I'm trying to use an API Token with Confluence Cloud and getting a 401 - Unauthorized error.
I created a scoped API token for Confluence, including all read scopes and the search scope. I'm trying to test this request:
curl -D- \
-u <my-email>:<my-api-token> \
-X GET \
-H "Content-Type: application/json" \
https://<my-domain>.atlassian.net/wiki/rest/api/space
I've triple-checked my API token and can see it listed as "Allowed" for my user in the Security > User API tokens admin screen. If I add a "-v" option to the curl command, I can see the authentication header and have verified the string following "Basic" exactly matches what I get with
echo -n <my-email>:my-api-token> | base64
It feels relatively straightforward, but I continue to get a "401 - Unauthorized" error with the text "The request has not been applied to the target resource because it lacks valid authentication credentials for that resource."
Our wiki is public and, if I remove the credentials, the REST call works properly. In fact, if I provide bogus credentials (e.g., "-u foo:bar") the request works. Why would adding username & API token fail as unauthorized?
We have a single identity provider using SAML SSO for our domain and I can see User API token access is allowed.
The fact that the very same REST call without credentials or with invalid credentials works and the request only fails as 401 Unauthorized when I use my API token suggests that I've got the correct credentials, but access is getting blocked by a missing scope or some policy I'm overlooking. I've included every single read + search scope for the API token and it sure looks like API tokens are enabled (the admin page literally tags the token as "allowed").
What am I doing wrong? I'm assuming it's something simple that's right in front of me that I'm missing. It wouldn't be the first time. :-)