Atlassian’s direction for new Cloud extensibility is Forge. If you still run a Connect app—especially one with iframes, remote backends, and JWT lifecycle hooks—you need a migration plan that protects installs, data, and Marketplace listing continuity.
This checklist is written for teams who already shipped Connect and need a sober path to Forge (or a hybrid period) without a big-bang rewrite.
Decide the migration shape
- Full Forge rewrite: UI Kit / Custom UI + Forge functions replace Connect modules and your remote server for the hot path.
- Forge + remote: Forge owns auth and UI; complex jobs stay on your EU-hosted API via egress.
- Retire and replace: sometimes a new Forge app with a cleaner data model is cheaper than mapping every Connect quirk.
Pick based on traffic, custom field debt, and how much of your value lives in proprietary algorithms vs Jira UX.
Inventory before you write code
- List every Connect module (
jira:issuePanel, admin pages, webhooks, etc.) and the equivalent Forge module—or the gap. - Catalogue REST scopes and user vs app permission usage.
- Map Connect storage (entity properties, your DB) to Forge storage / external DB.
- Document egress hosts, secrets, and compliance constraints (GDPR, retention).
- Note Marketplace listing assets: privacy URL, support URL, screenshots, pricing model.
Auth and identity
Connect’s JWT lifecycle is not Forge’s model. Plan for:
- OAuth / Forge scopes replacing ad-hoc JWT verification on your server.
asUservsasAppcall sites—many Connect apps mixed these implicitly.- Admin pages that assumed cookie sessions on your origin—those need redesign under Forge hosting rules.
Webhooks and lifecycle
- Replace Connect webhooks with Forge events / web triggers where possible.
- Rebuild install/uninstall handlers; do not assume silent data wipe policies match.
- Plan dual-running: Connect receives events until Forge is installed and verified, then deprecate.
UI migration
Iframes that depended on full control of CSS/JS often become Custom UI. UI Kit is faster when the interface is simple. Budget time for Atlassian design guidance compliance—Marketplace review cares.
Data migration checklist
- Export entity properties / app settings per install.
- Re-key storage under Forge installation context.
- Provide a one-time migration admin action with progress and logs.
- Keep a rollback: Connect remains installable until Forge metrics look healthy.
Testing gates
- Unit tests for mappers and auth.
- Forge tunnel against a dedicated Jira Cloud site.
- Permission matrix: site admin, project admin, standard user, anonymous (should fail).
- Load test webhooks if you ingest high volume.
- Privacy / security questionnaire drafts updated for Forge hosting.
Marketplace submission notes
- Update listing copy: hosting model changed; say so clearly.
- Refresh privacy policy for Forge (Atlassian subprocessors + your remotes).
- Verify Cloud Fortified / security requirements if you pursue them.
- Communicate breaking changes and migration windows to existing customers.
Timeline realism
A thin Connect panel can move in weeks. A Connect app with a large Node/Java backend, custom auth, and years of per-tenant config is a multi-sprint programme. Sequence by risk: read-only surfaces first, write paths second, billing/admin last.
Need this built? HostHob ships production integrations and Marketplace-ready apps from Rotterdam. See our services or Plan a Connect → Forge migration.
