- Customer facing incidents
- Security tickets
- Ongoing projects
How to configure Jira with Cortex
It is possible to configure the integration with a Jira Cloud instance or a self-hosted Jira instance (using either basic auth or OAuth). You can also use Cortex Axon Relay to securely integrate your on-premises data. Expand the tabs below for instructions on each option.Jira Cloud
Jira Cloud
- Create a Jira API token. To generate a token, you must have the
Browse users and groupspermissions in Jira and access to the needed Jira projects. - If you are using a scoped token, you will need your Atlassian Cloud ID. Scoped tokens must include the following scopes:
- Read:
jira-work,jira-user,project-category:jira,project:jira,project-version:jira,project.property:jira,project.component:jira,issue-type:jira,issue-type-hierarchy:jira,user:jira,avatar:jira,project.avatar:jira,application-role:jira,group:jira - Write:
jira-work
- Read:
- In Cortex, navigate to the Jira settings page:
- Click Integrations from the main nav. Search for and select Jira.
- Click Add configuration. then select Cloud for the integration type.
- If you are using a scoped token, select Cloud (scoped token).
- In the Jira integration modal, “Jira Cloud” is selected by default in the upper right corner. Configure the integration form:
- Account alias: Enter an alias for your account.
- Subdomain: Enter the subdomain for your Jira instance.
- For example, this field would take
cortex-docsfromhttps://cortex-docs.atlassian.net.
- For example, this field would take
- Base URL: This field automatically populates
atlassian.net.- If you are using a legacy Jira Cloud instance (i.e., you access your Jira instance on
jira.com), change the base URL from the dropdown.
- If you are using a legacy Jira Cloud instance (i.e., you access your Jira instance on
- Email: Enter the email address associated with the user who generated the token in Jira.
- Note: The email address associated with a given Jira token must match the email address of the user associated with that token.
- API token: Enter your Jira API token.
- Click Save.
On-prem (Basic)
On-prem (Basic)
- In Cortex, navigate to the Jira settings page:
- In Cortex, click your avatar in the lower left corner, then click Settings.
- Under “Integrations,” click Jira.
- Click Add configuration.
- In the upper right corner of the Jira integration modal, click the dropdown labeled
Cloud. SelectOn-prem (basic auth). - Configure the Jira integration form:
- Account alias: Enter an alias for your account.
- Host: Enter the URL for your Jira on-premises host.
- Frontend host: Enter the URL for your Jira on-premises frontend host.
- Username and Password: Enter your Jira username and password.
- Click Save.
On-prem (OAuth)
On-prem (OAuth)
- In your Jira server, navigate to Settings > Applications > Application Links. Click Create link.
- Configure the application link settings:
- Application type: Select
External. - Direction: Select
Incoming. - Redirect URL: For default configuration, enter the URL of your Cortex instance appended with
/oauth/internal/jira. For a non-default configuration, enter the URL of your Cortex instance appended with/oauth/internal/jira/. - Permission: Select
write.
- Application type: Select
- Click Save.
- The application link will have an associated client ID and client secret. Copy these values and store them in a secure location, as you will need them in the next steps.
- In Cortex, navigate to the Jira settings page:
- In Cortex, click your avatar in the lower left corner, then click Settings.
- Under “Integrations,” click Jira.
- Click Add configuration.
- In the upper right corner of the Jira integration modal, click the dropdown labeled
Cloud. SelectOn-prem (OAuth). - Configure the Jira integration form:
- Account alias: Enter an alias for your account.
- Host: Enter the URL for your Jira on-premises host.
- Frontend host: Enter the URL for your Jira on-premises frontend host.
- Client ID and Client secret: Enter the client ID and secret associated with the application link you created in the previous steps.
- Click Save.
- You will be redirected to the Jira settings page. Click Install next to your integration name.
- A confirmation modal will appear, asking you to allow Cortex access to your Jira account.
- The accessing user can be a user persona or a system account. We recommend using a system account to maintain your organization’s access in case the user who set up the integration leaves your organization.
Axon Relay
Axon Relay
Set a default JQL query for your Jira integration
You can set a custom JQL query for your Jira integration instances and for individual entities. This allows you to filter which Jira work items are surfaced on entity pages or in other places in Cortex where CQL is used. The default JQL applies tojira.issues() and jira.numOfIssues() but not to jira.rawJql().
Tenant level
Tenant level
statusCategory is directly grabbed from the API response.The default query — statusCategory in ("To Do", "In Progress") — will filter your Jira tickets to display only those with To Do and In Progress statuses, excluding closed tickets. The indeterminate status category will map to In Progress according to the API. Cortex does not use the status field for mapping these categories.Entering a custom JQL query on the Jira integration settings page allows you to override the default for all entities in your workspace. To map work items with a custom status, you can write a custom JQL query that uses status instead of statusCategory.Entity level
Entity level
Fallback logic for default JQL
It is possible to set custom JQL at both the entity and tenant level, but note the fallback logic:- If any JQL is passed into a query, Cortex uses that.
- If not, Cortex uses entity-level default JQL.
- If not, Cortex uses tenant-wide default JQL.
- If none, then no JQL is used for filtering.
Adding filter logic to the default JQL query in a Scorecard
The CQL statement will use the default JQL setting in a Scorecard rule only if you do not define additional filter logic. Any filter logic applied to the statement will override the default JQL query. To work around this: If you need to include additional filter logic on your query in a Scorecard, you can move the filter logic to the filter clause. For example, if your default JQL query is set to"project = project_a", then you can add jira.issues() to a Scorecard rule to automatically surface only the work items relating to Project A. However, you cannot use jira.issues(some_other_filter_logic) in a Scorecard; Cortex will not append your default JQL to the additional filter logic.
In this example, the workaround would be to add a filter clause:jira.issues().filter(some_other_filter_logic).
How to connect Cortex entities to Jira labels, components, or projects
Discovery
By default, Cortex will tie Jira tickets to entities by searching for any tickets where thelabel, component, or project field for the work item includes the Cortex tag. For example, if your Cortex tag is “my-entity,” then the corresponding tickets in Jira should have “my-entity” as a label, component, or project.
If your Jira label/component/project doesn’t cleanly match the Cortex tag, you can override this in the Cortex entity descriptor.
Without an override, a ticket’s label, component, or project must exactly match the Cortex tag in the descriptor.
Connecting via YAML or the Cortex UI
Cortex UI
Cortex UI
- Navigate to an entity’s details page in Cortex.
-
In the upper right corner, click Configure entity.

-
Click the Project management tab, then click +Add.

-
In the side panel, configure the details:
- Jira service type: Choose component, label, or project.
- Alias: If you have multiple Jira configurations, select which one this service is associated with.
- Name: Enter the name of the service.
- At the bottom of the side panel, click Add.
Entity YAML
Entity YAML
x-cortex-issues blocks in your Cortex entity descriptor.Note: For all of the following, alias is optional, and the default Jira configuration will be used if not provided. You can use Jira labels, components, or projects to match entities.Each of these blocks has the same field definitions.statusCategory in ("To Do", "In Progress"). If you’d like to override this, you can provide a new default query with:Identity mappings
Cortex maps Jira accounts to team members defined in the team catalog, so you do not need to define Jira users in a team member’s YAML file. You can confirm that users’ Jira accounts are connected from the Jira user mappings section in Settings.Using the Jira integration
Entity pages
Once the integration is established, you’ll be able to pull in data about the work items in any linked Jira instances for a given entity:- Number of issues: Unresolved issues associated with an entity that have the JQL status “in progress” or “to do”
- Number of issues from JQL query: Issues associated with an entity that match an arbitrary JQL query
- Key: The issue key (or “ticket number”) for a Jira work item.
- Issue summary: Title of the Jira work item and the user designated as the issue reporter.
- Assignee: User designated as the work item assignee.
- Priority: The work item’s priority level in Jira - Lowest, Low, Medium, High, Highest. This will display with the icon that corresponds to the priority level in your Jira instance.
- Created: Date the work item was created.
- Due: Due date for the work item, if applicable.
label, component, or project in Jira.
Initiatives
Initiatives allow you to set deadlines for specific rules or a set of rules in a given Scorecard and send notifications to users about upcoming due dates. From the Issues tab of an Initiative, you can automatically create a Jira ticket from a failing rule. Read about creating Jira issues from Initiatives in the documentation: Creating issues based on initiatives.Dev homepage
The Jira integration enables Cortex to pull information about issues into the dev homepage. You can find open work items assigned to you under the Issues tab. The work items that display will depend both on the Jira instances you’ve connected and the JQL query defined in Settings. Work items are refreshed every 5 minutes. You can use the Refresh work items button to manually refresh issues at any point.Scorecards and CQL
With the Jira integration, you can create Scorecard rules and write CQL queries based on Jira work items. See more examples in the CQL Explorer in Cortex.Issues
Issues
jira.numOfIssues()ExampleFor a Scorecard measuring entity maturity, you can use this expression to make sure entities have fewer than 3 Jira issues:Issues from JQL query
Issues from JQL query
jira.numOfIssues(jqlQuery: Text | Null)ExampleFor a more specific rule in an entity maturity Scorecard, you can use this expression with a JQL query to make sure entities have no more than 3 open customer-facing tickets.View integration logs

Background sync
The engineering homepage runs a background job every 5 minutes to refresh the Issues tab.Troubleshooting and FAQ
See frequently asked questions below.I've added a Jira integration, but I'm not sure what JQL is being generated to query Jira.
I've added a Jira integration, but I'm not sure what JQL is being generated to query Jira.
AND (component = cortex-tag OR labels = cortex-tag OR project = cortex-tag) to the JQL you defined, where cortex-tag is the Cortex tag.My Scorecard rules are failing, even though there are tickets in my Jira instance.
My Scorecard rules are failing, even though there are tickets in my Jira instance.
I received this error: 'Configuration error: Integration error for Jira - Unexpected HTTP response 0'.
I received this error: 'Configuration error: Integration error for Jira - Unexpected HTTP response 0'.
I received this error: 'Configuration error: Jira - Unexpected HTTP response 403: Forbidden'.
I received this error: 'Configuration error: Jira - Unexpected HTTP response 403: Forbidden'.
- Make sure that the entity name in Cortex matches the label, component, or project name in Jira.
- Make sure the subdomain and base URL correspond with the Jira instance you’re trying to connect.
- Verify that the Jira token you added is still valid. You can run the following curl command to confirm:
I configured the integration, but I am not seeing Work Items populate.
I configured the integration, but I am not seeing Work Items populate.