Features · Integrations

Made to fit your toolchain

REST API, signed webhooks, Slack, Git linking and Jira-compatible CSV.

Everything your team does in the tracker is reachable over a documented REST API, and every ticket event inside it can flow out — to your own endpoints, to Slack, or back onto tickets from your Git host. Outbound webhooks are signed and retried from a durable outbox. Inbound, commits and pull requests link themselves to tickets by key, CSV moves data in and out in a Jira-compatible shape, and a dedicated importer pulls whole projects from Jira Cloud or Data Center.

HMAC-SHA256 signed payloads5 delivery attempts with backoff3 plugin hooks1,000 rows per CSV import

What you get

  • REST API with OpenAPI — Every feature is served over a versioned REST API under /api/v1, with interactive OpenAPI documentation at /swagger-ui.html.
  • Signed outbound webhooks — Register per-project webhook endpoints with an event filter; each delivery carries an HMAC-SHA256 signature in the X-IssueHub-Signature header, plus event and delivery-id headers your endpoint can verify.
  • Slack channel updates — Point a project at a Slack incoming webhook and ticket activity posts to your channel — filtered to the event types you choose, sent asynchronously after the change commits so Slack can never slow a request.
  • Git commit and PR linking — A per-project inbound webhook authenticates pushes by GitHub HMAC signature or a shared token header, then links commits, branches and pull requests to tickets wherever a message, branch name or PR title mentions a key like PROJ-12.
  • Jira-compatible CSV — Export a project's tickets as CSV, and import CSV with only a title column required — Jira export headers such as Summary, Issue Type and Story Points are recognised automatically, with per-row error reporting.
  • Direct Jira import — An admin-only importer connects to Jira Cloud (REST v3, API token) or Jira Data Center (REST v2, personal access token), auto-detects the edition, and imports projects, issues, comments and attachments — rich text is normalised to Markdown and re-runs are idempotent.

Webhook delivery you can audit

Outbound deliveries use an outbox pattern: the delivery row is written in the same transaction as the change itself, so an event is never lost to a crash. A background poller then sends pending deliveries with exponential backoff — up to five attempts, starting at 30 seconds and doubling each time — and a compare-and-swap claim guarantees exactly one node delivers even when several backends poll the same queue. A per-webhook delivery log shows the last 50 deliveries with status, attempt count and last error; the signing secret itself is never returned by the API.

Smart commits

With Git integration enabled, a project admin can additionally opt in to Jira-style smart commits: #comment adds a comment, #time logs work (2h 30m, with w and d as working weeks and days), and any other #word is matched against your workflow's status names as a transition. Commands run as the commit author, matched by email — no matching account, no actions — and go through the same services as the UI, so permissions, workflow rules and notifications all apply.

Sandboxed plugins

Installed plugins can carry a JavaScript script that runs in a locked-down GraalJS sandbox: no host classes, no filesystem, no network. Scripts react to three hooks — onTicketEvent, onComment and onSlaBreach — and are bounded by a 100,000-statement limit and a 5-second wall-clock watchdog, with at most 10 collected actions per run. A failing or runaway script is isolated and logged; it can never break the operation that triggered it. The action surface is deliberately small today: scripts can add labels to the triggering ticket.

In practice

git commit -m "PROJ-12 #comment deployed to staging #time 2h 30m #done"

See Iskue on your own screen

A demo takes half an hour. A pilot runs on your servers, with your data, from day one.