openapi: 3.2.0 info: contact: email: ecosystem@atlassian.com description: Jira Cloud platform REST API documentation license: name: Apache 2.0 url: http://www.apache.org/licenses/LICENSE-2.0.html termsOfService: https://developer.atlassian.com/platform/marketplace/atlassian-developer-terms/ title: Jira Cloud platform REST Issue security schemes API version: 1001.0.0-SNAPSHOT-82b018affa468e58f284fbe4df33536469d757df servers: - url: https://your-domain.atlassian.net tags: - description: 'This resource represents issue security schemes. Use it to get an issue security scheme or a list of issue security schemes. Issue security schemes control which users or groups of users can view an issue. When an issue security scheme is associated with a project, its security levels can be applied to issues in that project. Sub-tasks also inherit the security level of their parent issue.' name: Issue Security Schemes paths: /rest/api/3/issuesecurityschemes: get: deprecated: false description: 'Returns all issue security schemes. **Permissions required:** *Administer Jira* global permission.' operationId: getIssueSecuritySchemes parameters: [] responses: '200': content: application/json: example: '{"issueSecuritySchemes":[{"defaultSecurityLevelId":10021,"description":"Description for the default issue security scheme","id":10000,"name":"Default Issue Security Scheme","self":"https://your-domain.atlassian.net/rest/api/3/issuesecurityschemes/10000"}]}' schema: $ref: '#/components/schemas/SecuritySchemes' description: Returned if the request is successful. '401': description: Returned if the authentication credentials are incorrect. '403': description: Returned if the user does not have permission to administer issue security schemes. security: - basicAuth: [] - OAuth2: - manage:jira-project summary: Get issue security schemes tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-atlassian-oauth2-scopes: - scheme: OAuth2 scopes: - manage:jira-project state: Current - scheme: OAuth2 scopes: - read:issue-security-level:jira - read:issue-security-scheme:jira state: Beta x-atlassian-connect-scope: PROJECT_ADMIN post: deprecated: false description: 'Creates a security scheme with security scheme levels and levels'' members. You can create up to 100 security scheme levels and security scheme levels'' members per request. **Permissions required:** *Administer Jira* global permission.' operationId: createIssueSecurityScheme parameters: [] requestBody: content: application/json: example: description: Newly created issue security scheme levels: - description: Newly created level isDefault: true members: - parameter: administrators type: group name: New level name: New security scheme schema: $ref: '#/components/schemas/CreateIssueSecuritySchemeDetails' required: true responses: '201': content: application/json: example: '{"id":"10001"}' schema: $ref: '#/components/schemas/SecuritySchemeId' description: Returned if the request is successful. '400': content: application/json: example: '{"errorMessages":["The length of the description must not exceed 4,000 characters."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the request is invalid. '401': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the user doesn't have the necessary permission. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Create issue security scheme tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-experimental: true x-atlassian-connect-scope: INACCESSIBLE /rest/api/3/issuesecurityschemes/level: get: deprecated: false description: 'Returns a paginated list of issue security levels. Only issue security levels in the context of classic projects are returned. Filtering using IDs is inclusive: if you specify both security scheme IDs and level IDs, the result will include both specified issue security levels and all issue security levels from the specified schemes. **Permissions required:** *Administer Jira* global permission.' operationId: getSecurityLevels parameters: - description: The index of the first item to return in a page of results (page offset). in: query name: startAt schema: default: '0' type: string - description: The maximum number of items to return per page. in: query name: maxResults schema: default: '50' type: string - description: 'The list of issue security scheme level IDs. To include multiple issue security levels, separate IDs with an ampersand: `id=10000&id=10001`.' in: query name: id schema: items: type: string type: array uniqueItems: true - description: 'The list of issue security scheme IDs. To include multiple issue security schemes, separate IDs with an ampersand: `schemeId=10000&schemeId=10001`.' in: query name: schemeId schema: items: type: string type: array uniqueItems: true - description: When set to true, returns multiple default levels for each security scheme containing a default. If you provide scheme and level IDs not associated with the default, returns an empty page. The default value is false. in: query name: onlyDefault schema: default: false type: boolean responses: '200': content: application/json: example: '{"isLast":true,"maxResults":50,"startAt":0,"total":1,"values":[{"description":"Only the reporter and internal staff can see this issue.","id":"10021","isDefault":true,"issueSecuritySchemeId":"10001","name":"Reporter Only","self":"https://your-domain.atlassian.net/rest/api/3/issuesecurityscheme/level?id=10021"}]}' schema: $ref: '#/components/schemas/PageBeanSecurityLevel' description: Returned if the request is successful. '400': content: application/json: example: '{"errorMessages":["-1000 is not a valid value. id must be zero or a positive integer."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the request is invalid. '401': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the user doesn't have the necessary permission. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Get issue security levels tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-atlassian-oauth2-scopes: - scheme: OAuth2 scopes: - manage:jira-configuration state: Current - scheme: OAuth2 scopes: - read:issue-security-level:jira - read:issue-security-scheme:jira state: Beta x-experimental: true x-atlassian-connect-scope: PROJECT_ADMIN /rest/api/3/issuesecurityschemes/level/default: put: deprecated: false description: 'Sets default issue security levels for schemes. **Permissions required:** *Administer Jira* global permission.' operationId: setDefaultLevels parameters: [] requestBody: content: application/json: example: defaultValues: - defaultLevelId: '20000' issueSecuritySchemeId: '10000' - defaultLevelId: '30000' issueSecuritySchemeId: '12000' schema: $ref: '#/components/schemas/SetDefaultLevelsRequest' required: true responses: '204': content: application/json: schema: {} description: Returned if the request is successful. '400': content: application/json: example: '{"errorMessages":["some-wrong-string is not a valid value. The issue security scheme ID must be a positive integer."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the request is invalid. '401': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the user doesn't have the necessary permission. '404': content: application/json: example: '{"errorMessages":["Issue security scheme with ID 10000 not found."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the issue resolution isn't found. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Set default issue security levels tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-experimental: true x-atlassian-connect-scope: INACCESSIBLE /rest/api/3/issuesecurityschemes/level/member: get: deprecated: false description: 'Returns a paginated list of issue security level members. Only issue security level members in the context of classic projects are returned. Filtering using parameters is inclusive: if you specify both security scheme IDs and level IDs, the result will include all issue security level members from the specified schemes and levels. **Permissions required:** *Administer Jira* global permission.' operationId: getSecurityLevelMembers parameters: - description: The index of the first item to return in a page of results (page offset). in: query name: startAt schema: default: '0' type: string - description: The maximum number of items to return per page. in: query name: maxResults schema: default: '50' type: string - description: 'The list of issue security level member IDs. To include multiple issue security level members separate IDs with an ampersand: `id=10000&id=10001`.' in: query name: id schema: items: type: string type: array uniqueItems: true - description: 'The list of issue security scheme IDs. To include multiple issue security schemes separate IDs with an ampersand: `schemeId=10000&schemeId=10001`.' in: query name: schemeId schema: items: type: string type: array uniqueItems: true - description: 'The list of issue security level IDs. To include multiple issue security levels separate IDs with an ampersand: `levelId=10000&levelId=10001`.' in: query name: levelId schema: items: type: string type: array uniqueItems: true - description: "Use expand to include additional information in the response. This parameter accepts a comma-separated list. Expand options include:\n\n * `all` Returns all expandable information\n * `field` Returns information about the custom field granted the permission\n * `group` Returns information about the group that is granted the permission\n * `projectRole` Returns information about the project role granted the permission\n * `user` Returns information about the user who is granted the permission" in: query name: expand schema: type: string responses: '200': content: application/json: example: '{"isLast":true,"maxResults":100,"startAt":0,"total":3,"values":[{"id":"10000","issueSecurityLevelId":"20010","issueSecuritySchemeId":"10010","holder":{"expand":"group","type":"group"}}]}' schema: $ref: '#/components/schemas/PageBeanSecurityLevelMember' description: Returned if the request is successful. '400': description: Returned if the request is invalid. '401': description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' description: Returned if the user doesn't have the necessary permission. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Get issue security level members tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-atlassian-oauth2-scopes: - scheme: OAuth2 scopes: - manage:jira-configuration state: Current - scheme: OAuth2 scopes: - read:issue-security-level:jira - read:issue-security-scheme:jira state: Beta x-experimental: true x-atlassian-connect-scope: PROJECT_ADMIN /rest/api/3/issuesecurityschemes/project: get: deprecated: false description: Returns a paginated mapping of projects that are using security schemes. You can provide either one or multiple security scheme IDs or project IDs to filter by. If you don't provide any, this will return a list of all mappings. Only issue security schemes in the context of classic projects are supported. **Permissions required:** *Administer Jira* global permission. operationId: searchProjectsUsingSecuritySchemes parameters: - description: The index of the first item to return in a page of results (page offset). in: query name: startAt schema: default: '0' type: string - description: The maximum number of items to return per page. in: query name: maxResults schema: default: '50' type: string - description: The list of security scheme IDs to be filtered out. in: query name: issueSecuritySchemeId schema: items: type: string type: array uniqueItems: true - description: The list of project IDs to be filtered out. in: query name: projectId schema: items: type: string type: array uniqueItems: true responses: '200': content: application/json: example: '{"issueSecuritySchemeId":"10000","projectId":"10000"}' schema: $ref: '#/components/schemas/PageBeanIssueSecuritySchemeToProjectMapping' description: Returned if the request is successful. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the search criteria is invalid.If you specify the project ID parameter '401': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the user doesn't have the necessary permission. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Get projects using issue security schemes tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-experimental: true x-atlassian-connect-scope: PROJECT_ADMIN put: deprecated: false description: 'Associates an issue security scheme with a project and remaps security levels of issues to the new levels, if provided. This operation is asynchronous. Follow the `location` link in the response to determine the status of the task and use Get task to obtain subsequent updates. **Permissions required:** *Administer Jira* global permission.' operationId: associateSchemesToProjects parameters: [] requestBody: content: application/json: example: oldToNewSecurityLevelMappings: - newLevelId: '30001' oldLevelId: '30000' projectId: '10000' schemeId: '20000' schema: $ref: '#/components/schemas/AssociateSecuritySchemeWithProjectDetails' required: true responses: '303': content: application/json: schema: $ref: '#/components/schemas/TaskProgressBeanObject' description: Returned if the request is successful. '400': content: application/json: example: '{"errorMessages":["some-wrong-string is not a valid value. The issue security scheme ID must be a positive integer."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the request is invalid. '401': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the user doesn't have the necessary permission. '404': content: application/json: example: '{"errorMessages":["Issue security scheme with ID 10000 not found."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the security scheme isn't found. '409': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if a task to remove the issue security level is already running. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Associate security scheme to project tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-experimental: true x-atlassian-connect-scope: INACCESSIBLE /rest/api/3/issuesecurityschemes/search: get: deprecated: false description: 'Returns a paginated list of issue security schemes. If you specify the project ID parameter, the result will contain issue security schemes and related project IDs you filter by. Use \{@link IssueSecuritySchemeResource\#searchProjectsUsingSecuritySchemes(String, String, Set, Set)\} to obtain all projects related to scheme. Only issue security schemes in the context of classic projects are returned. **Permissions required:** *Administer Jira* global permission.' operationId: searchSecuritySchemes parameters: - description: The index of the first item to return in a page of results (page offset). in: query name: startAt schema: default: '0' type: string - description: The maximum number of items to return per page. in: query name: maxResults schema: default: '50' type: string - description: 'The list of issue security scheme IDs. To include multiple issue security scheme IDs, separate IDs with an ampersand: `id=10000&id=10001`.' in: query name: id schema: items: type: string type: array uniqueItems: true - description: 'The list of project IDs. To include multiple project IDs, separate IDs with an ampersand: `projectId=10000&projectId=10001`.' in: query name: projectId schema: items: type: string type: array uniqueItems: true responses: '200': content: application/json: example: '{"id":10000,"self":"https://your-domain.atlassian.net/rest/api/3/issuesecurityscheme/10000","name":"Default scheme","description":"Default scheme description","defaultLevel":10001,"projectIds":[10002]}' schema: $ref: '#/components/schemas/PageBeanSecuritySchemeWithProjects' description: Returned if the request is successful. '400': content: application/json: example: '{"errorMessages":["-1000 is not a valid value. id must be zero or a positive integer."],"errors":{}}' description: Returned if the request is invalid. '401': description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' description: Returned if the user doesn't have the necessary permission. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Search issue security schemes tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-atlassian-oauth2-scopes: - scheme: OAuth2 scopes: - manage:jira-configuration state: Current - scheme: OAuth2 scopes: - read:issue-security-level:jira - read:issue-security-scheme:jira state: Beta x-experimental: true x-atlassian-connect-scope: PROJECT_ADMIN /rest/api/3/issuesecurityschemes/{id}: get: deprecated: false description: 'Returns an issue security scheme along with its security levels. **Permissions required:** * *Administer Jira* global permission. * *Administer Projects* project permission for a project that uses the requested issue security scheme.' operationId: getIssueSecurityScheme parameters: - description: The ID of the issue security scheme. Use the [Get issue security schemes](#api-rest-api-3-issuesecurityschemes-get) operation to get a list of issue security scheme IDs. in: path name: id required: true schema: format: int64 type: integer responses: '200': content: application/json: example: '{"defaultSecurityLevelId":10021,"description":"Description for the default issue security scheme","id":10000,"levels":[{"description":"Only the reporter and internal staff can see this issue.","id":"10021","name":"Reporter Only","self":"https://your-domain.atlassian.net/rest/api/3/securitylevel/10021"}],"name":"Default Issue Security Scheme","self":"https://your-domain.atlassian.net/rest/api/3/issuesecurityschemes/10000"}' schema: $ref: '#/components/schemas/SecurityScheme' description: Returned if the request is successful. '401': description: Returned if the authentication credentials are incorrect or missing. '403': description: Returned if the user does not have the administrator permission and the scheme is not used in any project where the user has administrative permission. security: - basicAuth: [] - OAuth2: - manage:jira-project summary: Get issue security scheme tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-atlassian-oauth2-scopes: - scheme: OAuth2 scopes: - manage:jira-project state: Current - scheme: OAuth2 scopes: - read:issue-security-level:jira - read:issue-security-scheme:jira state: Beta x-atlassian-connect-scope: PROJECT_ADMIN put: deprecated: false description: 'Updates the issue security scheme. **Permissions required:** *Administer Jira* global permission.' operationId: updateIssueSecurityScheme parameters: - description: The ID of the issue security scheme. in: path name: id required: true schema: type: string requestBody: content: application/json: example: description: My issue security scheme description name: My issue security scheme name schema: $ref: '#/components/schemas/UpdateIssueSecuritySchemeRequestBean' required: true responses: '204': content: application/json: schema: {} description: Returned if the request is successful. '400': content: application/json: example: '{"errorMessages":["The length of the description must not exceed 4,000 characters."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the request is invalid. '401': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the user doesn't have the necessary permission. '404': content: application/json: example: '{"errorMessages":["Issue security scheme with ID 10000 not found."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the issue security scheme isn't found. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Update issue security scheme tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-experimental: true x-atlassian-connect-scope: INACCESSIBLE /rest/api/3/issuesecurityschemes/{schemeId}: delete: deprecated: false description: 'Deletes an issue security scheme. **Permissions required:** *Administer Jira* global permission.' operationId: deleteSecurityScheme parameters: - description: The ID of the issue security scheme. in: path name: schemeId required: true schema: type: string responses: '204': content: application/json: schema: {} description: Returned if the request is successful. '400': content: application/json: example: '"You can''t delete an issue security scheme if any projects are associated with it."' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the request is invalid. '401': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the user doesn't have the necessary permission. '404': content: application/json: example: '{"errorMessages":["Issue security scheme with ID 10000 not found."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the issue security scheme isn't found. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Delete issue security scheme tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-experimental: true x-atlassian-connect-scope: INACCESSIBLE /rest/api/3/issuesecurityschemes/{schemeId}/level: put: deprecated: false description: 'Adds levels and levels'' members to the issue security scheme. You can add up to 100 levels per request. **Permissions required:** *Administer Jira* global permission.' operationId: addSecurityLevel parameters: - description: The ID of the issue security scheme. in: path name: schemeId required: true schema: type: string requestBody: content: application/json: example: levels: - description: First Level Description isDefault: true members: - type: reporter - parameter: jira-administrators type: group name: First Level schema: $ref: '#/components/schemas/AddSecuritySchemeLevelsRequestBean' required: true responses: '204': content: application/json: schema: {} description: Returned if the request is successful. '400': content: application/json: example: '{"errorMessages":["some-wrong-string is not a valid value. The issue security scheme ID must be a positive integer."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the request is invalid. '401': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the user doesn't have the necessary permission. '404': content: application/json: example: '{"errorMessages":["Issue security scheme with ID 10000 not found."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the security scheme isn't found. '422': content: application/json: schema: $ref: '#/components/schemas/LimitExceededResponseBean' description: 422 response security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Add issue security levels tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-experimental: true x-atlassian-connect-scope: INACCESSIBLE /rest/api/3/issuesecurityschemes/{schemeId}/level/{levelId}: delete: deprecated: false description: 'Deletes an issue security level. This operation is asynchronous. Follow the `location` link in the response to determine the status of the task and use Get task to obtain subsequent updates. **Permissions required:** *Administer Jira* global permission.' operationId: removeLevel parameters: - description: The ID of the issue security scheme. in: path name: schemeId required: true schema: type: string - description: The ID of the issue security level to remove. in: path name: levelId required: true schema: type: string - description: The ID of the issue security level that will replace the currently selected level. in: query name: replaceWith schema: type: string responses: '303': content: application/json: schema: $ref: '#/components/schemas/TaskProgressBeanObject' description: Returned if the request is successful. '400': content: application/json: example: '"You can''t delete an issue security scheme if any projects are associated with it."' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the request isn't valid. '401': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the user doesn't have the necessary permission. '404': content: application/json: example: '{"errorMessages":["Issue security scheme with ID 10000 not found."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the issue security level isn't found. '409': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if a task to remove the issue security level is already running. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Remove issue security level tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-experimental: true x-atlassian-connect-scope: INACCESSIBLE put: deprecated: false description: 'Updates the issue security level. **Permissions required:** *Administer Jira* global permission.' operationId: updateSecurityLevel parameters: - description: The ID of the issue security scheme level belongs to. in: path name: schemeId required: true schema: type: string - description: The ID of the issue security level to update. in: path name: levelId required: true schema: type: string requestBody: content: application/json: example: description: New level description name: New level name schema: $ref: '#/components/schemas/UpdateIssueSecurityLevelDetails' required: true responses: '204': content: application/json: schema: {} description: Returned if the request is successful. '400': content: application/json: example: '{"errorMessages":["The length of the description must not exceed 4,000 characters."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the request isn't valid. '401': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the user doesn't have the necessary permission. '404': content: application/json: example: '{"errorMessages":["Issue security scheme with ID 10000 not found."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the issue security level isn't found. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Update issue security level tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-experimental: true x-atlassian-connect-scope: INACCESSIBLE /rest/api/3/issuesecurityschemes/{schemeId}/level/{levelId}/member: put: deprecated: false description: 'Adds members to the issue security level. You can add up to 100 members per request. **Permissions required:** *Administer Jira* global permission.' operationId: addSecurityLevelMembers parameters: - description: The ID of the issue security scheme. in: path name: schemeId required: true schema: type: string - description: The ID of the issue security level. in: path name: levelId required: true schema: type: string requestBody: content: application/json: example: members: - type: reporter - parameter: jira-administrators type: group schema: $ref: '#/components/schemas/SecuritySchemeMembersRequest' required: true responses: '204': content: application/json: schema: {} description: Returned if the request is successful. '400': content: application/json: example: '{"errorMessages":["some-wrong-string is not a valid value. The issue security scheme ID must be a positive integer."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the request is invalid. '401': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the user doesn't have the necessary permission. '404': content: application/json: example: '{"errorMessages":["Issue security scheme with ID 10000 not found."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the security scheme isn't found. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Add issue security level members tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-experimental: true x-atlassian-connect-scope: INACCESSIBLE /rest/api/3/issuesecurityschemes/{schemeId}/level/{levelId}/member/{memberId}: delete: deprecated: false description: 'Removes an issue security level member from an issue security scheme. **Permissions required:** *Administer Jira* global permission.' operationId: removeMemberFromSecurityLevel parameters: - description: The ID of the issue security scheme. in: path name: schemeId required: true schema: type: string - description: The ID of the issue security level. in: path name: levelId required: true schema: type: string - description: The ID of the issue security level member to be removed. in: path name: memberId required: true schema: type: string responses: '204': content: application/json: schema: {} description: Returned if the request is successful. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the request is invalid. '401': content: application/json: schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the authentication credentials are incorrect or missing. '403': content: application/json: example: '{"errorMessages":["You are not authorized to perform this action. Administrator privileges are required."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the user doesn't have the necessary permission. '404': content: application/json: example: '{"errorMessages":["Issue security scheme with ID 10000 not found."],"errors":{}}' schema: $ref: '#/components/schemas/ErrorCollection' description: Returned if the security scheme isn't found. security: - basicAuth: [] - OAuth2: - manage:jira-configuration summary: Remove member from issue security level tags: - Issue Security Schemes x-atlassian-data-security-policy: - app-access-rule-exempt: true x-experimental: true x-atlassian-connect-scope: INACCESSIBLE components: schemas: SecuritySchemeLevelBean: additionalProperties: false properties: description: description: The description of the issue security scheme level. maxLength: 4000 type: string writeOnly: true isDefault: description: Specifies whether the level is the default level. False by default. type: boolean writeOnly: true members: description: The list of level members which should be added to the issue security scheme level. items: $ref: '#/components/schemas/SecuritySchemeLevelMemberBean' type: array writeOnly: true name: description: The name of the issue security scheme level. Must be unique. maxLength: 255 type: string writeOnly: true required: - name type: object writeOnly: true SecuritySchemeMembersRequest: additionalProperties: false description: Details of issue security scheme level new members. properties: members: description: The list of level members which should be added to the issue security scheme level. items: $ref: '#/components/schemas/SecuritySchemeLevelMemberBean' type: array writeOnly: true required: - securitySchemeLevelMembers type: object PageBeanSecurityLevel: additionalProperties: false description: A page of items. properties: isLast: description: Whether this is the last page. readOnly: true type: boolean maxResults: description: The maximum number of items that could be returned. format: int32 readOnly: true type: integer nextPage: description: If there is another page of results, the URL of the next page. format: uri readOnly: true type: string self: description: The URL of the page. format: uri readOnly: true type: string startAt: description: The index of the first item returned. format: int64 readOnly: true type: integer total: description: The number of items returned. format: int64 readOnly: true type: integer values: description: The list of items. items: $ref: '#/components/schemas/SecurityLevel' readOnly: true type: array type: object CreateIssueSecuritySchemeDetails: additionalProperties: true description: Issue security scheme and it's details properties: description: description: The description of the issue security scheme. maxLength: 255 type: string writeOnly: true levels: description: The list of scheme levels which should be added to the security scheme. items: $ref: '#/components/schemas/SecuritySchemeLevelBean' type: array writeOnly: true name: description: The name of the issue security scheme. Must be unique (case-insensitive). maxLength: 60 type: string writeOnly: true required: - name type: object SecuritySchemeId: additionalProperties: true description: The ID of the issue security scheme. properties: id: description: The ID of the issue security scheme. readOnly: true type: string required: - id type: object SecuritySchemeLevelMemberBean: additionalProperties: false properties: parameter: description: The value corresponding to the specified member type. type: string writeOnly: true type: description: The issue security level member type, e.g `reporter`, `group`, `user`, `projectrole`, `applicationRole`. type: string writeOnly: true required: - type type: object writeOnly: true OldToNewSecurityLevelMappingsBean: additionalProperties: false properties: newLevelId: description: The new issue security level ID. Providing null will clear the assigned old level from issues. type: string writeOnly: true oldLevelId: description: The old issue security level ID. Providing null will remap all issues without any assigned levels. type: string writeOnly: true required: - newLevelId - oldLevelId type: object writeOnly: true SecuritySchemeWithProjects: additionalProperties: true description: Details about an issue security scheme. properties: defaultLevel: description: The default level ID of the issue security scheme. format: int64 readOnly: true type: integer description: description: The description of the issue security scheme. readOnly: true type: string id: description: The ID of the issue security scheme. format: int64 readOnly: true type: integer name: description: The name of the issue security scheme. readOnly: true type: string projectIds: description: The list of project IDs associated with the issue security scheme. items: format: int64 readOnly: true type: integer readOnly: true type: array uniqueItems: true self: description: The URL of the issue security scheme. readOnly: true type: string required: - id - name - self type: object UpdateIssueSecuritySchemeRequestBean: additionalProperties: false properties: description: description: The description of the security scheme scheme. maxLength: 255 type: string writeOnly: true name: description: The name of the security scheme scheme. Must be unique. maxLength: 60 type: string writeOnly: true type: object LimitExceededResponseBean: additionalProperties: false properties: current_count: format: int32 type: integer entity_type: type: string error_code: type: string limit_type: type: string max_allowed_limit: format: int32 type: integer message: type: string scope_id: type: string type: object PageBeanSecurityLevelMember: additionalProperties: false description: A page of items. properties: isLast: description: Whether this is the last page. readOnly: true type: boolean maxResults: description: The maximum number of items that could be returned. format: int32 readOnly: true type: integer nextPage: description: If there is another page of results, the URL of the next page. format: uri readOnly: true type: string self: description: The URL of the page. format: uri readOnly: true type: string startAt: description: The index of the first item returned. format: int64 readOnly: true type: integer total: description: The number of items returned. format: int64 readOnly: true type: integer values: description: The list of items. items: $ref: '#/components/schemas/SecurityLevelMember' readOnly: true type: array type: object SecurityLevelMember: additionalProperties: true description: Issue security level member. properties: holder: allOf: - $ref: '#/components/schemas/PermissionHolder' description: The user or group being granted the permission. It consists of a `type` and a type-dependent `parameter`. See [Holder object](../api-group-permission-schemes/#holder-object) in *Get all permission schemes* for more information. readOnly: true id: description: The ID of the issue security level member. readOnly: true type: string issueSecurityLevelId: description: The ID of the issue security level. readOnly: true type: string issueSecuritySchemeId: description: The ID of the issue security scheme. readOnly: true type: string managed: type: boolean writeOnly: true required: - holder - id - issueSecurityLevelId - issueSecuritySchemeId type: object PageBeanSecuritySchemeWithProjects: additionalProperties: false description: A page of items. properties: isLast: description: Whether this is the last page. readOnly: true type: boolean maxResults: description: The maximum number of items that could be returned. format: int32 readOnly: true type: integer nextPage: description: If there is another page of results, the URL of the next page. format: uri readOnly: true type: string self: description: The URL of the page. format: uri readOnly: true type: string startAt: description: The index of the first item returned. format: int64 readOnly: true type: integer total: description: The number of items returned. format: int64 readOnly: true type: integer values: description: The list of items. items: $ref: '#/components/schemas/SecuritySchemeWithProjects' readOnly: true type: array type: object SecurityScheme: additionalProperties: false description: Details about a security scheme. properties: defaultSecurityLevelId: description: The ID of the default security level. format: int64 readOnly: true type: integer description: description: The description of the issue security scheme. readOnly: true type: string id: description: The ID of the issue security scheme. format: int64 readOnly: true type: integer levels: items: $ref: '#/components/schemas/SecurityLevel' type: array name: description: The name of the issue security scheme. readOnly: true type: string self: description: The URL of the issue security scheme. readOnly: true type: string type: object AssociateSecuritySchemeWithProjectDetails: additionalProperties: false description: Issue security scheme, project, and remapping details. properties: oldToNewSecurityLevelMappings: description: The list of scheme levels which should be remapped to new levels of the issue security scheme. items: $ref: '#/components/schemas/OldToNewSecurityLevelMappingsBean' type: array writeOnly: true projectId: description: The ID of the project. type: string writeOnly: true schemeId: description: The ID of the issue security scheme. Providing null will clear the association with the issue security scheme. type: string writeOnly: true required: - projectId - schemeId type: object ErrorCollection: additionalProperties: false description: Error messages from an operation. properties: errorMessages: description: The list of error messages produced by this operation. For example, "input parameter 'key' must be provided" items: type: string type: array errors: additionalProperties: type: string description: 'The list of errors by parameter returned by the operation. For example,"projectKey": "Project keys must start with an uppercase letter, followed by one or more uppercase alphanumeric characters."' type: object status: format: int32 type: integer type: object SecuritySchemes: additionalProperties: false description: List of security schemes. properties: issueSecuritySchemes: description: List of security schemes. items: $ref: '#/components/schemas/SecurityScheme' readOnly: true type: array type: object PageBeanIssueSecuritySchemeToProjectMapping: additionalProperties: false description: A page of items. properties: isLast: description: Whether this is the last page. readOnly: true type: boolean maxResults: description: The maximum number of items that could be returned. format: int32 readOnly: true type: integer nextPage: description: If there is another page of results, the URL of the next page. format: uri readOnly: true type: string self: description: The URL of the page. format: uri readOnly: true type: string startAt: description: The index of the first item returned. format: int64 readOnly: true type: integer total: description: The number of items returned. format: int64 readOnly: true type: integer values: description: The list of items. items: $ref: '#/components/schemas/IssueSecuritySchemeToProjectMapping' readOnly: true type: array type: object AddSecuritySchemeLevelsRequestBean: additionalProperties: false properties: levels: description: The list of scheme levels which should be added to the security scheme. items: $ref: '#/components/schemas/SecuritySchemeLevelBean' type: array writeOnly: true type: object SecurityLevel: additionalProperties: false description: Details of an issue level security item. properties: description: description: The description of the issue level security item. readOnly: true type: string id: description: The ID of the issue level security item. readOnly: true type: string isDefault: description: Whether the issue level security item is the default. readOnly: true type: boolean issueSecuritySchemeId: description: The ID of the issue level security scheme. readOnly: true type: string name: description: The name of the issue level security item. readOnly: true type: string self: description: The URL of the issue level security item. readOnly: true type: string type: object TaskProgressBeanObject: additionalProperties: false description: Details about a task. properties: description: description: The description of the task. type: string elapsedRuntime: description: The execution time of the task, in milliseconds. format: int64 type: integer finished: description: A timestamp recording when the task was finished. format: int64 type: integer id: description: The ID of the task. type: string lastUpdate: description: A timestamp recording when the task progress was last updated. format: int64 type: integer message: description: Information about the progress of the task. type: string progress: description: The progress of the task, as a percentage complete. format: int64 type: integer result: description: The result of the task execution. self: description: The URL of the task. format: uri type: string started: description: A timestamp recording when the task was started. format: int64 type: integer status: description: The status of the task. enum: - ENQUEUED - RUNNING - COMPLETE - FAILED - CANCEL_REQUESTED - CANCELLED - DEAD type: string submitted: description: A timestamp recording when the task was submitted. format: int64 type: integer submittedBy: description: The ID of the user who submitted the task. format: int64 type: integer required: - elapsedRuntime - id - lastUpdate - progress - self - status - submitted - submittedBy type: object UpdateIssueSecurityLevelDetails: additionalProperties: true description: Details of issue security scheme level. properties: description: description: The description of the issue security scheme level. maxLength: 255 type: string writeOnly: true name: description: The name of the issue security scheme level. Must be unique. maxLength: 60 type: string writeOnly: true type: object SetDefaultLevelsRequest: additionalProperties: true description: Details of new default levels. properties: defaultValues: description: List of objects with issue security scheme ID and new default level ID. items: $ref: '#/components/schemas/DefaultLevelValue' maxLength: 1000 type: array writeOnly: true required: - defaultValues type: object IssueSecuritySchemeToProjectMapping: additionalProperties: true description: Details about an project using security scheme mapping. properties: issueSecuritySchemeId: readOnly: true type: string projectId: readOnly: true type: string type: object DefaultLevelValue: additionalProperties: true description: Details of scheme and new default level. maxLength: 1000 properties: defaultLevelId: description: The ID of the issue security level to set as default for the specified scheme. Providing null will reset the default level. type: string writeOnly: true issueSecuritySchemeId: description: The ID of the issue security scheme to set default level for. type: string writeOnly: true required: - defaultLevelId - issueSecuritySchemeId type: object writeOnly: true PermissionHolder: additionalProperties: false description: Details of a user, group, field, or project role that holds a permission. See [Holder object](../api-group-permission-schemes/#holder-object) in *Get all permission schemes* for more information. properties: expand: description: Expand options that include additional permission holder details in the response. readOnly: true type: string parameter: description: As a group's name can change, use of `value` is recommended. The identifier associated withthe `type` value that defines the holder of the permission. type: string type: description: The type of permission holder. type: string value: description: The identifier associated with the `type` value that defines the holder of the permission. type: string required: - type type: object securitySchemes: OAuth2: description: OAuth2 scopes for Jira flows: authorizationCode: authorizationUrl: https://auth.atlassian.com/authorize scopes: delete:async-task:jira: Delete asynchronous task. delete:attachment:jira: Delete issue attachments. delete:avatar:jira: Delete system and custom avatars. delete:comment.property:jira: Delete issue comment properties. delete:comment:jira: Delete issue comments. delete:dashboard.property:jira: Delete dashboard properties. delete:dashboard:jira: Delete dashboards. delete:field-configuration-scheme:jira: Delete field configuration schemes. delete:field-configuration:jira: Delete field configurations. delete:field.option:jira: Delete field options. delete:field:jira: Delete fields. delete:filter.column:jira: Delete filter columns. delete:filter:jira: Delete filters. delete:group:jira: Delete user groups. delete:issue-link-type:jira: Delete issue link types. delete:issue-link:jira: Delete issue links. delete:issue-type-scheme:jira: Delete issue type schemes. delete:issue-type-screen-scheme:jira: Delete issue type screen schemes. delete:issue-type.property:jira: Delete issue type properties. delete:issue-type:jira: Delete issue types. delete:issue-worklog.property:jira: Delete issue worklog properties. delete:issue-worklog:jira: Delete issue worklogs. delete:issue.property:jira: Delete issue properties. delete:issue.remote-link:jira: Delete issue remote links. delete:issue:jira: Delete issues. delete:permission-scheme:jira: Delete permission schemes. delete:permission:jira: Delete permissions. delete:project-category:jira: Delete project categories. delete:project-role:jira: Delete project roles. delete:project-version:jira: Delete project versions. delete:project.avatar:jira: Delete project avatars. delete:project.component:jira: Delete project components. delete:project.property:jira: Delete project properties. delete:project:jira: Delete projects and their details, such as issue types, project lead, and avatars. delete:screen-scheme:jira: Delete screen schemes. delete:screen-tab:jira: Delete screen tabs. delete:screen:jira: Delete screens. delete:screenable-field:jira: Delete screenable fields. delete:user-configuration:jira: Delete user configurations. delete:user.property:jira: Delete user properties. delete:webhook:jira: Delete webhooks. delete:workflow-scheme:jira: Delete workflow schemes. delete:workflow.property:jira: Delete workflow properties. delete:workflow:jira: Delete workflows. manage:jira-configuration: Configure Jira settings that require the Jira administrators permission, for example, create projects and custom fields, view workflows, manage issue link types. manage:jira-project: Create and edit project settings and create new project-level objects, for example, versions, components. manage:jira-webhook: Manage Jira webhooks. Enables an OAuth app to register and unregister dynamic webhooks in Jira. It also provides for fetching of registered webhooks. read:app-data:jira: Read app data. read:application-role:jira: View application roles. read:attachment:jira: View issue attachments. read:audit-log:jira: View audit logs. read:avatar:jira: View system and custom avatars. read:comment.property:jira: View issue comment properties. read:comment:jira: View issue comments. read:custom-field-contextual-configuration:jira: Read custom field contextual configurations. read:dashboard.property:jira: View dashboard properties. read:dashboard:jira: View dashboards. read:email-address:jira: View email addresses of all users regardless of the user's profile visibility settings. read:field-configuration-scheme:jira: View field configuration schemes. read:field-configuration:jira: Read field configurations. read:field.default-value:jira: View field default values. read:field.option:jira: View field options. read:field.options:jira: Read field options. read:field:jira: View fields. read:filter.column:jira: View filter columns. read:filter.default-share-scope:jira: View filter default share scopes. read:filter:jira: View filters. read:group:jira: View user groups. read:instance-configuration:jira: View instance configurations. read:issue-details:jira: View issue details. read:issue-event:jira: Read issue events. read:issue-field-values:jira: View issue field valueses. read:issue-link-type:jira: View issue link types. read:issue-link:jira: View issue links. read:issue-meta:jira: View issue meta. read:issue-security-level:jira: View issue security levels. read:issue-security-scheme:jira: View issue security schemes. read:issue-status:jira: View issue statuses. read:issue-type-hierarchy:jira: Read issue type hierarchies. read:issue-type-scheme:jira: View issue type schemes. read:issue-type-screen-scheme:jira: View issue type screen schemes. read:issue-type.property:jira: View issue type properties. read:issue-type:jira: View issue types. read:issue-worklog.property:jira: View issue worklog properties. read:issue-worklog:jira: View issue worklogs. read:issue.changelog:jira: View issue changelogs. read:issue.property:jira: View issue properties. read:issue.remote-link:jira: View issue remote links. read:issue.time-tracking:jira: View issue time trackings. read:issue.transition:jira: View issue transitions. read:issue.vote:jira: View issue votes. read:issue.votes:jira: View issue voteses. read:issue.watcher:jira: View issue watchers. read:issue:jira: View issues. read:jira-expressions:jira: View jira expressions. read:jira-user: View user information in Jira that you have access to, including usernames, email addresses, and avatars. read:jira-work: Read project and issue data. Search for issues and objects associated with issues (such as attachments and worklogs). read:jql:jira: View JQL. read:label:jira: View labels. read:license:jira: View licenses. read:notification-scheme:jira: View notification schemes. read:permission-scheme:jira: View permission schemes. read:permission:jira: View permissions. read:priority:jira: View priorities. read:project-category:jira: View project categories. read:project-role:jira: View project roles. read:project-type:jira: View project types. read:project-version:jira: View project versions. read:project.avatar:jira: Read project avatars. read:project.component:jira: View project components. read:project.email:jira: View project emails. read:project.feature:jira: Read project features. read:project.property:jira: View project properties. read:project:jira: View projects. read:resolution:jira: View resolutions. read:role:jira: View roles. read:screen-field:jira: View screen fields. read:screen-scheme:jira: View screen schemes. read:screen-tab:jira: View screen tabs. read:screen:jira: View screens. read:screenable-field:jira: View screenable fields. read:status:jira: View statuses. read:user-configuration:jira: View user configurations. read:user.columns:jira: View user columnses. read:user.property:jira: View user properties. read:user:jira: View users. read:webhook:jira: View webhooks. read:workflow-scheme:jira: View workflow schemes. read:workflow.property:jira: View workflow properties. read:workflow:jira: View workflows. send:notification:jira: Send notifications. validate:jql:jira: Validate JQL. write:app-data:jira: Write app data. write:attachment:jira: Create and update issue attachments. write:avatar:jira: Create and update system and custom avatars. write:comment.property:jira: Create and update issue comment properties. write:comment:jira: Create and update issue comments. write:custom-field-contextual-configuration:jira: Save custom field contextual configurations. write:dashboard.property:jira: Create and update dashboard properties. write:dashboard:jira: Create and update dashboards. write:field-configuration-scheme:jira: Create and update field configuration schemes. write:field-configuration:jira: Save field configurations. write:field.default-value:jira: Create and update field default values. write:field.option:jira: Create and update field options. write:field:jira: Create and update fields. write:filter.column:jira: Create and update filter columns. write:filter.default-share-scope:jira: Create and update filter default share scopes. write:filter:jira: Create and update filters. write:group:jira: Create and update user groups. write:instance-configuration:jira: Create and update instance configurations. write:issue-link-type:jira: Create and update issue link types. write:issue-link:jira: Create and update issue links. write:issue-type-scheme:jira: Create and update issue type schemes. write:issue-type-screen-scheme:jira: Create and update issue type screen schemes. write:issue-type.property:jira: Create and update issue type properties. write:issue-type:jira: Create and update issue types. write:issue-worklog.property:jira: Create and update issue worklog properties. write:issue-worklog:jira: Create and update issue worklogs. write:issue.property:jira: Create and update issue properties. write:issue.remote-link:jira: Create and update issue remote links. write:issue.time-tracking:jira: Create and update issue time trackings. write:issue.vote:jira: Create and update issue votes. write:issue.watcher:jira: Create and update issue watchers. write:issue:jira: Create and update issues. write:jira-work: Create and edit issues in Jira, post comments, create worklogs, and delete issues. write:permission-scheme:jira: Create and update permission schemes. write:permission:jira: Create and update permissions. write:project-category:jira: Create and update project categories. write:project-role:jira: Create and update project roles. write:project-version:jira: Create and update project versions. write:project.avatar:jira: Create and update project avatars. write:project.component:jira: Create and update project components. write:project.email:jira: Create and update project emails. write:project.feature:jira: Save project features. write:project.property:jira: Create and update project properties. write:project:jira: Create and update projects. write:screen-scheme:jira: Create and update screen schemes. write:screen-tab:jira: Create and update screen tabs. write:screen:jira: Create and update screens. write:screenable-field:jira: Create and update screenable fields. write:user-configuration:jira: Create and update user configurations. write:user.property:jira: Create and update user properties. write:webhook:jira: Create and update webhooks. write:workflow-scheme:jira: Create and update workflow schemes. write:workflow.property:jira: Create and update workflow properties. write:workflow:jira: Create and update workflows. tokenUrl: https://auth.atlassian.com/oauth/token type: oauth2 basicAuth: description: You can access this resource via basic auth. scheme: basic type: http externalDocs: description: Find out more about Atlassian products and services. url: http://www.atlassian.com x-atlassian-narrative: documents: - anchor: about body: "The Jira REST API enables you to interact with Jira programmatically. Use this API to \n[build apps](https://developer.atlassian.com/cloud/jira/platform/integrating-with-jira-cloud/), script interactions with \nJira, or develop any other type of integration. This page documents the REST resources available in Jira Cloud, including \nthe HTTP response codes and example requests and responses." title: About - anchor: version body: "This documentation is for **version 3** of the Jira Cloud platform REST API, which is the latest\nversion. [Version 2](https://developer.atlassian.com/cloud/jira/platform/rest/v2/) and\nversion 3 of the API offer the same collection of operations. However, version 3 provides support for\nthe [Atlassian Document Format](https://developer.atlassian.com/cloud/jira/platform/apis/document/structure/)\n(ADF) in:\n- `body` in comments, including where comments are used in issue, issue link, and transition resources.\n- `comment` in worklogs.\n- `description` and `environment` fields in issues.\n- `textarea` type custom fields (multi-line text fields) in issues. Single line custom fields\n (`textfield`) accept a string and don't handle Atlassian Document Format content.\n" title: Version - anchor: authentication body: "### Forge apps\n\nFor Forge apps, [REST API scopes](https://developer.atlassian.com/cloud/jira/platform/scopes-for-oauth-2-3LO-and-forge-apps/) \nare used when authenticating with Jira Cloud platform. See [Add scopes to call an Atlassian REST API](https://developer.atlassian.com/platform/forge/add-scopes-to-call-an-atlassian-rest-api/) for more details.\n\nThe URIs for Forge app REST API calls have this structure:\n\n`/rest/api/3/`\n\nFor example, `/rest/api/3/issue/DEMO-1`\n\n### Connect apps\n\nFor Connect apps, authentication (JWT-based) is built into the Connect libraries. Authorization is implemented using either \nscopes (shown as _App scope required_ for operations on this page) or user impersonation. See \n[Security for Connect apps](https://developer.atlassian.com/cloud/jira/platform/security-for-connect-apps/) \nfor details.\n\nThe URIs for Connect app REST API calls have this structure:\n\n`https:///rest/api/3/`\n\nFor example, `https://your-domain.atlassian.net/rest/api/3/issue/DEMO-1`\n\n### Other integrations\n\nFor integrations that are not Forge or Connect apps, use OAuth 2.0 authorization code grants (3LO) for security \n(3LO scopes are shown as for operations _OAuth scopes required_). See \n[OAuth 2.0 (3LO) apps](https://developer.atlassian.com/cloud/jira/platform/oauth-2-3lo-apps/) \nfor details.\n\nThe URIs for OAuth 2.0 (3LO) app REST API calls have this structure:\n\n`https://api.atlassian.com/ex/jira//rest/api/3/`\n\nFor example, `https://api.atlassian.com/ex/jira/35273b54-3f06-40d2-880f-dd28cf8daafa/rest/api/3/issue/DEMO-1`\n\n### Ad-hoc API calls\n\nFor personal scripts, bots, and ad-hoc execution of the REST APIs use basic authentication. See [Basic auth for REST APIs](https://developer.atlassian.com/cloud/jira/platform/basic-auth-for-rest-apis/) for details. \n\nThe URIs for basic authentication REST API calls have this structure:\n\n`https:///rest/api/3/`\n\nFor example, `https://your-domain.atlassian.net/rest/api/3/issue/DEMO-1`\n" title: Authentication and authorization - anchor: permissions body: "### Operation permissions\n\nMost operations in this API require permissions. The calling user must have the required permissions for an operation to \nuse it. Note that for Connect apps, the app user must have the required permissions for the operation and the app must \nhave scopes that permit the operation.\n\nA permission can be granted to a group, project role, or issue role that the user is a member of, or granted directly to a user. \nSee [Permissions overview](https://confluence.atlassian.com/x/FQiiLQ) for details. The most common permissions are:\n\n- **Administer the Cloud site**: Users in the _site-admins_ group have this \npermission. See [Manage groups](https://confluence.atlassian.com/x/24xjL) for details.\n- **Administer Jira**: Granted by the _Jira Administrators_ global permission. There is a default group for this permission. \nSee [Manage groups](https://confluence.atlassian.com/x/24xjL) and [Managing global permissions](https://confluence.atlassian.com/x/x4dKLg) for details.\n- **Administer a project in Jira**: Granted by the _Administer projects_ project permission for a project. This can be \ngranted to a user, a group, a project role, and more. \nSee [Managing project permissions](https://confluence.atlassian.com/x/yodKLg) for details.\n- **Access a project in Jira**: Granted by the _Browse projects_ project permission for a project. This can be \ngranted to a user, a group, a project role, and more. \nSee [Managing project permissions](https://confluence.atlassian.com/x/yodKLg) for details.\n- **Access Jira**: Granted by the _Jira Users_ global permission. Users in the default product access group (for example, \n_jira-software-users-acmesite_) have this permission. \nSee [Manage groups](https://confluence.atlassian.com/x/24xjL) and \n[Managing global permissions](https://confluence.atlassian.com/x/x4dKLg) for details.\n\n### Anonymous access\n\nSome operations provide support for anonymous access. However, anonymous access is only available if \nthe Jira permission needed to access the object or records returned by the operation is granted to \nthe _Public_ group. See [Allowing anonymous access to your project](https://confluence.atlassian.com/x/GDxxLg) \nfor details.\n\nIf an operation is called anonymously and anonymous access is not available, the operation will return \nan error. Note that not all operations that correspond to objects that can be given public access \nprovide for anonymous access.\n" title: Permissions - anchor: expansion body: "### Expansion\n\nThe Jira REST API uses resource expansion, which means that some parts of a resource are not returned unless specified \nin the request. This simplifies responses and minimizes network traffic.\n\nTo expand part of a resource in a request, use the expand query parameter and specify the object(s) to be expanded. \nIf you need to expand nested objects, use the `.` dot notation. If you need to expand multiple objects, use a \ncomma-separated list. \n\nFor example, the following request expands the `names` and `renderedFields` properties for the _JRACLOUD-34423_ issue:\n\n`GET issue/JRACLOUD-34423?expand=names,renderedFields`\n\nTo discover which object can be expanded, refer to the `expand` property in the object. \nIn the JSON example below, the resource declares `widgets` as expandable.\n\n```json\n{\n \"expand\": \"widgets\", \n \"self\": \"https://your-domain.atlassian.net/rest/api/3/resource/KEY-1\", \n \"widgets\": {\n \"widgets\": [],\n \"size\": 5\n }\n}\n```\n\n### Pagination\n\nThe Jira REST API uses pagination to improve performance. Pagination is enforced for operations that could return a large \ncollection of items. When you make a request to a paginated resource, the response wraps the returned array of values in \na JSON object with paging metadata. For example:\n\n```json\n{\n \"startAt\" : 0,\n \"maxResults\" : 10,\n \"total\": 200,\n \"isLast\": false,\n \"values\": [\n { /* result 0 */ },\n { /* result 1 */ },\n { /* result 2 */ }\n ]\n}\n```\n\n* `startAt` is the index of the first item returned in the page.\n* `maxResults` is the maximum number of items that a page can return. Each operation can have a different limit for\n the number of items returned, and these limits may change without notice. To find the maximum number of items \n that an operation could return, set `maxResults` to a large number—for example, over 1000—and if the returned value of `maxResults` is less than the requested value, the returned value is the maximum.\n* `total` is the total number of items contained in all pages. This number **_may change_** as the client \nrequests the subsequent pages, therefore the client should always assume that the requested page can be empty. Note \nthat this property is not returned for all operations.\n* `isLast` indicates whether the page returned is the last one. Note that this property is not returned for all operations.\n\n### Ordering\n\nSome operations support ordering the elements of a response by a field. Check the documentation for the operation to \nconfirm whether ordering of a response is supported and which fields can be used. Responses are listed in ascending order \nby default. You can change the order using the `orderby` query parameter with a `-` or `+` symbol. For example:\n\n* `?orderBy=name` to order by `name` field ascending.\n* `?orderBy=+name` to order by `name` field ascending.\n* `?orderBy=-name` to order by `name` field descending.\n\n\n" title: Expansion, pagination, and ordering - anchor: timestamps body: 'By default, top-level timestamps (e.g. updated and created) are returned in [ISO 8601](https://www.w3.org/TR/NOTE-datetime) format, in the system default user time zone. To return date time data in the logged in user''s timezone, please refer to `renderedFields` property under the `expand` query parameter in relevant APIs. ' title: Timestamps - anchor: special-request-headers body: 'The following request and response headers define important metadata for the Jira Cloud REST API resources. - `X-Atlassian-Token` (request): Operations that accept multipart/form-data must include the `X-Atlassian-Token: no-check` header in requests. Otherwise the request is blocked by cross-site request forgery (CSRF/XSRF) protection. - `X-Force-Accept-Language` (request): controls how the standard HTTP `Accept-Language` header is processed. By default `Accept-Language` is ignored and the response is in the language configured in the user''s profile or, when no language is configured for the user, the default Jira instance language. For the response to recognize `Accept-Language` send `X-Force-Accept-Language = true` as well. If `Accept-Language` requests a language that Jira can return the response is in that language, otherwise Jira returns the response in the default language. If `Accept-Language` is not specified the response is in the default language. - `X-AAccountId` (response): This response header contains the Atlassian account ID of the authenticated user.' title: Special headers - anchor: anonymous-operations body: " Jira provides for all permissions, except the [global permission](https://confluence.atlassian.com/x/x4dKLg) Administer Jira, to be assigned to *Anyone*. Once a permission is assigned to *Anyone*, anyone knowing a project's URL is able to use the features in Jira enabled by the permission. However, the Jira REST API does not enable anonymous access for operations by default. This means that an anonymous user who may be able to perform an action through Jira, may not be able to perform the same action where it's enabled by the REST API. \n\n The operations that provide anonymous access are annotated \"This operation can be accessed anonymously.\"" title: Anonymous operations - anchor: async-operations body: "Some Jira REST API operations may trigger long-running or computationally expensive tasks. In these cases, the operation \nwill schedule an asynchronous task and return a `303 (See Other)` response, indicating the location of the queued task \nin the `Location` header. You can query this task to get progress updates.\n\nWhen the task finishes, the response object will contain the `result` field. The content of the field is specific to the \noperation that created the task. Refer to the operation’s documentation for more information.\n\nNote that asynchronous tasks are not guaranteed to be run in order. In other words, if you need your tasks to execute \nin a certain order, you should start a task only after the prerequisite task(s) have finished." title: Asynchronous operations - anchor: experimental body: "Features and methods marked as experimental may change without notice. Feedback on experimental functionality is welcome. \nReport issues to [Developer and Marketplace support](https://developer.atlassian.com/support) (preferred) or use the \n**Give docs feedback** link at the top of this page. \n" title: Experimental features - anchor: status-codes body: "The Jira Cloud platform REST API uses the [standard HTTP status codes](https://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html).\n\nOperations that return an error status code may also return a response body containing details of the error or errors. \nThe schema for the response body is shown below:\n\n\n```json\n{\n \"id\": \"https://docs.atlassian.com/jira/REST/schema/error-collection#\",\n \"title\": \"Error Collection\",\n \"type\": \"object\",\n \"properties\": {\n \"errorMessages\": {\n \"type\": \"array\",\n \"items\": {\n \"type\": \"string\"\n }\n },\n \"errors\": {\n \"type\": \"object\",\n \"patternProperties\": {\n \".+\": {\n \"type\": \"string\"\n }\n },\n \"additionalProperties\": false\n },\n \"status\": { \n \"type\": \"integer\"\n }\n },\n \"additionalProperties\": false\n}\n```" title: Status codes