How to Set Up Jira API Tokens and Back Up Jira Cloud

Jira API tokens and a tested backup routine give your team integrations that authenticate with only the access they need and a Jira Cloud site you can restore on demand. Configuring both from day one puts every script, sync, and restore on a documented path instead of a personal login. This guide covers four tasks:

Before You Start

Create a Personal API Token With Scopes

  1. Sign in at id.atlassian.com/manage-profile/security/api-tokens.
  2. Select Create API token with scopes.
  3. Name the token after the script or tool that will use it.
  4. Select an expiration date. Tokens last between 1 and 365 days, and the default is one year.
  5. Select the app the token will access, such as Jira.
  6. Select only the scopes the token needs.
  7. Select Create, then Copy to clipboard.
  8. Save the token in your password manager.

Scripts authenticate with basic auth, using your Atlassian account email as the username and the token in place of a password. To revoke a token, return to the same page and select Revoke next to it, or Revoke all API tokens.

A personal token acts as you and stops working when your account is deactivated, so keep it for your own scripts and short-lived tasks.

Create a Service Account Token for Integrations

Service accounts are not tied to a person, so integrations built on them keep running through staffing changes.

  1. Go to Atlassian Administration and select your organization.
  2. Select Directory → Service accounts.
  3. Select the service account, then Create credentials.
  4. Select API token, then Next.
  5. Name the token and select an expiration date.
  6. Select the scopes it needs in Jira or Confluence.
  7. Review the token, select Create, then Copy to clipboard.

Service account tokens must be scoped, and scopes cannot be changed after creation, so create a new token when an integration needs different access. Requests must use the api.atlassian.com gateway URLs rather than your site URL. Service accounts can also use OAuth 2.0 credentials for integrations built on OAuth flows.

Create a Jira Cloud Backup

Backup manager exports the whole site, so one backup covers every project at once.

  1. Select Settings → System.
  2. Under Import and Export, select Backup manager.
  3. Under Backup for cloud, choose whether to include attachments, avatars, and logos.
  4. Select Create backup for cloud.
  5. When the backup completes, select Download backup file and store it with restricted access.

Backups that include attachments, avatars, or logos need 48 hours between runs. Backup manager restores only from backups that are 30 days old or less, so a regular schedule keeps a usable file on hand.

Restore a Backup

Run a restore into a sandbox or an empty site before you ever need one in production.

  1. Select Settings → System.
  2. Under Import and Export, select Import Jira Cloud.
  3. Upload the backup file and follow the prompts.

A restore overwrites the target site's database, and importing attachments, avatars, or logos overwrites those files as well. Users in the backup merge with existing cloud users, which can grant additional app access, and the import does not apply default app access settings. Review group membership after every restore.

What a Restore Brings Back

The backup restores:

These are not in the backup and need their own record:

Keep a copy of your automation rules and a list of installed apps alongside each backup file. On Premium or Enterprise plans, Atlassian Backup and Restore is available as an add-on that runs scheduled backups in Atlassian storage and restores to an empty site or sandbox.

What You Gain

Who Should Own It

Outsourcing Jira administration is the default recommendation for most SMBs. A managed IT partner runs token rotation, backup downloads, and test restores as routine work, and keeps the credentials on service accounts from the start. Companies that already have an IT partner get the most from this by adding token expiry and backup checks to the work that partner already covers.

ScaleIt administers Jira and Jira Service Management for startups and SMBs as part of managed IT support, including service accounts, token rotation, and backup schedules. Book a free call and we will map a token and backup setup for your site.

Verified against Jira Cloud and Atlassian Administration on 2026-09-29. Vendor docs: https://support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/, https://support.atlassian.com/user-management/docs/manage-api-tokens-for-service-accounts/, https://support.atlassian.com/jira-cloud-administration/docs/export-issues/, https://support.atlassian.com/jira-cloud-administration/docs/import-issues/, https://support.atlassian.com/organization-administration/docs/manage-backup-and-restore-for-atlassian-products/.