---
title: "Jira Issue Sync"
description: "Automatically create a Jira issue for each TurboPentest finding so your team can triage and track remediation in the tools they already use."
canonical: https://turbopentest.com/docs/integrations/jira
source: "TurboPentest Docs"
---

# Jira Issue Sync

Create Jira issues for each finding so your team can track remediation.

## Setup

1. Generate a Jira API token at [id.atlassian.com](https://id.atlassian.com/manage-profile/security/api-tokens)
2. Go to **Dashboard > Account > Notifications** (the Integrations tab links here too)
3. Add the Jira integration with your instance details

### Via API

```bash title="Terminal"
curl -X POST https://turbopentest.com/api/integrations \
  -H "Authorization: Bearer $TURBOPENTEST_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "type": "jira",
    "config": {
      "instanceUrl": "https://your-org.atlassian.net",
      "projectKey": "SEC",
      "email": "your-email@example.com",
      "apiToken": "your-jira-api-token",
      "ticketMode": "per_finding",
      "minSeverity": "low"
    }
  }'
```

## Configuration

| Field | Description |
|-------|-------------|
| `instanceUrl` | Your Jira Cloud URL (e.g. `https://your-org.atlassian.net`) |
| `projectKey` | The project key where issues will be created |
| `email` | The email associated with your Jira API token |
| `apiToken` | Your Jira API token |
| `ticketMode` | Optional. `per_finding` (default) or `summary` |
| `minSeverity` | Optional. Minimum severity to sync: `critical`, `high`, `medium`, `low` (default), or `info` |

TurboPentest connects to Jira Cloud through its REST API v3 using basic auth (your email plus the API token).

## Sync modes

TurboPentest supports two modes for turning findings into Jira issues:

| Mode | Behavior |
|------|----------|
| `per_finding` (default) | Creates one Jira issue per finding |
| `summary` | Creates a single summary issue for the whole pentest |

You can also set a **minimum severity threshold** so that only findings at or above a chosen severity are synced (for example, skip Info and Low findings).

## How it works

When a pentest completes, TurboPentest creates Jira issues according to your configured mode and severity threshold. Each issue is created with issue type **Bug**, the `turbopentest` label, and:
- Title matching the finding title
- Description with severity, proof of exploit, and remediation
- Priority mapped from finding severity

### Severity to priority mapping

| Finding severity | Jira priority |
|------------------|---------------|
| Critical | Highest |
| High | High |
| Medium | Medium |
| Low | Low |
| Info | Lowest |
