Case 1 :When we use a valid username and api_token combination ,(as per https://developer.atlassian.com/cloud/jira/platform/basic-auth-for-rest-apis/)i.e., useremail:api_token (Base64 encoded) with any rest API call<br><br>The response <strong>code is 200 OK and we get the valid respons</strong>e also.<br><br><u>Case 2:</u><br><br>But when the <strong>invalid</strong> username and api_token combination is used with any rest API call,<br><br>The response code is still <strong>200 OK but the response will be empty as the authentication will be failed</strong>.<br><br><strong><em>Question 1 : What is the best way to validate if the given username and API token is correct / valid. ??</em></strong><br><br><br>one observation we found while analyzing is as part of the above Case 2 is that as part of the response headers when the Authentication is failed, there will be a header value <strong>"X-Seraph-Loginreason=AUTHENTICATED_FAILED".<br><br><em>Question 2 : Can we relay on the above response header to validate if the username and api_token is valid or not ??</em></strong><br><br>
api_token
useremail:api_token (Base64 encoded) with any rest API call<br><br>The response <strong>code is 200 OK and we get the valid respons</strong>e also.<br><br><u>Case 2:</u><br><br>But when the <strong>invalid</strong> username and api_token combination is used with any rest API call,<br><br>The response code is still <strong>200 OK but the response will be empty as the authentication will be failed</strong>.<br><br><strong><em>Question 1 : What is the best way to validate if the given username and API token is correct / valid. ??</em></strong><br><br><br>one observation we found while analyzing is as part of the above Case 2 is that as part of the response headers when the Authentication is failed, there will be a header value <strong>"X-Seraph-Loginreason=AUTHENTICATED_FAILED".<br><br><em>Question 2 : Can we relay on the above response header to validate if the username and api_token is valid or not ??</em></strong><br><br>
@vholechi,
Try making a call for a specific issue instead - https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issues/#api-rest-api-3-issue-issueidorkey-get.
Some rest calls work even without being authenticated, but the get issues end point should return a 401 is the token is wrong.
@Kian Stack Mumo Systems Thanks for the response,We verified this api and such api's by providing the particular issue id/key but still it does not give the 401 response code and it gives 404 Not found error.Also to use the suggested api we wouldn't have the issue id/key before hand while validating, hence this would not help in our case.
We tried api similar to below once and this gives 404 NOT FOUND if the username/api-token is invalidhttps://developer.atlassian.com/rest/api/3/issue/CD-22
@vholechi, developer.atlassian.com is not a jira site, so the API wouldn't work.
Try this one https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-jira-settings/#api-rest-api-3-application-properties-get
It looks like you're new here. Sign in or register to get started.