Skip to content

Jira

Jira is a ticket integration, configured in the app next to GitHub. The SDKs do not call Jira. Vulnify uses the connection to create, transition, and comment on issues in one project.

The app asks for the Atlassian account email and an API token created at id.atlassian.com. The token is stored encrypted. Replacing it uses the same email and takes effect on the next ticket.

Field Constraint shown in the app
Site https address of the Jira site, without a path.
Project key Jira project key, for example SEC. The form uppercases it.
Issue type Issue type name. The form starts at Task.
Labels Optional, comma-separated, up to 10, no spaces inside a label.

The same rules as GitHub. The form starts with tickets on block and on review, and a minimum risk of LOW. You can set a transition for an approved review and a transition for denied or expired.

Disconnecting revokes the stored token and stops queued jobs. Issues already created stay, with their links on the Vulnify events.

A Jira credential is not a gateway upstream credential. Gateway routes inject credentials from API integrations only.