Hi everyone,
I am facing a critical issue with Jira Service Management Cloud REST APIs regarding a workflow that used to work perfectly until recently.
Our Context & Past Workflow:
We have an automation script running with an Agent's credentials (Email + API Token). For security reasons, we absolutely do not want to elevate this integration account to Global Admin.
Until recently, the script performed the following steps smoothly:
Checked if a user existed via API.
If the user did not exist in Jira, it proceeded to create them as a portal-only customer using the /rest/servicedeskapi/customer endpoint.
Added the newly created customer to a specific Organization.
The Current Problem (The Change): Without any changes on our side, this workflow has stopped working. Now, the script fails at step 2 with a 403 Forbidden error:
{"errorMessage":"Unauthorized to perform the requested action, JIRA Administrators global permission is required."}If I run the exact same script using my Global Admin credentials, it works. However, using a Global Admin account for a standard API integration is a massive security risk and against our company policy.
Our Current UI Configuration:
Under global Customer Access, the setting is correctly configured to: "Don't allow customers to create their own accounts. Only agents or admins can create accounts for customers."
From the Jira UI, the Agent can still successfully add/invite new portal-only customers to the project manually.
My Question: Why did Atlassian restrict the /rest/servicedeskapi/customer endpoint to Global Admins only, completely overriding the global UI settings that allow Agents to create customers?
Since this was a working feature for non-admin accounts, is there an official, secure workaround to allow an Agent's API token to provision a portal-only customer without granting them full global admin access to the entire Jira instance?
Thank you in advance for your help!