Hi Jira Platform Team,
We’ve recently observed several instances where users are encountering a 403 Forbidden error when calling the following endpoint via our 3LO (OAuth 2.0) integration:
GET <a href="https://api.atlassian.com/ex/jira/%7BcloudId%7D/rest/api/3/project/search?expand=lead&startAt=0&maxResults=200&status=live&action=browse" rel="noopener nofollow noreferrer" target="_blank">https://api.atlassian.com/ex/jira/{cloudId}/rest/api/3/project/search?expand=lead&startAt=0&maxResults=200&status=live&action=browse</a>
Context:
We would like to clarify:
Is this 403 error a result of a recent platform change or a specific security policy (e.g., granular scope enforcement)?
Is this an omission in the documentation, or is there a new requirement for additional scopes (such as read:user:jira due to the expand=lead parameter)?
Looking forward to your guidance on whether this is expected behavior or a potential regression.
Best regards,