I am working on a requirement where we are going to use OAuth 2.0(3LO) flow for authentication purpose with one of our applications. I was successfully able to generate Access token by going through the steps mentioned here: here: https://developer.atlassian.com/cloud/confluence/oauth-2-3lo-apps/
I want to validate above generated access token in backend application and to do the same we need a private and public key(or IssuerSigningKey key). I am not sure where i can find the same?
Thanks much in advance !
Welcome to the Atlassian Community!
I am not sure what you mean by "validate access token"?
The private and public key pair should be created for your account. If you're on a proper operating system, you can generate a new pair really easily by just running "ssh-keygen" on the command line.
Hi @Nic Brough -Adaptavist- ,
Thanks for the answer, I will provide you with detailed information for my query.
I have created OAuth 2.0 integration app at https://developer.atlassian.com/ by following all the steps mentioned at https://developer.atlassian.com/cloud/jira/platform/oauth-2-3lo-apps/
Now there are two steps involved to get JWT access token to make Jira API calls
1. Start the authorization flow by directing the user to the authorization URL https://auth.atlassian.com/authorize with all required parameters.It will provide authorization code which is again a JWT token only and we can validate the signature of this authorize code by client_secret mentioned in the settings of OAuth 2.0 integration app. We can simply visit https://jwt.io/ and in the signature provide client_secret and it will say JWT token signature is valid.2. Now to get the actual access token(which is in JWT format only) we need to make another call at https://auth.atlassian.com/oauth/token with all required parameters. If successful we will get an access token and now if i simply visit https://jwt.io/ and paste this access token. In the Verify signature part it will ask for a public and private key pair. Now my question is where I can get the same. I assumed public key would be client_id and private key would be client_secret mentioned in the settings of OAuth 2.0 integration app but it is not the case.
I am looking for this private/public key because I just want to validate the signature of this access token without making any further Jira call.
Note: We are using the organizational level Jira cloud.
So what happens when you create the key pair you need?
Hi @Nic Brough -Adaptavist-
This is the point I am not creating any key pair from my side. I am assuming that I should get the same from OAuth 2.0 integration app settings.
If you are saying I should generate key pair at my side, I can do the same but the question is how internally it will be linked to OAuth 2.0 integration app created at https://developer.atlassian.com/console/myapps/.
Note: I am using Jira cloud as a developer.
May be I am missing something here. Could you please guide me to do it in the right way ?
It looks like you're new here. Sign in or register to get started.