Overview

Two ways to reach your BesTest data from outside Jira: a REST API for scripts and CI, and an MCP server for AI agents. Both are in open beta, both use the same self-service tokens.

BesTest keeps your requirements, test cases, cycles and executions in one place inside Jira. This section is about reaching that same data from outside the app: from a script, a CI pipeline, or an AI agent.

There are two doors, and they open onto the same data with the same permissions:

REST APIMCP
You use it fromScripts, CI pipelines, dashboards, your own toolsAI agents: Claude, Cursor, Codex, Copilot and others
You writeHTTP requestsPlain English
Best forRepeatable, scheduled, exact workExploring, summarising, one-off questions, drafting and bulk edits
Typical job"Record last night's Playwright results against the cycle""Which test cases failed twice in a row this week?"

Most teams end up using both. The pipeline writes results through the REST API every night, and a person asks the agent what the results mean in the morning.

Open beta

The REST API and the MCP server are both in open beta. Anyone can create a token and start today, with no request form and no waiting. Beta means the surface can still change; we will tell you before anything breaks. What is on these pages is what works now.

One token, both doors

You do not need separate credentials. A single BesTest token authenticates the REST API and MCP alike, sent as a bearer token in an Authorization header.

You create tokens yourself, from the app menu in BesTest, under API & MCP tokens. API tokens has the full walkthrough with screenshots.

Three things about a token shape everything else:

  • A token reaches exactly one Space. If you automate two Spaces, you create two tokens. That keeps revocation honest: switching off one token can never silently break something in a Space you were not thinking about.
  • A token is either read only or read and write, chosen when you create it.
  • A token always expires, after 30, 60 or 90 days, a year, or a date you pick. A year is the maximum, and there is no never-expires option.

Pick the right base URL for your region

BesTest runs separate, independent servers in three regions, and your data lives in exactly one of them. A token only works against the region that issued it. If a correct-looking token gets 403 Forbidden, the base URL is the first thing to check.

Your data regionBase URL
Europehttps://prod-eu.getbestest.com
North Americahttps://prod-us.getbestest.com
Indiahttps://prod-in.getbestest.com

Every path in this section hangs off that base URL:

SurfacePathFull example (Europe)
REST API/api/v1https://prod-eu.getbestest.com/api/v1
MCP/mcphttps://prod-eu.getbestest.com/mcp
Not sure which region you are in?

Call GET /api/v1/projects with your token against each base URL. Only your own region answers 200, and it returns the Space your token reaches; the other two answer 403. If you would rather ask, support will tell you which server holds your data.

Regional hosting is also why your data stays where you need it: an EU customer's requirements, test cases and results stay on the EU server. Other regions can be provisioned on request.

What a token can see

A token never grants more than the person who created it already has. It is not a service account and it is not a way to escalate.

  • It is bound to one Space, so it cannot read or write anything in any other Space.
  • Inside that Space, a read only token reads what you can read and changes nothing. A read and write token can also create and update, within your own permissions.
  • Every write is attributed to the token's owner, so history still shows a person, not an anonymous robot.

A Space admin sees every token pointed at their Space and can revoke any of them, the safety valve when someone leaves the team or a laptop goes missing. Admins cannot create, rotate or see someone else's token.

What you can reach

The API covers the testing data you work with every day: requirements, test cases and their steps, test cycles, executions and step results, test collections, test campaigns, folders, traceability links to Jira work items, comments, and your Space's custom fields.

A few things are deliberately out of reach of a token during the beta: review and approval decisions, the reporting and coverage views, notifications, token management itself, and the in-app bulk importer. For a large one-off migration, use Import, Export in the app, or have an agent create records in batches over MCP.

Rate limits

Requests are rate-limited per person, and the REST API and MCP share the same limits. They sit well above what a pipeline or an agent normally needs. If you do go over, you get HTTP 429 with the code RATE_LIMITED; wait a few seconds and retry. How not to hit them.

What it costs

Nothing extra. Programmatic access is included on every plan, the free tier included, with no per-call charge.

Where to go next

  1. Create your first token. Everything else needs one.
  2. Connect an AI agent if you want to ask questions in plain English. There are step-by-step guides for Claude Code, Claude Desktop, Cursor, VS Code, Codex and others.
  3. Read the REST API guide if you are writing a script or a pipeline step, then copy a recipe: recording a CI run into a cycle, gating a release, exporting to a dashboard.
  4. Browse the API reference for every endpoint, field and filter, plus worked multi-step workflows.
Getting started

Live in about a minute.

  1. ~30 seconds
    1.Install from the Marketplace

    One click on "Get it now" - no sales call, no signup form, no separate login.

  2. ~1 minute
    2.Enable it on a Space

    Flip it on in Space settings. BesTest shows up in the Space menu, where your team already works.

  3. right away
    3.Run your first test

    Create a requirement, link a test case, hit run. No training course required.

Host your data in the EU, US, or IndiaNo Jira issue bloat - your library stays out of Jira’s wayBuilt on Atlassian Forge