Jira Issue Sync
Create Jira issues for each finding so your team can track remediation.
Setup
- Generate a Jira API token at id.atlassian.com
- Go to Dashboard > Account > Notifications (the Integrations tab links here too)
- Add the Jira integration with your instance details
Via API
curl -X POST https://turbopentest.com/api/integrations \
-H "Authorization: Bearer $TURBOPENTEST_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"type": "jira",
"config": {
"instanceUrl": "https://your-org.atlassian.net",
"projectKey": "SEC",
"email": "your-email@example.com",
"apiToken": "your-jira-api-token",
"ticketMode": "per_finding",
"minSeverity": "low"
}
}'Configuration
| Field | Description |
|---|---|
instanceUrl | Your Jira Cloud URL (e.g. https://your-org.atlassian.net) |
projectKey | The project key where issues will be created |
email | The email associated with your Jira API token |
apiToken | Your Jira API token |
ticketMode | Optional. per_finding (default) or summary |
minSeverity | Optional. Minimum severity to sync: critical, high, medium, low (default), or info |
TurboPentest connects to Jira Cloud through its REST API v3 using basic auth (your email plus the API token).
Sync modes
TurboPentest supports two modes for turning findings into Jira issues:
| Mode | Behavior |
|---|---|
per_finding (default) | Creates one Jira issue per finding |
summary | Creates a single summary issue for the whole pentest |
You can also set a minimum severity threshold so that only findings at or above a chosen severity are synced (for example, skip Info and Low findings).
How it works
When a pentest completes, TurboPentest creates Jira issues according to your configured mode and severity threshold. Each issue is created with issue type Bug, the turbopentest label, and:
- Title matching the finding title
- Description with severity, proof of exploit, and remediation
- Priority mapped from finding severity
Severity to priority mapping
| Finding severity | Jira priority |
|---|---|
| Critical | Highest |
| High | High |
| Medium | Medium |
| Low | Low |
| Info | Lowest |
Slack Notifications
Get TurboPentest results delivered straight to your Slack channel, with a notification each time a pentest completes so your team stays in the loop.
MCP Server & Dev Tools
Drive TurboPentest from your editor and terminal - a local and remote MCP server for AI coding agents, plus native Burp Suite and VS Code extensions.