Confluence turn off REST API

Is it possible to turn off the rest api in Confluence? We recently performed a webscan of Confluence using HP WebInpect and it reported numerous criticals due to the rest api. This could be easily resolved if I can restrict or turn off the rest api.

3 answers

1 vote

Lot of the default functionality in Confluence uses REST and hence it is not possible to disable it. Maybe you can put something like Apache in the front to prevent calls to certain urls!

I thought the REST api was just to integrate other applications with Confluence. Does Confluence itself post to the REST API?

Steven Behnke Community Champion Jun 29, 2016

Yes some functionality of the product uses the REST API.

The only thing you can disable is the "Remote API (XML-RPC & SOAP)" as described here:

But it is deprecated from Confluence 5.5 on, so they will turn it of someday anyway.


False positives are common from most automated security checking tools. Can you say what kind of results were found? Atlassian is most likely aware of the results from their own security checks - they use these tools too

Suggest an answer

Log in or Sign up to answer
Community showcase
Posted Feb 06, 2019 in Confluence

Try out the new editing experience

Hi team, I’m Avinoam, a product manager on Confluence Cloud, and today I’m really excited to let the Community know that all customers can now try out the new editing experience and see some of the ...

1,094 views 56 8
Join discussion

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you