Hi Team,
I’m integrating Jira Cloud REST APIs using OAuth 2.0 (3LO) and noticed some unexpected token invalidation behavior during automation.
Here’s my current setup:
- I obtain an access token and refresh token via the authorization code flow.
- The access token is used for various API calls (create issues, update project settings, etc.).
- When the access token expires, my automation uses the refresh token to get a new pair of tokens (access + refresh).
- I then replace the old refresh token with the newly generated one (since the old one becomes invalid).
However, I’ve observed that as soon as the refresh token is used, all existing API calls using the old access token start failing with 401 Unauthorized, even though the access token’s exp value still indicates 1 hour of validity.
So I wanted to confirm,
- Does Jira Cloud revoke all access tokens that were issued using a refresh token when that refresh token is used to obtain a new pair?
- Is this behavior part of Jira’s implementation of rotating refresh tokens, meaning that both the old refresh token and all access tokens derived from it become invalid?
- If so, what’s the recommended approach for handling this in multi-threaded or distributed automation (where multiple workers might still be using the old access token when a refresh occurs)?
This seems to explain why I occasionally get 401 Unauthorized errors right after a token refresh, even though the access token hasn’t yet reached its expiry time.
Thanks,
Gopal