We have a project where external contractors are supposed to log work on tickets they work on. We have set the project up such that every user who is part of the "Developer" project role:

Now we added the contractor the the "Developer" project role and he can indeed log work in Jira directly (in the browser). In addition we have a time tracking tool that is integrated with Jira using Oauth and the Jira REST client library.
Now if this same contractor who can log work just fine in the web interface tries to do this using the REST client, he gets a 403. He can read issues in the project just fine on the REST client so in general the token seems to work but logging work yields a 403 every time. Is there some special set of permissions that kick in when you use the REST client vs the web interface and that I need to configure somehow?
We're using a self-hosted Jira 7.12.3.