Hi there,
I have been through many, many jira community questions/stackoverflow/all the REST documentation and haven't been able to pin down the exact required steps for authenticating JIRA rest API via Oauth2 (Office365).
Current setup:
- Custom JIRA cloud instance (<mycompany.jira.atlassian.net)
- Basic auth disabled / SSO via Office365 enabled
- Oauth 2.0 via AzureAD/Office 365
Endpoint I am testing: mycompany.jira.atlassian.net/rest/api/latest/issue/ISSUE-123
I am using Postman to test the API call. I have tried various methods and will outline the difference responses I get below. From my reading, I have been unclear on what combination of these things I need to authenticate an endpoint:
- JIRA API Token
- Oauth2.0 Token from SSO provider
- Certificates outlined in JIRA Oauth docs (public_key.pem, key.pcks8, private_key.pem, public_key.cer)
I have added my private key to postman in postman > settings as well as adding the appropriate keys to application links in JIRA admin as outlined in documentation.
Test 1 (API Key auth, similar to curl -u my.username:api-key):
GET mycompany.jira.atlassian.net/rest/api/latest/issue/ISSUE-123
Accept: application/json
Content-Type: application/json
Authorization: Basic <base64encoded(my.username:jira-api-key)>
Response (The issue absolutely exists, and I am able to view the JSON structure when visiting the rest/api url directly in the browser):
{"errorMessages":["Issue does not exist or you do not have permission to see it."],"errors":{}}
Test 2:
GET mycompany.jira.atlassian.net/rest/api/latest/issue/ISSUE-123
Accept: application/json
Content-Type: application/json
Authorization: Bearer <Oauth2 token from AzureAD/Office365>
Response:
{"message":"Client must be authenticated to access this resource.","status-code":401}
Any help or context from anyone who has gotten this working would be greatly appreciated. I did read somewhere that JIRA rest may only support Oauth1... However I see a plugin here that does what I seek:
https://plugins.miniorange.com/rest-api-authentication-using-azure-ad-as-oauth-provider
This plugin is only supported for server/data-center and not cloud hosted so I cannot use it - so wondering how to accomplish authenticating endpoint on my own.