Evidence-backed facts
- Jira REST v3 exposes programmatic resource operations, and each operation documents scopes, permissions, anonymous availability, pagination, and response behavior. informative
- A mutating operation requires both the API authorization mechanism and the calling user or app's Jira permissions for the target resource. informative
- Forge uses scopes, Connect uses JWT and scopes or impersonation, and other integrations are directed to OAuth 2.0 authorization-code grants; basic auth is for personal scripts. informative
- Anonymous access exists only where an operation explicitly declares it and underlying Jira permissions permit it; authentication never bypasses project or issue security. informative