Hello Jira Support,
We are working with Jira Cloud and API tokens with scopes, and we would like to clarify whether it is possible to create an API token whose permissions are strictly limited to what is explicitly defined on the token itself, rather than inheriting the full set of permissions of the user who created it.
More specifically, we are looking for a way to create an API token that:
Can perform a very limited set of actions (for example: browse issues and add comments only)
Is not allowed to delete comments, delete issues, or perform other destructive actions
Does not inherit additional permissions from the user’s project roles, groups, or permission schemes
From our understanding and testing so far:
API token scopes appear to only limit which APIs can be called
Actual permissions (e.g. deleting comments or issues) are still governed by the project’s Permission Scheme and the user’s roles/groups
As a result, even a scoped token can perform actions that the underlying user is allowed to perform
Can you please confirm:
Whether Jira Cloud currently supports API tokens with independent, enforceable permissions that override or do not inherit the creating user’s permissions?
If not, is the recommended approach to create a dedicated “integration user” with a minimal project role and manage permissions exclusively via the project’s Permission Scheme?
Are there any plans or recommended patterns (e.g. OAuth apps, Forge, Connect) for achieving true least-privilege access for integrations?
Thank you for your clarification.
Best regards,
Sagi Karach