As I understand from my searches on web, Jira REST API is using by Jira itself and cannot be restricted. Thus, the users (servers of users) can use the REST API as well as the Jira use. In other words, the users can do anything they can do in Jira via REST API.
So, I am looking for any other possibilities even I know that issue. I want some brain storming, actually.
Is there any way to restrict the usage of REST API?
I want to know that the request is made by the user; not by the Jira or not from the Jira web pages. Is there any token or any other way to understand the requester?
If I know that, I can restrict or manipulate the request maybe. And probably the next question will be how can I do that?
Thanks for your valuable comments.
Have a nice day!