Hi everyone, I'm interested in looking at the Jira API. I'm trying to keep it safe though by using two factor authentication for all logins.
When looking at the Jira API though, it seems like there is only the "Basic Authentication" which is just username+password? Is this correct? And it switches the API on for everyone, so its not even a one off case of skipping two factor for a single user.
It seems to be similar for PATs as well once you've logged in if its switched on anyone can create a PAT, and I can't just have one user be with limited access make a single PAT last 60 days. Instead it allows everyone to do this. And everyone will be able to make a PAT that allows them to update Jira without logging them in, in the future?