Hi everyone,
I'm implementing OAuth 2.0 for a Jira Data Center application and have a question about how the client credentials work in a multi-user environment.
From what I understand, an OAuth provider is configured once in Jira Data Center, which generates a Client ID and Client Secret.
I would like to confirm the following:
- Is the same Client ID and Client Secret used for all users who authorize the application?
- Or are separate Client IDs and Client Secrets generated for each user?
- If the Client ID and Client Secret are shared, are the authorization code, access token, and refresh token the only user-specific credentials?
- What is the recommended approach for securely implementing OAuth 2.0 when multiple users authenticate against the same Jira Data Center instance?
I want to make sure my implementation follows the recommended best practices for Jira Data Center.
Thanks in advance for your help!