Hi community,
I'm trying to connect to the REST API of our Jira Data Center instance (<a href="https://jira.globaldevtools.bbva.com" rel="noopener nofollow noreferrer" target="_blank">https://jira.globaldevtools.bbva.com</a>) using a Python script, but I'm stuck on a persistent authentication error.
My account has two-factor authentication (MFA) enabled.
What I've tried so far:
1. Basic Authentication (Failed)
My first attempt was to use basic_auth with my email and an API Token. This failed with a 403: Basic Authentication has been disabled on this instance error, which is expected.
2. Bearer Token Authentication (Failed)
Following best practices, I changed my connection method in Python to use a Bearer Token in the headers. The code is as follows:
Python
<span>from</span> jira <span>import</span> JIRA
jira_server = <span>'https://jira.globaldevtools.bbva.com'</span>
api_token = <span>'MY_NEWLY_GENERATED_API_TOKEN'</span>
headers = {
<span>'Authorization'</span>: <span>f'Bearer {api_token}'</span>
}
jira = JIRA(server=jira_server, options={<span>'headers'</span>: headers})However, this results in a 401 Unauthorized: Client must be authenticated to access this resource error.
3. Regenerating Tokens
I have revoked and regenerated the API Token multiple times, copying it very carefully to ensure it is correct, but the result is always the same 401 error.
4. Testing with cURL (Outside of Python)
To rule out an issue with the Python library, I made a direct request using curl from my terminal. The result was identical:
Bash
curl --request GET \
--url <span>'https://jira.globaldevtools.bbva.com/rest/api/2/myself'</span> \
--header <span>'Authorization: Bearer MY_NEWLY_GENERATED_API_TOKEN'</span> \
--header <span>'Accept: application/json'</span>
Response: {"message":"Client must be authenticated to access this resource.","status-code":401}
My Question:
Given that Basic Authentication is disabled and Bearer authentication with a freshly generated API token fails in both Python and curl, what server-side Jira configurations could be causing this consistent rejection?
Is there a specific user-level or group-level permission that my account needs to have in order to use the REST API?
Could this be related to an IP Allowlist that is blocking requests from external services like Google Colab (where I am running the script)?
Are there any other recommended authentication methods for corporate instances with MFA that I should consider?
Any guidance would be greatly appreciated, as I have exhausted the client-side solutions. Thank you!