Hi Everyone 👋
I’m setting up an integration from a deployment tool (Capistrano) to Jira Software Cloud using the Deployments API, and I’m running into a strange OAuth 2.0 scope issue.
Here’s what I’ve done:
In Jira Cloud Admin, I went to Settings → Marketplace apps → OAuth credentials → Create new credentials.
I entered a name, server base URL (https://oursite.atlassian.net), and added an internet-sourced logo.
Under Permissions, I only selected Deployments (unchecked Builds, Development information, Feature flags, and Remote links).
I saved the credential and copied the Client ID and Secret.
I requested a token using the client credentials flow:
<span>POST https://api.atlassian.com/oauth/token
{
"grant_type": "client_credentials",
"client_id": "<client_id>",
"client_secret": "<client_secret>",
"audience": "api.atlassian.com"
}</span>The request succeeds, but the returned scope is:
<span>"scope": "manage:jira-data-provider"</span>
instead of the expected:
<span>"scope": "write:deployment-info:jira"</span>
When I use that token against the Deployments endpoint:
<span>POST https://api.atlassian.com/jira/deployments/0.1/cloud/<cloudId>/bulk</span>
I get:
<span>[{"message":"The request failed: Could not get devops record for cloudId <id>"}]</span>
What I’ve Confirmed
This credential was created through Settings → Marketplace apps → OAuth credentials.
Only Deployments is checked under permissions.
The credential is shown as “Installed – done” in the Jira Admin UI.
The cloudId is correct (confirmed via the /_edge/tenant_info API).
My Question
Is this a known issue where OAuth credentials with Deployments permission incorrectly return the manage:jira-data-provider scope?
Or am I missing an additional configuration step?
Ultimately, I’m just trying to report deployments from Capistrano into Jira Software’s Deployments view.