonder if this is the right way-of-working for granting access to a single application. We are in doubt whether we might have introduced a security risk by granting the whole world access to the API without the use of 2FA.

Anyone having experience with granting API access in combination with the Secure Login Plugin to answer our doubts?

1 answer

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

0 votes
Nicholas Hall
August 2, 2022

Hi Daniel 

Sorry I don't have answer.

 

But I would also like to do this. Have  you any more information on how you grant access to avoid 2FA?

DEPLOYMENT TYPE
SERVER
VERSION
8.13.7
TAGS
AUG Leaders

Atlassian Community Events