Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Jira Automations - Send Web Request Response Payload Logged?

Kevin Tra
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 21, 2025

I am trying to create an automation rule that sends a Web Request. The API uses OAUTH2 for authentication, so in an initial action, I need to request for an access-token, which will then be returned in the response body, then I will be able to use this access-token in the header of subsequent API calls as a bearer token.

I want to understand the security implications of this in terms of the chances of the bearer token being exposed. I understand that Header values of the Send Web Request Action can be 'Hidden', so you can configure the access-token as a smart-value in the subsequent API calls as a Hidden value.

My concern is if the response body of a Send web request is logged anywhere in which the bearer token will be exposed in the first request.

1 answer

0 votes
Trudy Claspill
Community Champion
August 22, 2025

Hello @Kevin Tra 

Welcome to the Atlassian community.

I recommend that you ask your Administrators to pose that question directly to Atlassian through a support case created here:

https://support.atlassian.com/contact/#/

From a Jira user/admin perspective within the rule itself it is possible to use a Log action to print the response into the rule Audit Log.

Beyond that I don't have any information about what information might be getting logged in backend system logs, but Atlassian Support should be able to provide that information.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events