Skip to main content

Connecting Vanta & Jira Data Center

Overview

The Jira Data Center integration connects your self-hosted Jira Data Center instance to Vanta using a Personal Access Token (PAT). It works as two integrations in one: an access integration that syncs your Jira user accounts for access reviews and offboarding checks, and a task tracker that syncs labeled Jira issues and lets you create new ones directly from Vanta. It is best suited for organizations that run Jira Data Center (formerly Jira Server) on their own infrastructure.

Jira Data Center and Jira Cloud are separate integrations in Vanta. They are connected, configured, and managed separately, and appear as separate integration cards. If you use both, connect both.

Estimated setup time: 10-15 minutes per instance


Connection details

Connection type

Personal Access Token (PAT) + instance URL. This is not an OAuth connection.

Supported products

Jira Data Center (self-hosted). Jira Cloud and Jira for Government use the separate Jira integration.

Who should connect

A Vanta admin, using a Personal Access Token generated by a Jira user with the access described under Permissions.

Multiple instances

Yes. Each Jira Data Center instance is added as its own connection, identified by its instance URL.

Network access

Your Jira instance must be reachable from Vanta. If it sits behind an IP allowlist, add Vanta's IP address.


Use cases and capabilities

  • User Account Tracking: Connect your Jira Data Center instance and we automatically sync active user accounts, including their group memberships, to Vanta's Access page. Accounts are auto-linked to your personnel by matching email address or display name, supporting access reviews and offboarding checks. Accounts that don't match anyone are left unlinked for you to resolve.

⚠️ Note: Only active Jira users with an email address are synced. Inactive users are excluded.

  • Task Management: Pull labeled Jira issues into Vanta as tasks, so security work tracked in Jira shows up against your tests and controls. Vanta reads every project the connecting account can see and deduplicates issues that appear in more than one project. An issue is marked closed in Vanta when it has a resolution date or its status is in Jira's "Done" category. Task sync is label-based; only issues carrying a matching label sync to Vanta.

  • Task Creation from Vanta: Create Jira issues directly from a Vanta test or control, choosing the project, issue type, assignee, and reporter. The issue is created in your Jira Data Center instance and appears linked in Vanta.

  • Multiple Instance Support: If your organization runs more than one Jira Data Center instance, you can connect each one to the same Vanta account. Each instance is added and managed as its own connection, and you choose which instance to file an issue in when creating a task from Vanta.

Capabilities overview

Resource / Capability

Supported

How it is used in Vanta

User Accounts

Yes

Personnel tracking, access reviews, deprovisioning checks

Group Membership

Yes

Synced with each account to support access reviews

Tasks

Yes

Test remediation, linked task tracking, status sync

Task Status

Yes

Open or closed status reflected on linked Vanta tests and controls

Task Assignee

Yes

Displayed on linked tasks in Vanta

Task Priority

Yes

Jira's default priorities (Highest through Lowest) mapped to Vanta priority levels; custom priorities aren't mapped automatically

Labels

Yes

Determine which Jira issues sync to Vanta as tasks

Task Creation from Vanta

Yes

Create issues in Jira Data Center directly from Vanta tests or controls

Epic and Sub-task Creation

No

Not supported when creating issues from Vanta

MFA Status

No

Not available from the Jira Data Center API

Role, Last Login, Account Created Date

No

Not available from the Jira Data Center API

File Attachments

No

Not supported. Issue comments, attachments, and work logs are not collected

Comment Posting

No

Not supported. Vanta does not post updates back to Jira issues

Multiple Jira Data Center Connections

Yes

Connect each instance as its own connection; the same instance URL cannot be added twice


Prerequisites

Before starting setup, confirm the following:

  • You have a Vanta admin account.

  • You have the base URL of your Jira Data Center instance, for example https://jira.mydomain.com. Include the scheme, and the port if your instance uses a non-standard one.

  • Your instance is running Jira Data Center 8.14 or later. Vanta authenticates with Personal Access Tokens, which Jira introduced in 8.14.

  • You have a Jira Data Center account that can browse the projects and users you want Vanta to see, and that can create issues if you plan to file Jira issues from Vanta.

  • Your Jira instance is reachable from Vanta. Because Jira Data Center is self-hosted, if you restrict inbound traffic by IP you must allowlist Vanta's IP address before connecting.

💡 Tip: We recommend generating the token from a dedicated service account rather than a personal account, since the integration authenticates as that user. If the account is later deactivated or its permissions change, the connection stops working.


Setup guide

Steps 1-3 connect the integration. Steps 4-6 put each part of it to work: verifying access monitoring, setting up task tracking, and creating Jira issues from Vanta.

Step 1: Create a Personal Access Token in Jira Data Center

  • Sign in to your Jira Data Center instance as the account Vanta will use.

  • Open your profile menu and go to Personal Access Tokens.

  • Click Create token and give it a recognizable name, such as Vanta integration.

  • Set the expiry to never. If your instance requires an expiry date, note it. The connection will stop syncing when the token expires, and you will need to generate a new one and update the connection in Vanta.

  • Copy the token. Jira only shows it once.

For more detail, see Atlassian's documentation on managing personal access tokens.

Step 2: Connect Jira Data Center in Vanta

  • In Vanta, go to the Integrations page, click Add integration, and then search for Jira Data Center. For help, see our guide to the Integrations Page.

  • Click Connect.

  • Paste the Personal Access Token you created in Step 1.

  • Click Store credentials.

Vanta validates the credentials and then shows as Connected.

Step 3: Add additional instances (optional)

If your organization runs more than one Jira Data Center instance, repeat the setup for each one. Adding a second instance does not affect the first.

  • Go to Integrations and search for Jira Data Center as a Connected integration.

  • Click Edit and then Add credentials.

  • Enter the Tenant URL for the second instance, and a Personal Access Token generated on that instance.

  • Click Store credentials.

Each connection needs its own token. A token from one instance will not authenticate against another. Your connections are listed together on the Jira Data Center integration page, where you can edit or remove them individually.

ℹ️ Note: Each connection is identified by its instance URL, so you cannot add the same URL twice. If you need to change which instance a connection points to, edit the existing connection instead of adding a new one.

Step 4: Confirm access monitoring is working

The access side of the integration starts working as soon as you connect. No extra configuration is needed.

  • Open the Access page in Vanta and confirm your Jira Data Center accounts appear, including their group memberships.

  • Review the matches. Vanta auto-links accounts to personnel by email address or display name. Link any unmatched accounts to the right person, or mark them as service accounts.

  • Once accounts are synced, the compliance tests begin evaluating: accounts associated with users, and accounts deprovisioned when personnel leave.

Step 5: Set up task tracking

The task side requires one piece of configuration: the labels that tell Vanta which Jira issues to track.

  • After connecting, Vanta prompts you to configure which labels identify the issues you want tracked. You can update these anytime from the integration's settings.

  • In Jira, add a matching label to each issue you want tracked in Vanta.

  • Confirm a labeled issue appears as a task in Vanta.

  • Synced issues show as open or closed in Vanta based on their Jira status, so resolving the issue in Jira resolves it in Vanta on the next sync.

Step 6: Create Jira issues from Vanta

You can also work in the other direction, creating a Jira issue directly from Vanta, for example to assign remediation work for a failing test.

  • In Vanta, go to Tests and open the relevant test.

  • Open the Tasks tab and click Create task.

  • From the dropdown, select Create Jira Data Center issue.

  • In the modal, select the connection you want to create the issue in. If you have more than one instance connected, the available projects, issue types, and assignees load from the connection you pick.

  • Select the project and the issue type (for example Bug, Story, or Task).

  • Optionally, assign the issue to someone and set a reporter.

  • Choose how to handle the test's detected items: create one issue covering all detected items, or create an individual issue for each one.

  • Adjust the issue name and description if needed, then click Create.

The issue is created in your Jira instance and appears linked in Vanta, and its open or closed status syncs back automatically.

⚠️ Note: Epic and Sub-task issue types are not available when creating an issue from Vanta.


Permissions

Jira Data Center uses a Personal Access Token, not OAuth. A PAT inherits the permissions of the user who created it, so Vanta can see exactly what that user can see, no more and no less. There are no separate scopes to grant or review.

Read access

We use the token to read user accounts (display name, email address, username, active status, and group membership), and to pull issues, labels, projects, and issue types from the projects the connecting account can browse. Projects that account cannot see will not sync.

Write access

We have write access in one specific situation:

  • Creating issues: When you create a Jira issue from a Vanta test or control, we post the issue to your Jira Data Center instance on behalf of the connecting account, including setting the reporter you select. This requires the account to have permission to create issues in the target project and to set the reporter field (Jira's Modify Reporter permission). If it doesn't, syncing still works but issue creation fails.

We do not modify or delete existing Jira issues, projects, or user data.


Troubleshooting and FAQs

"Failed to validate Jira Data Center credentials. Please ensure that you are using a valid API Key."

  • Likely cause: The tenant URL is wrong or incomplete, the token is invalid or expired, or Vanta cannot reach your instance.

  • How to confirm: Check that the tenant URL includes https:// and any non-standard port. Confirm the token has not expired and that the account that created it is still active with access to the projects you expect.

  • Fix: Correct the tenant URL, or generate a new Personal Access Token and update the connection. If your instance restricts inbound traffic by IP, allowlist Vanta's IP address.

I picked a connection but the issue was created in the wrong instance

  • Likely cause: The projects, issue types, and assignees in the create-task modal are loaded from the connection selected at the top of the modal.

  • How to confirm: Check which connection was selected when the issue was created.

  • Fix: Select the connection first, and if you change it after choosing a project, re-check your selections before creating the issue.

Some of my Jira projects aren't syncing

  • Likely cause: Vanta only sees projects the connecting account can browse.

  • How to confirm: Sign in to Jira as the connecting account and confirm whether the missing projects are visible.

  • Fix: Grant that account access to the missing projects, then wait for the next sync.

My accounts stopped syncing after someone left the company

  • Likely cause: The token was generated from that person's personal account, and the account was deactivated, which invalidates the token.

  • How to confirm: Check whether the Jira account used to generate the token is still active.

  • Fix: Generate a new token from a dedicated service account and update the connection in Vanta.

Before contacting Support

Collect the following:

  • Your Jira Data Center instance URL

  • The exact error message shown in Vanta

  • The Jira account used to generate the token, and its project access

  • Whether the instance is behind a VPN, firewall, or IP allowlist