I have built and deployed a Jira app using Atlassian Forge. The app acts as a lightweight chatbot that listens to Jira Automation Webhooks (e.g., issue commented) and then fetches issue data via the Jira REST API to generate automated insights.
The app works perfectly on my own Jira site, but when installed on another Jira site (by an admin using the official install link), it fails to fetch issues due to permission errors.
What the app does
- Installed as a Forge Jira app
- Triggered by Jira Automation → Send Web Request
- Receives webhook payload in Forge
- Fetches issue details using:
api.asApp().requestJira(`/rest/api/3/issue/${issueKey}`)Posts an automated comment back to the issue
Observed behavior
On the external Jira site Chengwei Semiconductor, the automation fires successfully, but the Forge app fails when fetching the issue.
Jira Automation error:
Unable to publish the web request - received HTTP status response: 500
Failed to fetch Jira data
Forge logs:
Failed to fetch issue OD2T-2: 404 Not Found
"Issue does not exist or you do not have permission to see it."
Critical: Failed to fetch Jira data. Check App Permissions.
Important details
- The issue definitely exists
- The user who commented on the issue is a Jira admin
- The user who installed the app is a Jira admin
- The automation rule can see the issue
- The Forge app cannot
Same code works on my own Jira site (where I’m also an admin)
Forge permissions (manifest.yml)
permissions:
scopes:
- read:jira-work
- read:jira-user
What I suspect
This seems related to project-level permissions or issue security schemes for the Forge app system user, especially since:
- Forge apps execute as the app user, not the human user
- Jira returns 404 instead of 403 when an app lacks issue visibility
- External Jira sites often use custom permission schemes
However, I’m unclear on:
- Whether Forge apps must be explicitly added to project permission schemes
- Whether issue security levels block Forge apps by default
- Whether this is expected behavior for api.asApp() in automation-triggered contexts
- Whether there’s a recommended pattern for cross-site access to issues in Forge apps
Questions
- Why does a Forge app have access to issues on my Jira site but not on other admin-installed sites?
- Do Forge apps require explicit project permission or issue security access to read issues?
- Is this a limitation of api.asApp() when used with Jira Automation webhooks?
- What is the correct and recommended way to ensure a Forge app can read issues across customer sites without over-scoping permissions?
Any guidance from Forge or Jira platform experts would be greatly appreciated.
Environment
- Atlassian Forge (latest runtime)
- Jira Cloud
- Jira Automation → Send Web Request
- REST API v3
- App installed via official Forge install link