- Documentation
- Integrations
- Apps
- Confluence Cloud integration
Confluence Cloud integration
Create, update, and search pages, blog posts, comments, and tasks across your clients' Confluence Cloud sites from any TaskJuice workflow.
What it does
The Confluence Cloud integration lets your agency run documentation operations inside every client's wiki from a single workflow. Connect a client's site once and TaskJuice can create and update pages and blog posts, upload attachments, manage labels and comments, run CQL searches across all content, chase page tasks, set content restrictions, and watch for new or changed content on an interval.
Confluence shares its Atlassian identity with Jira Cloud, so a client who authorizes both grants them through one consent screen against the same site.
Connect a Confluence Cloud account
Every OAuth integration in TaskJuice uses your own Atlassian app, so your client sees your agency's name on the consent screen rather than ours.
Confluence Cloud previously authenticated with an Atlassian account email and API token. Connections made under that model cannot be carried over — an API token cannot be exchanged for an Atlassian access token, and the new endpoints are addressed by cloud ID rather than site name. Re-create any existing Confluence connection through the flow below.
One-time setup for your agency
- Go to developer.atlassian.com/console/myapps and create an OAuth 2.0 integration.
- Under Permissions, add the Confluence API and select Configure. Tick the scopes listed below — you need entries from both the granular and classic lists.
- Under Authorization, configure OAuth 2.0 (3LO) and add your workspace's callback URL (
https://<your-domain>/oauth/callback). - Under Distribution, enable sharing so clients other than yourself can authorize the app. Atlassian will ask for a privacy policy URL and a support contact.
- Copy the client ID and secret from Settings, then in TaskJuice open Settings → Integrations → OAuth clients and add a Confluence Cloud client with those credentials and the same scope list.
Scopes to request
The bundle spans both Confluence REST APIs, because v2 does not implement everything v1 does. Ticking only the granular scopes leaves attachment upload, label writes, and CQL search failing when you publish a workflow. Tick exactly these — every one is consumed by a shipped action, trigger, or picker, and anything extra is standing access to your client's wiki that nothing here uses. User lookups are covered by the classic read:confluence-user, so the granular read:user:confluence is not required.
Granular (REST v2): read:page:confluence, write:page:confluence, delete:page:confluence, read:comment:confluence, write:comment:confluence, delete:comment:confluence, read:attachment:confluence, delete:attachment:confluence, read:space:confluence, write:space:confluence, read:label:confluence, read:task:confluence, write:task:confluence
Classic (REST v1): write:confluence-content, read:confluence-content.all, write:confluence-file, search:confluence, write:confluence-space, read:confluence-user
Refresh: offline_access — add this to your TaskJuice OAuth client only. It is a request-time scope and does not appear in the Atlassian console's permission list, but without it Atlassian issues no refresh token.
Connecting a client's site
-
In the workflow editor, add a Confluence Cloud node and choose Add connection.
-
Sign in as the Atlassian user whose Confluence site you are managing, and approve the scopes.
-
Paste the client's Atlassian Cloud ID into the connection field. There is no picker — Atlassian only exposes the ID through its own API, so fetch it with the access token you just minted and copy the
idof the site you are managing:curl -sS -H "Authorization: Bearer $ACCESS_TOKEN" \ -H "Accept: application/json" \ https://api.atlassian.com/oauth/token/accessible-resourcesThe response is an array of the sites that token can reach —
[{"id":"11223344-a1b2-3b33-c44d-1234abcd9876","url":"https://acme.atlassian.net", ...}]. Match onurland copy the siblingid. Every subsequent call is routed to that site.
To revoke access, the connected user opens id.atlassian.com → Account settings → Connected apps and removes your app.
Triggers
Confluence Cloud does not offer webhook registration to OAuth or API-token apps. Webhooks exist only for Connect and Forge marketplace apps, so TaskJuice ships polling as the declarative path, plus one manually-wired real-time trigger.
new-page, page-updated and new-blog-post each poll one space, and the space is a required setting — Confluence's page and blog-post lists take a single space filter, so there is no "all spaces" value to leave blank. To watch every space at once, use new-content-matching-cql with a CQL query.
Every polling trigger suppresses its first cycle — it records a baseline and emits nothing, so content that already existed when you published the workflow does not fire. Each cycle emits one activation whose items array carries the newly observed records; add a Loop node (type: array, arrayPath: items) downstream to act on each one, or skip the Loop for digest-style workflows.
confluence-cloud/new-page— pages created in one space. The space is required.confluence-cloud/page-updated— pages edited in one space. The space is required. De-duplicates per version, so each new version fires once and an unchanged page does not re-fire.confluence-cloud/new-blog-post— blog posts published in one space. The space is required.confluence-cloud/new-comment— footer comments added anywhere on the site.confluence-cloud/new-attachment— files attached to any content.confluence-cloud/new-space— spaces created. Low volume; use a long interval.confluence-cloud/new-content-matching-cql— content that newly matches a CQL query you supply. This covers every filter the other triggers do not: label, ancestor, contributor, content state, or full text. Appendorder by created descto your query: v1 search orders by relevance by default, which is not a stable watermark.confluence-cloud/automation-event— real-time delivery from a Confluence Automation rule you wire by hand (below).
There is no trigger for Confluence page tasks. GET /api/v2/tasks exposes no sort parameter and returns tasks oldest-first, so a poll over it re-reads the same first page forever once a site holds more than one page of tasks. The find-tasks action covers the same data on demand.
Real-time delivery with a Confluence Automation rule
This is the only sub-poll-interval path Confluence supports.
- In the target space, go to Space settings → Automation → Create rule.
- Choose a trigger such as Page published or Page updated.
- Add a Send web request action and paste the webhook URL from the
automation-eventtrigger in TaskJuice. - Set the HTTP method to POST and add a header
X-TaskJuice-Inbound-Secretwith the shared secret shown on the trigger. Deliveries without it are refused. Confluence cannot sign or timestamp the request, so that header is the whole check: anyone who captures one delivery can replay it indefinitely, and rotating the shared secret is the only way to revoke it. - Set the body to Custom data and paste:
{
"event": "page_published",
"pageId": "{{page.id}}",
"pageTitle": "{{page.title}}",
"pageUrl": "{{page.url}}",
"spaceKey": "{{space.key}}",
"actorAccountId": "{{initiator.accountId}}",
"timestamp": "{{now}}"
}Confluence meters automation in steps (each trigger, condition, action, branch and loop that runs counts as one), pooled at the organization level. Free carries a low monthly allowance that will not sustain sustained webhook use; paid plans scale it per user. Check the client's actual headroom before relying on this trigger — View your Confluence automation usage.
Actions
Pages — create-page, get-page, update-page, rename-page, delete-page, purge-page, find-pages, get-child-pages, get-page-ancestors, get-page-versions, move-page, copy-page
Blog posts — create-blog-post, get-blog-post, update-blog-post, delete-blog-post, find-blog-posts
Comments — add-comment, reply-to-comment, get-page-comments, delete-comment
Attachments — upload-attachment, get-page-attachments, delete-attachment
Labels — add-labels, remove-label, get-page-labels
Spaces — get-space, find-spaces, create-space, update-space
Tasks — find-tasks, get-task, update-task
People and search — get-current-user, find-user, search-pages (CQL across all content)
Permissions and content — get-content-restrictions, add-user-restriction, remove-user-restriction, convert-content-body, get-page-properties, set-page-property
There is no generic pass-through action. Every URL above is pinned to …/ex/confluence/{cloudid}/wiki, which is what keeps one client's calls inside one client's site; an action that spliced a caller-supplied path into that position would be able to walk out of it. For an endpoint this integration does not cover, use a generic HTTP Request node, where the URL is the workflow author's explicit, reviewable choice.
Updating a page requires its current version
Confluence rejects a page update whose version number is not exactly the current version plus one. update-page therefore takes a New Version Number input, and the reliable pattern is two nodes:
- Get Page on the page ID.
- Update Page, with New Version Number set to the expression
{{$steps.get_page.data.version.number + 1}}. The arithmetic must sit inside the marker —{{…number}} + 1renders the number and then the literal text+ 1.
If you only need to change the title, use Rename Page instead — it increments the version itself and needs no upstream read.
Writing page content
create-page and update-page take a Body Format of storage (Confluence's XHTML), atlas_doc_format (ADF JSON), or wiki markup. If your upstream data is in none of these, run it through convert-content-body first.
Deleting is reversible by default
delete-page and delete-blog-post move content to the space trash, where it stays restorable and still reads back with status trashed. Use purge-page to destroy a trashed page permanently — that cannot be undone.
Known limitations
- No registrable webhooks. Confluence Cloud exposes no webhook API to OAuth 3LO or API-token apps. Real-time delivery requires the Automation rule described above, subject to your client's plan automation-step allowance.
- No task triggers.
GET /api/v2/tasksoffers no sort order and no watermark a declarative poll can page from, so no task trigger ships rather than one that would read the same oldest page forever. Pollnew-page/page-updatedand read tasks withfind-tasks, or wire an Automation rule. - Rate limits are shared across your clients. Atlassian meters the points quota against your OAuth app, not per client site, so every client site you connect draws on one 65,000 point-per-hour pool by default. Reads cost 1 point plus 1 per object returned; writes cost 1. Prefer longer poll intervals and smaller page sizes on large sites. If you outgrow the pool, apply to Atlassian for a per-tenant quota or register a second OAuth app and split clients across the two. See Confluence rate limiting.
- CQL has no
now()function. Relative dates usestartOfDay("-7d")style expressions. - v2 cannot create attachments or write labels. Those actions call REST v1, which is why the classic scopes are required.
- Footer comments only.
add-comment,reply-to-comment,get-page-comments,delete-commentand thenew-commenttrigger all address/api/v2/footer-comments. Confluence keeps inline comments (the ones anchored to a text selection) on a separate/api/v2/inline-commentsresource that this integration does not ship — reach it with an HTTP Request node.