Confluence turn off REST API

Is it possible to turn off the rest api in Confluence? We recently performed a webscan of Confluence using HP WebInpect and it reported numerous criticals due to the rest api. This could be easily resolved if I can restrict or turn off the rest api.

3 answers

This widget could not be displayed.

Lot of the default functionality in Confluence uses REST and hence it is not possible to disable it. Maybe you can put something like Apache in the front to prevent calls to certain urls!

I thought the REST api was just to integrate other applications with Confluence. Does Confluence itself post to the REST API?

Steven Behnke Community Champion Jun 29, 2016

Yes some functionality of the product uses the REST API.

This widget could not be displayed.

The only thing you can disable is the "Remote API (XML-RPC & SOAP)" as described here:

But it is deprecated from Confluence 5.5 on, so they will turn it of someday anyway.


This widget could not be displayed.

False positives are common from most automated security checking tools. Can you say what kind of results were found? Atlassian is most likely aware of the results from their own security checks - they use these tools too

Suggest an answer

Log in or Sign up to answer
Community showcase
Posted Monday in Confluence

Why start from scratch? Introducing four new templates for Confluence Cloud

Hi my Community friends!  For those who don't know me, I'm a product marketer on the Confluence Cloud team - nice to meet you! For those of you who do, you know that I've been all up in your Co...

398 views 4 6
Join discussion

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you