Skip to content
Published

Last reviewed: 2026-09-11

Jira and Linear issue trackers

Create Jira Cloud or Linear tickets automatically from CodeCleared webhook events, with multi-connection routing and OAuth or API token auth.

Purpose

Native issue-tracker connections create tickets in Jira Cloud or Linear when selected CodeCleared events fire. Use them to close the loop from finding or scan signal to your team’s backlog without copying payloads by hand.

Who this is for

Organization admins and owners on Team or Regulated (SLA feature gate). Engineers consume the resulting tickets in Jira or Linear.

Prerequisites

  • Team or Regulated plan with SLA entitlement.
  • Jira Cloud site or Linear workspace where the connecting account can create issues.
  • For OAuth: CodeCleared’s platform apps are preconfigured; you only authorize your workspace.
  • For API token fallback: a Jira API token (email + token + site URL) or Linear API key.

Steps

  1. Open Settings → Issue trackers.
  2. Choose Connect Jira (OAuth) or Connect Linear (OAuth), or Add with API token.
  3. After connect, open Configure:
    • Jira: pick site (if several), project, and issue type (required; Epic and subtasks are not supported).
    • Linear: pick team.
  4. Select events (same catalog as outbound webhooks). Defaults are finding.sla.at_risk and finding.sla.breached.
  5. Enable Active and save. Use Test to verify credentials.

You may create up to five connections per organization (multiple Jira and/or Linear). Example: one connection routes SLA breaches to a security project; another routes scan.completed to an ops board.

Business rules

  • Events match the outbound webhook catalog (scan.completed, policy and PR-check failures, SLA lifecycle, governance exceptions, compliance score changes).
  • Idempotency: for finding SLA events, one ticket per finding per connection (later lifecycle events do not open duplicates). Other events use occurrence-specific keys (scan job, PR SHA, etc.).
  • OAuth tokens are stored encrypted; refresh failures soft-disable that connection only. Repeated ticket-create failures also soft-disable the connection (same idea as webhook delivery thresholds).
  • Ticket titles/descriptions include scan type, finding summary counts, repo/project-unit names, SLA fields, and an in-app deep link when available.
  • Issue creation is one-way in this version (no close/sync back into CodeCleared).
  • Jira Epic / parent-link and subtask types are out of scope for auto-create.

Scenarios & edge cases

Two Jira projects: add two Jira connections with different projects and event sets.
OAuth vs token: OAuth is preferred; API token remains available when OAuth apps cannot be used.
Inactive until configured: a connection stays inactive until Jira has project + issue type (or Linear has team).

Limits

About five connections per organization. HTTP timeouts apply to provider APIs. Ticket titles and descriptions are truncated and sanitized.

Common errors

  • Activating without project/issue type or team.
  • Selecting a private or non-HTTPS Jira base URL when using API tokens (SSRF protection).
  • OAuth state expired — restart Connect.
  • Plan without SLA entitlement — upgrade to Team or higher.

Links