Browse documentation

Hooks / Docs / Security and data

Security and data

Last updated 24/08/2026

  • Forge-native, zero egress. Every function runs inside Atlassian's sandboxed runtime. The app operates no external servers and makes no external network calls — no analytics, no third parties.
  • Your scripts stay in Atlassian. Scripts, versions, run history, and job records live in Forge Key-Value storage, encrypted at rest and tied to your site.
  • Admin-only. The app is a Jira admin page and every backend endpoint independently verifies the caller holds Administer Jira.
  • Curated script surface. Scripts receive only jira, console, and context — no require, process, or Forge SDK.
  • Scopes: read:jira-user, read:jira-work, write:jira-work, storage:app. Scripts normally run as the app; the Console's “Run as: me” runs a single script with the invoking admin's own permissions.

Full policies: Privacy · Security.