You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Postman中用OAuth访问令牌调用Jira Server REST API?直接传参无效

Hey there, let's figure out why your approach isn't working and get you up and running with Jira Server REST API authentication correctly.

First off, the key issue here is that Jira Server's REST API doesn't support passing an access_token as a URL query parameter—that's a pattern more commonly used in some OAuth 2.0 frontend flows, but Jira Server follows stricter OAuth 1.0a or OAuth 2.0 (for newer versions) authentication standards that require tokens to be handled via request headers or proper OAuth signing.

Let's break down the correct implementation for both common OAuth methods in Postman:


OAuth 1.0a (Most common for older Jira Server versions)

Jira Server traditionally uses OAuth 1.0a for API authentication, which requires signature generation rather than just a token parameter. Here's how to set it up in Postman:

  • Step 1: Create an OAuth consumer in Jira Server

    1. Log into Jira as an admin, go to Settings > Applications > Application links
    2. Create a new application link (use any dummy URL if you don't have one, you'll edit it next)
    3. Once created, click the Edit button for the link, navigate to the Incoming Authentication tab
    4. Fill in a Consumer Key (make a note of this), Consumer Secret (save this securely too), and set the Callback URL to https://www.getpostman.com/oauth2/callback (Postman's default callback)
    5. Save the settings
  • Step 2: Configure Postman for OAuth 1.0

    1. Open your Jira API request in Postman (e.g., http://localhost:8080/rest/api/2/issuetype)
    2. Switch to the Authorization tab
    3. Set the Type to OAuth 1.0
    4. Paste your Consumer Key and Consumer Secret into the respective fields
    5. Click Get New Access Token—this will open a Jira login window where you'll authorize the Postman app
    6. Once authorized, Postman will auto-populate the Token and Token Secret fields
    7. Send your request—Postman will automatically add the required OAuth 1.0 signature headers, and your API call should work now

OAuth 2.0 (For Jira Server 7.10+)

If you're running a newer Jira Server version (7.10 or later), you can use OAuth 2.0 which is a bit simpler:

  • Step 1: Create an OAuth 2.0 client in Jira Server

    1. Log into Jira as admin, go to Settings > Applications > OAuth 2.0 > Client registration
    2. Click Register client
    3. Fill in the client details:
      • Client ID: Auto-generated, make a note of it
      • Client Secret: Generate and save this securely
      • Authorization grant type: Select Authorization code
      • Redirect URI: Use https://www.getpostman.com/oauth2/callback (Postman's default)
      • Scopes: Add the necessary scopes (e.g., read:jira-work for viewing issue types)
    4. Save the client
  • Step 2: Configure Postman for OAuth 2.0

    1. Open your Jira API request in Postman
    2. Go to the Authorization tab, set Type to OAuth 2.0
    3. Click Get New Access Token
    4. Fill in the token configuration:
      • Token Name: Any name you like
      • Grant Type: Authorization Code
      • Callback URL: https://www.getpostman.com/oauth2/callback
      • Auth URL: Your Jira Server's OAuth authorize endpoint, e.g., http://localhost:8080/oauth/authorize
      • Access Token URL: http://localhost:8080/oauth/token
      • Client ID: The one you saved earlier
      • Client Secret: The generated secret
      • Scope: The scopes you selected in Jira (e.g., read:jira-work)
    5. Click Request Token—authorize the app in the Jira window that pops up
    6. Postman will add the Authorization: Bearer <your-access-token> header to your request automatically. Now send the API call, and it should succeed.

Quick Checks to Avoid Common Issues

  • Make sure your Jira user account has the necessary permissions to access the API endpoint (e.g., the "Browse Projects" permission for viewing issue types)
  • Double-check your API URL—Jira Server's REST API uses the /rest/api/2/ prefix, so your issue type endpoint should be http://localhost:8080/rest/api/2/issuetype (no extra parameters needed once auth is set up)
  • For OAuth 2.0, confirm that Jira Server has OAuth 2.0 enabled in the admin settings (it's disabled by default in some versions)

内容的提问来源于stack exchange,提问作者Aahel Guha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:58:22