Stackleaks
Sign in

Connecting Atlassian: the API key, step by step

Stackleaks reads your Jira and Confluence seats through Atlassian's admin API. There's no app to install — you create an API key in your own admin console, and you can revoke it there at any time. Two minutes, org-admin rights required.

1. Where the keys live

Go to admin.atlassian.com → Organization settings → API keys → Create API key. While you're there, note your organization ID — the long identifier in the page's URL (admin.atlassian.com/o/your-org-id/…). Stackleaks asks for both.

2. "With scopes" or "without scopes"?

Atlassian asks you to choose an access level. Choose "API key with scopes" — Atlassian's recommendation and ours — and tick exactly two scopes, both read-only:

  • read:directories:admin — your directory: who has a seat, account status, which products (Jira/Confluence) each person uses, and when each was last used. Powers ghost-seat and dormant-seat detection.
  • read:workspaces:admin — each site's plan tier per product (Free, Standard, Premium). This is what makes the money honest: a seat on a free product counts as €0 waste, and paid seats price at their real tier's list price instead of a generic estimate.

A key with only the first scope still works — you just get list-price estimates instead of tier-accurate numbers. An unscoped key works too, but it can reach every Atlassian admin API; there's no reason to hand that out for this. If you already created one, it's fine: we call the same read endpoints either way.

3. Expiry

Atlassian caps these keys at one year — pick the maximum unless your policy says otherwise. Your Stackleaks connector card shows the re-key date, and re-connecting with a fresh key takes the same two minutes.

4. Paste it into Stackleaks

Back in Connectors, open the Atlassian card, paste the organization ID and the key, and we verify it with a single API call before storing anything. A key that doesn't check out is never saved.

What we read — and what we can never do — is documented scope by scope on What we can see. Disconnecting deletes the key and everything read through it, immediately.