Assets API returning 401 for all requests

Recently noticed that Connect JWT Bearer Token auth calls to Assets API endpoints such as
https://api.atlassian.com/jsm/assets/workspace/{workspaceId}/v1/objectschema/list

Are returning a 401: Unauthorized response despite the impersonated user having the appropriate JSM license and permissions to call this API. This is happening for multiple test instances with different workspace IDs. I don’t see anything from Atlassian about the authentication requirements for these endpoints changing.

Hello @ray_rarey

In your example request URL, it starts with ‘https://api.atlassian.com’ but you said you are making the request from a Connect app and using a JWT token.

In that scenario, shouldn’t the path start with the JSM site name?

https://{JSMSiteName}/jsm/assets/workspace/{workspaceId}/v1/objectschema/list

Hi @anon96974232,

We had considered this because the documentation is a little vague. Although calls to the endpoints I mentioned in my first post had previously been working properly. In the interest of being thorough, we did test with the {JSMSiteName} base instead of the api.atlassian.com base, but those calls return a 404 instead of a 401.

OK.

I’m using the https://api.atlassian.com base path for my requests, but I’m using OAuth and haven’t noticed any changes to access permissions.

I don’t use Connect + JWT or Basic Auth any more, so can’t comment any further on changes that would affect a single user’s permissions to that endpoint.

You can use https://{JSMSiteName}.atlassian.net/gateway/api/jsm/assets/workspace/{workspaceId}/v1 to access assets from a Connect app using JWT. Just checked it again and it’s still working.

We are having the same problem. The issue started on Friday, Sept 12th. Things were fine before that. The URL you sent doesn’t work for us.

I have a ticket opened with support but it has not been solved. All JSM endpoints are returning 401 - Unauthorized at the moment.

@LaisZagattiPedro , thank you for posting this! I was starting to think I was going crazy. Please let us know if Atlassian resolves the issue for you.

@ray_rarey API seems to be working now!

@LaisZagattiPedro I was just coming here to say the same thing! Not sure what happened but everything looks good from our end now as well. :+1: