I'm currently exploring best practices for API key management and rotation for our integration with Atlassian Jira. As part of our security measures, we want to rotate API keys programmatically to align with industry standards, which recommend regular key rotation to enhance security.
Current Situation:
- We are aware of the ability to manually create and manage API tokens through the Atlassian UI.
- We are looking for ways to automate the key rotation process, ideally via a REST API or any backend solution that supports automated key generation and management.
Key Questions:
- Is there an existing REST API or endpoint provided by Atlassian that allows for the creation of API tokens programmatically on behalf of a user?
- Are there any recommended practices or third-party tools that integrate with Atlassian to help automate API key rotation while adhering to security best practices?
- Has anyone implemented browser automation, or other creative solutions, to manage key rotation, and what were your experiences or challenges?
We currently use secret management tools like HashiCorp Vault and CI/CD workflows for managing credentials, but we want to know if direct API integration with Jira for key rotation is feasible.
For context, this is for a service account.
Any insights, advice, or pointers to relevant documentation would be greatly appreciated. Thank you for your time and assistance!