When an AI agent cannot read Jira or Confluence, check the failure in this order: identify whether the site is Cloud or Data Center, verify the agent’s identity and authentication route, confirm token or app scopes, then check product and content permissions. A successful login or basic API response does not prove the agent can read a particular project, space, or page.
Start by identifying the failing access layer
Before changing credentials or permissions, capture the details needed to distinguish authentication from authorization and URL errors:
- Deployment: Atlassian Cloud or Data Center.
- Identity used by the agent: a user, service account, OAuth app, or Data Center application link.
- Authentication method and token type.
- Exact request URL, HTTP method, status code, and response body.
- The target project, space, page, or other content the agent is trying to retrieve.
Use a minimal read-only request to test access, and redact tokens and personal data from logs, tickets, and examples. Choose the Cloud or Data Center path below based on the actual deployment; their integration settings are not interchangeable.
Troubleshoot Atlassian Cloud service-account requests
Route scoped tokens through the Atlassian API gateway
For Atlassian Cloud service accounts using scoped API tokens, requests use api.atlassian.com and the site’s Cloud ID. A site-specific URL is not the documented route for scoped-token requests. The endpoint patterns are https://api.atlassian.com/ex/jira/{cloudId}/... and https://api.atlassian.com/ex/confluence/{cloudId}/.... See Atlassian’s 401 Unauthorized error when service account accesses Jira or Confluence API and Scoped API Tokens in Confluence Cloud documentation.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Atlassian documents these minimal checks:
- Jira:
GET /rest/api/3/myself, using the Jira gateway route and Cloud ID. - Confluence:
GET /wiki/rest/api/space, using the Confluence gateway route and Cloud ID.
A 200 response confirms that the request’s route, token, and applicable scopes work for that check. It does not establish access to every project, space, or page the agent may need.
If the request returns 401 Unauthorized
Check the authentication and routing details before changing content permissions:
Rank #2
- Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
- Confirm the service account is active and the token is valid, has not expired, and is being passed in the format the integration expects.
- Verify that the token type is supported by the integration. Some integrations expect classic tokens and may not support scoped tokens; confirm compatibility with the integration vendor.
- Check that the request uses the correct Cloud ID, product gateway route, and API path.
- Confirm the token has the required scope for the endpoint.
- Run the matching minimal Jira or Confluence request above, then inspect the returned status and body.
Atlassian lists scoped service-account token expiration as configurable from 1 to 365 days; this is a configuration range, not a guarantee that a particular token remains valid. Review Manage API tokens for service accounts for token and account checks.
If the request returns 403 Forbidden or content is missing
A valid token can still belong to an identity that lacks product or content access. Check these boundaries separately:
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
- Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
- Product access and provisioning: Confirm that the account has access to Jira or Confluence and has completed any required first-login provisioning. For Confluence Cloud, Atlassian recommends signing out fully and signing in again after account-provisioning or product-access changes before retesting.
- Organization controls: Check applicable IP allowlisting, SSO, or other organization restrictions.
- Groups and scopes: Confirm the account’s group membership and that the token has the required read scope.
- Target permissions: Check Jira project permissions or Confluence space permissions for the agent’s identity.
- Content restrictions: For Confluence, inspect restrictions on the requested page and any inherited parent content.
Atlassian’s User Can’t Access Confluence Cloud and Confluence Cloud Access Denied guidance separates account, product, space, and content checks. A user may be allowed into a space but blocked from an individual page; an inherited parent restriction can also affect access. See Troubleshoot access problems to content for inherited permissions.
Check OAuth apps and request URL construction
“Your site admin must authorize this app”
This prompt indicates an app-approval issue, not necessarily a problem with the agent’s API token. Ask a site administrator to authorize the Cloud app, then confirm the app requests the scopes it needs and its implementation actually uses them. App authorization and an API token’s scopes are distinct access layers. Atlassian explains this prompt in “Your site admin must authorize this app” error in Atlassian Cloud apps.
Rank #4
- Easily store and access 4TB of content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
“Unauthorized; scope does not match” on Jira search
Validate the exact URL, including slash placement around the query string. Atlassian documents one Jira Cloud case in which a search path ending in search/? caused a scope-mismatch response; removing the slash to use search? fixed that specific URL-formatting issue. Treat this as a targeted check, not a general fix for every OAuth error. See oAuth app throwing error Unauthorized scope does not match.
Troubleshoot Jira–Confluence links in Data Center
For Data Center, investigate the application link between Jira and Confluence rather than applying Cloud scoped-token instructions. Verify that the link reports connected and uses the intended OAuth configuration. If the failure persists, check reciprocal allowlists, custom SSO or authenticator configuration, and the Jira and Confluence logs.
Recommended Free Tools
Best Value
- [Upgraded Version] - This external hard drive features a mirrored logo stripe combined with a striped anti-slip design, and the rounded corners of the casing make it easier to grip. The stripes also have a heat dissipation function, ensuring stable and fast data transfer.
- 【Ultra-thin and quiet】 - The motherboard adopts JMicron 578 noise-free solution, giving you a quiet working environment. Lightweight and portable size designed to fit in your pocket for easy portability.
- 【Ultra-Fast Data Transfers】 - Pairing this external hard drive with JMicron 578 solution USB 3.0 and USB 2.0 interfaces enables blazing-fast data transfer. It boasts theoretical read speeds of up to 125MB/s and write speeds of up to 103MB/s.
- 【Plug and Play】 - With no software to install, just plug it in and the drive is ready to use.The hard disk chip is wrapped with an aluminum anti-interference layer to increase heat dissipation and protect data.
- 【What You Get】 - 1 x Portable Hard Drive, 1 x USB 3.0 Cable, 1 x User Manual, Gift-type shell packaging ,Three-year manufacturer's warranty and free technical support services.
Atlassian’s procedure for a Jira Roadmap macro returning 401 is specific to Confluence Data Center and Jira Software Data Center 9.0 and later; use it only when that product and version context matches the failure: How to fix 401 unauthorized error loading Jira Roadmap macro in Confluence Data Center.
Quick Recap
Match the symptom to the next check
| Observed symptom | Check first | Then |
|---|---|---|
| 401 from a Cloud scoped-token request | Token type and validity, Cloud ID, gateway route, required scope, and integration support | Run the documented minimal endpoint; then check account status and product access. |
| 403 from Confluence API | Gateway route and Cloud ID, read scope, product access, provisioning, groups, and organization restrictions | Check space permissions, page restrictions, and inherited parent restrictions. |
| App-authorization prompt | Whether a site administrator approved the app and which scopes it requests | Have the site admin authorize it and confirm the implementation uses the required scopes. |
| Jira search reports scope mismatch | Exact request path and slash placement before the query string | For the documented case, remove the slash immediately before ?. |
| Data Center Jira–Confluence macro returns 401 | Application-link status and OAuth configuration | Check reciprocal allowlists, SSO customization, logs, and whether the documented procedure applies to the versions in use. |
| Agent can read a Confluence space but not a page | Page restriction and inherited parent restrictions | Ask a space administrator or content editor with permission to inspect the specific content restrictions. |
Confirm the fix and escalate safely
- After each change, retry the exact request that failed, using the same identity, method, URL, and target content.
- Compare both the HTTP status and returned content. A successful basic endpoint is not a substitute for testing the original project, space, or page.
- If access remains blocked, provide the administrator or Atlassian Support with the endpoint, method, status, response body, relevant request metadata, and applicable logs. Remove tokens and personal data before sharing.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

