Hooks / Docs / Security and data
Security and data
Last updated 24/08/2026
- Forge-native, zero egress. Every function runs inside Atlassian's sandboxed runtime. The app operates no external servers and makes no external network calls — no analytics, no third parties.
- Your scripts stay in Atlassian. Scripts, versions, run history, and job records live in Forge Key-Value storage, encrypted at rest and tied to your site.
- Admin-only. The app is a Jira admin page and every backend endpoint independently verifies the caller holds Administer Jira.
- Curated script surface. Scripts receive only
jira,console, andcontext— norequire,process, or Forge SDK. - Scopes:
read:jira-user,read:jira-work,write:jira-work,storage:app. Scripts normally run as the app; the Console's “Run as: me” runs a single script with the invoking admin's own permissions.