Hello,
We are developing an internal integration for Jira Service Management Cloud Assets.
Users authenticate through OAuth 2.0 (3LO), and the integration performs Assets operations on behalf of the authenticated user. We need to create comments in the activity section of Assets objects while preserving the user who performed the action as the comment author.
We found references to an Assets comment endpoint similar to:
POST /jsm/assets/workspace/{workspaceId}/v1/comment/create
With a payload similar to:
{
"objectId": 12345,
"comment": "<p>Example comment</p>",
"role": 0
}
However, the public Assets Cloud REST API does not appear to document comment operations for OAuth 2.0 apps. The available granular scopes, such as:
read:cmdb-object:jira
write:cmdb-object:jira
refer to object data and attributes, but do not explicitly mention object comments.
Using Basic Authentication with an API token works through a technical account, but the comment is then attributed to that account instead of the user who initiated the operation. This prevents an accurate per-user audit trail.
Could someone confirm:
- Is there a supported public endpoint for creating Assets object comments using OAuth 2.0 (3LO)?
- If supported, what is the correct URL format and required scope?
- Will the comment be attributed to the user who authorized the OAuth connection?
- Are reading and deleting those comments also supported through OAuth?
- If this is not currently supported, is there an existing feature request we can follow and vote on?
Our expected behavior is that the request respects the authenticated user’s Assets schema permissions and records that user as the comment author.