Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a script or manual client calling Jira Cloud’s Automation REST API, authenticate with an Atlassian API token using HTTP Basic authentication: combine the account email and token as email:token, Base64-encode that string, and send it in an Authorization: Basic header. Then check the specific endpoint’s authorization rules: valid credentials identify the caller, but do not grant access the caller lacks in Jira.

Choose the authentication method for your client

The Automation REST API lets clients work with Automation entities, including rules, across Atlassian products. Its documented API-token method uses the Atlassian account email and API token—not the account password. Atlassian describes Basic authentication with an API token as suitable for simple scripts and manual calls; for an app integration, consider OAuth 2.0. See The Automation REST API and Automation API authentication.

Client situation Method Important distinction
Script or manual REST client Atlassian API token with HTTP Basic authentication Use the account email and token; do not use the account password.
Supported browser-originated call Browser session cookie through the site gateway base path Cookie authentication is associated with the gateway path, not the api.atlassian.com base path.
Forge or OAuth 2.0 authorization-code app App scopes appropriate to the operations Scopes do not replace the user’s Jira permissions. The general Jira scope guide does not map scopes to every Automation endpoint.
Automation rule calling an external OAuth-protected service Rule obtains and then sends an OAuth access token This authenticates the rule’s outgoing request to the external service; it is not the method for a client calling the Automation REST API.

Set up API-token Basic authentication

  1. Create an Atlassian API token. Create it for the account that will make the request. Atlassian tokens are used instead of an account password and can be revoked. Follow Atlassian’s authentication guidance.
  2. Build the credential string. Join the account email and token with a colon: email:token.
  3. Base64-encode the complete string. Encode the email, colon, and token together, then send the result as Authorization: Basic <encoded-credential>. Base64 encoding is part of the header format; it does not grant permissions.
  4. Use a base path supported by your client. For API-token calls, use https://api.atlassian.com/automation/public/{product}/{cloudid}. The site gateway path, https://{sitename}/gateway/api/automation/public/{product}/{cloudid}, also supports browser session-cookie authentication. Here {product} is the product being called, such as jira, and {cloudid} identifies the Cloud site. Atlassian documents https://{sitename}/_edge/tenant_info for finding the cloud ID. See Automation API paths.
  5. Use the endpoint’s documented method and route. Automation endpoints have their own paths and API versions. Check the REST reference for the operation you need.

Check authorization for the exact endpoint

Authentication answers “who is making this request?” Authorization answers “may this user perform this operation on this resource?” Atlassian says Automation API authorization is based on the requesting user’s relevant product permissions. Many endpoints require site- or container-level administrator access, while others check permissions on the particular object involved. There is no single administrator role that can be assumed to cover every endpoint. Consult the Automation authorization guide and the individual endpoint reference.

  • Confirm the user behind the token has access to the Jira product and site being called.
  • Check whether the endpoint requires site or container administration, or permission on a specific object.
  • For a Forge or OAuth 2.0 app, select scopes for the operations it calls, then verify the user’s Jira permissions separately. Jira scopes do not override user permissions; for example, an app scope cannot grant a user who lacks Browse projects access to project data. See Jira scopes for OAuth 2.0 (3LO) and Forge apps.

Atlassian’s Jira Basic-auth guidance also notes that REST access follows the same restrictions as access through the Jira interface. See Basic auth for REST APIs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Separate API authentication from a rule’s outgoing OAuth request

A Jira Automation rule that calls an external OAuth-protected service has a different credential flow from a script calling the Automation REST API. Atlassian Support describes a two-request pattern: the rule first makes an outgoing request to obtain an access token, then sends a subsequent request to the external service with that token in an Authorization header, for example Bearer {{webhookResponse.body.access_token}}. Do not use that Bearer-token example as the Automation REST API’s client authentication method. The support article also warns that values in the webhook body are not HTML URL-encoded; special characters are sent as-is and may need encoding if authentication fails. Details: Authenticating OAuth 2.0 for outgoing web requests in Jira Automation rules.

Rank #4
The SQL Programming Language: .
  • Used Book in Good Condition

Troubleshoot a denied request

  • Request is rejected as unauthenticated: verify the token belongs to the account email used in the Basic credential, that the full email:token string was encoded, and that the header uses the Basic scheme.
  • Credentials work but the operation is denied: investigate authorization rather than repeatedly changing the token. Check the endpoint’s required site, container, product, or object access for the requesting user.
  • Session-cookie call fails: verify that the request uses the site gateway base path; cookie authentication is not the documented method for the api.atlassian.com path.
  • OAuth app can call some Jira APIs but not the Automation operation: confirm the required scope and user permissions, and verify the exact Automation endpoint requirements. The general Jira scope documentation is not an endpoint-by-endpoint Automation scope map.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.