> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Atlassian

<div className="page-title-row">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/connectors/atlassian.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=c9604a0fcc88f7a29f1fde0bdd27d85d" alt="" noZoom width="24" height="24" data-path="images/connectors/atlassian.svg" />

  <h1>Atlassian</h1>
</div>

## Connection

### Setup

In Atlassian Administration,
[create an organization API key](https://support.atlassian.com/organization-administration/docs/manage-an-organization-with-the-admin-apis/)
with the scopes listed under [Settings](#settings).

### Settings

| Setting         | Required | Description                                                                                                                                                                                                                               |
| --------------- | -------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Organization ID | Yes      | Organization ID, the identifier after /o/ in the Atlassian Administration address.                                                                                                                                                        |
| API key         | Yes      | Organization API key from Settings, API keys. It needs only these scopes: read:directories:admin, read:user:admin, write:user:admin, read:group:admin, write:group:admin. Atlassian expires a key after a year at most. Stored encrypted. |
| Directory ID    |          | Directory accounts are written in. Leave empty when the organization has only one.                                                                                                                                                        |

### Permissions

Minimum permissions the connection requires.

| Capability   | Required | Granted by (any one)   |
| ------------ | -------- | ---------------------- |
| Manage users | Yes      | `Organization API key` |
| Read groups  | Yes      | `Organization API key` |

## atlassian.user

### Fields

| Field      | Type            | Required | Description                                                                                                                                                                                    |
| ---------- | --------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `email`    | reference, user | Yes      | Address the invitation goes to and the account signs in with. Cannot change once the account exists. Names the account rather than describing it, so a diff leaves it out.                     |
| `active`   | bool            |          | Whether the account has access. An inactive account is suspended, which frees its seat and holds its groups for a later restore.                                                               |
| `groups`   | grant           |          | Groups the account belongs to, which is what carries app access. A group an identity provider synchronizes is not offered, because only that provider may change it. One row grants one group. |
| `groups[]` | string          |          | Group ID.                                                                                                                                                                                      |

### Default Account Matching Rules

When Klef [adopts](/docs/adoption) an account that already exists in Atlassian, it works out whose it is by trying these in order. A connection can override them.

| Account field | Worker field            |
| ------------- | ----------------------- |
| `email`       | `worker.business_email` |

## Examples

### Atlassian users

An Atlassian account for every engineer, in the groups that carry Jira and Confluence access, suspended and cleared when they leave.

```hcl theme={null}
stage active {
  target atlassian.user {
    email  = worker.business_email
    active = true
    groups = ["jira-software-users", "confluence-users"]
  }
}
```
