Azure DevOps for Jira
Auto Light Dark
Auto Light Dark

How Azure DevOps for Jira works and what data is stored

This guide covers how Azure DevOps for Jira is architected on Atlassian Forge, what data it stores versus simply passes through, and how long each is retained.

This document related to Azure DevOps for Jira.

Azure DevOps for Jira runs entirely on Atlassian Forge. All app data is stored and processed on Atlassian infrastructure.


At a glance

Topic

Answer

Hosting

Atlassian Forge, on Atlassian infrastructure.

Credentials

PATs and webhook credentials are stored only in the Forge Secret Store, never returned to the client, and masked in logs. OAuth tokens (Create branch) are held by Atlassian's Forge OAuth provider; the app never sees them.

Commits, branches, pull requests, builds, deployments

Passed through to Jira. Not stored by the app.

Work items, comments, attachments

Passed between Jira and Azure DevOps. Not stored by the app; only identifiers and file metadata are kept for deduplication.

Logs

Atlassian Forge logs, event metadata only, retained 30 days. Site admins can disable developer access.

After uninstall

Atlassian retains Forge storage for 28 days, then deletes it.


Architecture

The app has two main features sharing the same infrastructure:

  • Dev Activities in Jira - shows Azure DevOps commits, branches, pull requests, builds and deployments in Jira, and lets users create branches from Jira.

  • Work Items Sync - keeps Azure DevOps work items and Jira issues in sync, optionally including comments and attachments.

Both receive Azure DevOps events through Forge web triggers, process them via Forge async queues, and call the Azure DevOps and Jira REST APIs.

Dev Activities Setup Flow

Setup (Dev Info).png

Work Item Sync Setup Flow

Setup (Work Item Sync).png

Azure DevOps Webhook Processing Flow

Setup (Azure DevOps Webhook Processing).png


External systems

  • dev.azure.com, vsrm.dev.azure.com, app.vssps.visualstudio.com, vsaex.dev.azure.com - or your Azure DevOps Server host

  • login.microsoftonline.com - OAuth for Create branch

  • Jira Cloud REST API - via the Forge platform


Dev Activities in Jira

Setup

  • Only Jira administrators can create, view or delete integrations.

  • Required PAT scopes: Code (Read), Build (Read), Release (Read). Validated with read-only calls.

  • PAT is stored in the Forge Secret Store; configuration metadata in the Forge Custom Entity Store.

Connecting a project

  • Registers Azure DevOps Service Hooks for code pushes, pull requests (created, updated, merged), build completion, pipeline stage changes and deployments.

  • Each hook is protected by generated credentials stored in the Forge Secret Store.

  • The PAT owner needs the Edit subscriptions permission on the project. If hook creation fails, the connection is rolled back.

Event processing

  • The app authorizes the request, fetches any missing details from Azure DevOps, and sends the development information to Jira.

  • Nothing from the event is stored.

Backfill

  • Imports historical commits, pull requests and branches into Jira - up to two months per run, up to two years back.

  • Stores only run status, selected scope, progress and who started the run.

Creating a branch

  • Uses the user's own credentials, never the integration PAT.

  • OAuth: scopes vso.code_write, vso.project, vso.profile, offline_access; tokens managed by Atlassian.

  • PAT: requires Code (Read & write); stored in the Forge Secret Store.

  • Azure DevOps enforces the user's repository permissions.


Work Items Sync

Setup

  • Only Jira administrators can create integrations.

  • Required PAT scopes by direction:

    • Azure DevOps → Jira: Work Items (Read), Project and Team (Read & write)

    • Jira → Azure DevOps: Work Items (Read & write)

    • Two-way: both of the above

  • Member Entitlement Management (Read) is optional - used only to list users when configuring assignee mappings.

Synchronization

  • Registers Service Hooks for work item created, updated and (if enabled) commented.

  • Work item content, comments and attachments are passed between the systems in memory and not stored.

  • The app keeps only identifiers and metadata for deduplication.

  • User mappings (Jira and Azure DevOps user ids and emails) are stored only for users an administrator explicitly maps.


Logs

  • Written to Atlassian Forge logs; retained by Atlassian for 30 days.

  • Contain event metadata only (ids, event types, statuses, errors). Credentials are masked.

  • Site administrators can disable developer access to app logs in Atlassian Administration.


Data retention

  • Configurations remain until deleted by an administrator or the app is uninstalled.

  • On uninstall, Atlassian retains Forge storage for 28 days and then deletes it. Customers can request data recovery from Atlassian within that period.


Note on Azure DevOps Server (on-premises) and static IP

To reach an on-premises Azure DevOps Server when the Static IP option is enabled, the app routes its Azure DevOps traffic through a proxy operated by Move Work Forward on AWS (api.moveworkforward.net, static.moveworkforward.net).

  • The proxy relays requests and responses between Forge and your Azure DevOps host, including inbound Service Hook events. It does not persist the data it relays.

  • Proxy logs are retained for 7 days.

  • All other storage and processing remains on Atlassian Forge as described above.


Updated: September, 2025