Atlassian MCP server: connect Jira and Confluence to Claude, Cursor and ChatGPT

Atlassian's official Rovo MCP server gives AI clients governed access to Jira, Confluence and more at mcp.atlassian.com/v2/mcp. Setup per client, OAuth vs API tokens, the tools it exposes, admin controls, Rovo credits and how to keep writes in check.

Walma Engineering·Updated 5 October 2026·7 min read

Jira holds what the team is doing and Confluence holds why. An agent that can read both stops asking you to paste ticket descriptions and spec pages into the chat. Atlassian's answer is the Rovo MCP server, a hosted, official MCP server that connects Claude, Cursor, ChatGPT, VS Code and other clients to your Atlassian Cloud site. This guide covers the current endpoint, setup per client, auth options, what the tools do, and the controls an admin should look at before rolling it out. If MCP itself is new to you, start with what an MCP server is.

The endpoint: use v2

Atlassian made version 2 of the server generally available on 8 September 2026. The endpoint is:

https://mcp.atlassian.com/v2/mcp

It speaks streamable HTTP and authenticates with OAuth 2.1 by default. If you have an older config pointing at a /v1/... path, move it to /v2/mcp. According to Atlassian's changelog, the v1 endpoint will start exposing the v2 tools on 1 March 2027 anyway, and the v2 preview URL used over the summer is deprecated.

The server is Cloud only. Jira and Confluence Data Center are not covered. Teams on Data Center typically use the community project mcp-atlassian (run with uvx mcp-atlassian), which supports Server/Data Center but is explicitly not an Atlassian product.

Connecting your client

Claude Code.

claude mcp add --transport http atlassian https://mcp.atlassian.com/v2/mcp

Then run /mcp in a session and finish the Atlassian login in the browser. Add --scope project to share the server with your team through .mcp.json. More on scopes in adding an MCP server to Claude Code.

Claude Desktop. Atlassian's docs point to Settings, Extensions, Browse extensions, Plugins, then search for Atlassian and install. The Claude connectors guide explains how connectors are enabled per conversation and per organization.

Cursor. Install the Atlassian plugin from the Cursor Marketplace ("Add to Cursor"), or add the URL yourself in .cursor/mcp.json:

{
  "mcpServers": {
    "atlassian": { "url": "https://mcp.atlassian.com/v2/mcp" }
  }
}

See adding an MCP server to Cursor for where that file lives.

VS Code with GitHub Copilot. Open the Extensions view, search @mcp Atlassian and install from the MCP gallery.

Others. Atlassian lists ChatGPT, Codex, GitHub Copilot CLI, Google Gemini, Amazon Quick Suite, Windsurf and Docker as supported clients. Any client that speaks remote MCP over HTTP can use the URL above.

The first time someone connects, they go through an OAuth consent screen in the browser. If your company uses an IP allowlist, Atlassian applies it to MCP requests too, so a user outside the allowed range gets a "You don't have permission to connect from this IP address" error.

OAuth or API token

OAuth 2.1API token
Who it is forA person in an interactive clientCI jobs, backend services, scheduled agents
Enabled by defaultYesNo, an org admin must switch it on
HeaderBearer <access_token> from the OAuth flowBasic base64(email:token) or Bearer <service account key>
LimitsSome tools need it (code search, Teams)Needs agent-interface scopes; no domain allowlist check; must pass cloudId explicitly

A token-based config looks like this:

{
  "mcpServers": {
    "atlassian": {
      "url": "https://mcp.atlassian.com/v2/mcp",
      "headers": { "Authorization": "Bearer YOUR_SERVICE_ACCOUNT_KEY" }
    }
  }
}

Prefer a service account with narrow access over a personal token for anything automated. A personal token carries everything that person can see and do.

What the tools cover

v2 uses dynamic tool discovery. Instead of loading hundreds of tool definitions into the model's context at connect time, the client sees a few primary tools (discover, executeRead, executeWrite, executeDestructive, searchJiraIssuesUsingJql, searchConfluence, the Teamwork Graph tools and a beta cross-product search) and pulls in the rest as needed. If you sit behind a gateway that needs the full catalogue up front, Atlassian provides a paginated flat list at https://mcp.atlassian.com/v2/mcp?tools=all.

The tools are grouped by product and by read or write:

  • Jira. Read issues, comments, changelogs, worklogs, transitions, boards, sprints, versions, filters and dashboards. Write: create and edit issues, transition them, comment, log work, link issues, manage sprints and versions, upload attachments.
  • Confluence. Read pages, spaces, comments, versions (including diffs), attachments, tasks and templates. Write: create, update, move, copy and archive pages, comment, label, manage tasks, and change page permissions and public links.
  • Also covered: Jira Service Management Ops alerts (API token only), Bitbucket Cloud repos, pull requests and pipelines, Loom videos and meeting action items, Goals, Projects, Focus Areas, Teams, Capacity Planning and Talent.

Two groups are off by default: delete_jira (delete issues, comments and attachments) and manage_jira (create and update projects, workflows and screens). An admin has to enable them.

What teams actually ask it

The prompts that pay off are the ones that cross Jira and Confluence:

  • "Summarise everything that moved in sprint 42 and flag issues with no update in five days."
  • "Read the spec page for checkout v3 and create a Jira epic with one story per requirement."
  • "Turn these meeting notes into action items in project OPS, assigned to the people named."
  • "Find the Confluence page that explains our release process and check whether open release tickets follow it."
  • In a coding client: "Read PROJ-1287, implement it, then transition it to In Review and comment with the PR link."

JQL is where the agent shines for non-technical users. People who never learned JQL can ask in their own words and the model writes the query for searchJiraIssuesUsingJql.

Writes, permissions and prompt injection

Every call runs as the authenticated user, with that user's existing Jira and Confluence permissions. That is good for access control and risky for blast radius: an agent connected by a Jira admin can do what a Jira admin can do. Atlassian's own admin docs tell admins to monitor audit logs, since MCP clients act with the user's full permissions.

Practical rules:

  1. Keep the destructive groups off unless a specific workflow needs them.
  2. Use your client's approval prompts for writes. Claude Code, Cursor and Claude Desktop can all ask before each tool call; leave that on for executeWrite and executeDestructive.
  3. Treat page and ticket content as untrusted input. A Confluence page or an issue description can contain instructions aimed at the model. Our MCP security guide covers the patterns.
  4. Watch the Confluence permission tools. Tools like enableConfluencePublicLink and addConfluenceContentPermissions can expose content outside the team. They are worth an explicit approval every time.

Admin controls

Org admins manage the server in Atlassian Administration under Rovo, Rovo MCP server:

  • Allowed domains. By default Atlassian-supported client domains (Anthropic, OpenAI and others) are allowed. You can block all of them, but not pick off individual ones, and you can add your own trusted domains.
  • API token authentication toggle.
  • Data Security Policy. Since 29 September 2026 admins can add a Rovo MCP server control to a Data Security Policy to govern which data the server can reach.
  • IP allowlists are set at the organization level and apply to MCP traffic.

Cost

Rovo credits are included in paid Jira, Confluence, Service Collection and Teamwork Collection cloud plans and pooled per organization. Lookups and updates in a single app, including writes such as updating a Jira work item, are free. Enriched Teamwork Graph calls and unified search use credits, mostly 1 to 10 per call. From 3 December 2026 extra usage is billed at 0.01 US dollars per credit, with admin spending limits and alerts at 80 and 100 percent.

Where the data goes

Atlassian's MCP documentation does not describe a data residency commitment for the MCP server itself. Keep the bigger picture in mind: whatever the tools return (ticket text, page content, comments) is sent to the model your client uses, wherever that model runs. Pinning your Jira site to the EU does not change where Claude or GPT processes the results.

That is the gap Walma closes. Walma's AI gateway runs in your own Azure tenant in an EU region and sits between your team's clients, the models and MCP servers like Atlassian's, with one policy for which tools are allowed, which writes need approval, and a log of every call. If you are comparing approaches, the MCP gateway guide lays out the options.

Frequently asked questions

Does Atlassian have an official MCP server for Jira and Confluence?+

Yes. The Atlassian Rovo MCP server is hosted by Atlassian at https://mcp.atlassian.com/v2/mcp. It covers Jira, Confluence, Jira Service Management, Bitbucket, Loom, Goals, Projects and more, and it works with Atlassian Cloud only.

How do I add the Atlassian MCP server to Claude Code?+

Run claude mcp add --transport http atlassian https://mcp.atlassian.com/v2/mcp, then type /mcp inside a Claude Code session and complete the OAuth login with your Atlassian account.

Can the Atlassian MCP server run without a user logging in?+

Yes, if your organization admin enables API token authentication. You then send either a personal API token (Basic auth with email and token) or a service account API key (Bearer). Some tools, such as code search and Teams, still require OAuth 2.1.

Can an AI agent delete Jira issues through the Atlassian MCP server?+

Only if an admin turns it on. The delete_jira and manage_jira tool groups are disabled by default. Ordinary writes, such as creating issues, transitioning them and editing Confluence pages, are available to anyone whose Atlassian permissions allow them.

Does the Atlassian MCP server cost anything?+

Rovo credits are included in paid Jira, Confluence, Service Collection and Teamwork Collection cloud subscriptions. Lookups and writes in a single app are free; enriched Teamwork Graph and unified search calls use roughly 1 to 10 credits each. Extra usage is billed at 0.01 US dollars per credit from 3 December 2026.

Walma AI Hub

The same tools, in your EU region, under your control

A 20-minute walkthrough with an engineer. We map it to your tools, your MCP servers and your budget model.

About AI Hub