-
-
Notifications
You must be signed in to change notification settings - Fork 10
Expand file tree
/
Copy pathatlassian-rovo-mcp.json
More file actions
114 lines (114 loc) · 10.8 KB
/
Copy pathatlassian-rovo-mcp.json
File metadata and controls
114 lines (114 loc) · 10.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
{
"id": "atlassian-rovo-mcp",
"name": "Atlassian Rovo MCP",
"summary": "Atlassian\u0027s official hosted MCP server (Rovo MCP v2). One authorization can reach Jira, Confluence, Jira Service Management, Bitbucket Cloud, Loom, Goals, Projects, Teams, Focus, Talent, Teamwork Graph, Rovo search, and connected source-code search, each as its own admin-managed permission group.",
"source_url": "https://support.atlassian.com/atlassian-ai-gateway/",
"kind": "mcp_server",
"supported_agents": [
"claude_code",
"codex",
"gemini_cli",
"cursor",
"generic"
],
"installation": {
"automatic": false,
"scope": "project_or_user",
"prerequisites": [
"An Atlassian Cloud account on the site to be authorized",
"An MCP client supporting remote Streamable HTTP and browser OAuth, pointed at https://mcp.atlassian.com/v2/mcp",
"An authorized Atlassian site",
"For Bitbucket tools, a Bitbucket workspace linked to an Atlassian organization",
"For API-token authentication, an organization admin who has enabled it"
]
},
"data_boundary": {
"credentials": [
"OAuth 2.1 authorization managed by the MCP client, consented for a specific Atlassian site (cloudId) and product set, with redirect-domain allowlist checks",
"When enabled by an organization admin, API-token authentication: a personal API token (Basic auth, email:token) or a service-account API key (Bearer); such tokens are not bound to a cloudId, so cross-site calls are possible, and no redirect-domain allowlist check applies",
"Jira Service Management tools are available only through API-token authentication"
],
"reads": [
"Sensitive Jira issues, epics, sprints, boards, filters, dashboards, comments, worklogs, change history, user lookups by name or email, and attachment downloads across the authorized site",
"Confluence spaces, content of every type (pages, blog posts, live docs, whiteboards, databases, folders), version history and diffs, comments, attachment downloads, PDF or Word exports, content permissions and public-link status, and CQL search",
"Jira Service Management operations alerts, on-call schedules, and teams; Bitbucket Cloud workspaces, repositories, file and directory contents, branches, commits, pull requests and diffs, pipelines and step logs, deployments, and environments",
"Loom videos with transcripts, comments, AI meeting action items, and signed MP4 download URLs; Goals, Projects, Teams, Focus areas, and Talent data (positions, managers, headcount by country, level, or job family, and skill assignments)",
"Teamwork Graph context across all of the above plus third-party data connected to Jira (GitHub, Azure DevOps, GitLab, Jenkins, and Spinnaker pull requests, builds, and deployments); Rovo semantic search across Jira, Confluence, and connected apps; source-code search and full file reads across connected source-control providers"
],
"writes": [
"Jira: create, edit, transition, link, watch, and comment on work items, log time, upload attachments, set entity properties, and manage sprints, versions (including release and archive), and boards; with the admin-enabled manage_jira group, create and update projects",
"Confluence: create pages, blog posts, live docs, whiteboards, databases, embeds, smart links, and folders through a single content tool; full-body or granular updates; copy, move, archive, restore versions, convert modes, and set content status; comments, attachments, labels, spaces, and space instructions",
"Confluence access control: add, remove, or replace content permission grants (replace removes any grant absent from the request), set restriction state, and enable or disable the anonymous public link for a page",
"Bitbucket Cloud: create, update, comment on, approve, request changes on, and merge pull requests; create branches and commits; run pipelines",
"Jira Service Management: acknowledge, close, or escalate operations alerts; Loom: upload and publish videos, rename, set visibility to OWNER, WORKSPACE, or PUBLIC, share, comment, and move; Goals, Projects, Focus areas, and Teams: create and update; Talent: create skills, assign or decline worker skills, and allocate positions to focus areas; Teamwork Graph: add relationships between objects",
"Permanent deletion through the admin-enabled delete_jira group: Jira issues, comments, and issue attachments"
]
},
"capabilities": {
"read": true,
"sensitive_read": true,
"write": true,
"remote_write": true,
"publish": true,
"overwrite": true,
"delete": true,
"arbitrary_execution": false,
"oauth": true,
"destructive": true,
"details": [
"Recommended narrow profile, not the declared boundary: enable only the Jira and Confluence read and search groups, and widen deliberately",
"Recommended: exclude Teamwork Graph and Rovo search; both widen visibility to organization-wide and third-party connected data, and each call may consume up to 10 Rovo credits",
"Organization admins grant or revoke access per permission group; delete_jira and manage_jira are disabled by default and must be enabled by an admin",
"Three tools delete permanently and cannot be undone: deleteJiraIssue, deleteJiraComment, and deleteJiraIssueAttachment",
"Confluence writes are content-level tools, so one write tool reaches blog posts, whiteboards, databases, and folders as well as pages; enableConfluencePublicLink and updateLoomVideoPermissions can make content anonymously or publicly reachable",
"Bitbucket writes include merging pull requests and running pipelines; a commit that changes pipeline configuration followed by a pipeline run executes code on Bitbucket runners under the user\u0027s permissions",
"The server exposes a small primary tool set and defers the rest behind discover plus executeRead, executeWrite, and executeDestructive, so new tools become reachable without reconnecting; the ?tools=all endpoint variant exposes the full flat list",
"Creating, updating, publishing, or deleting anything requires explicit outbound confirmation"
]
},
"confirmation": {
"required_for": [
"credential_setup",
"external_install",
"read_sensitive",
"write",
"write_remote",
"publish",
"overwrite",
"delete",
"oauth",
"destructive"
],
"notes": "Confirm the target Atlassian site, permission groups, and project or space before reading sensitive organizational state; show proposed Jira, Confluence, or Bitbucket changes before execution; gate the three delete tools, public-link and permission changes, pull-request merges, and pipeline runs separately from other writes; and keep Teamwork Graph and Rovo search disabled by default."
},
"risk_tags": [
"credentials",
"hosted",
"project-management",
"private-repositories",
"sensitive-read",
"remote-write",
"publish-capable",
"public-publish",
"overwrite-capable",
"delete-capable",
"oauth",
"destructive-capable",
"ci-cd",
"dynamic-api-surface",
"prompt-injection"
],
"maturity": "verified",
"last_verified": "2026-09-03",
"evidence": [
"https://support.atlassian.com/atlassian-ai-gateway/docs/supported-tools/",
"https://support.atlassian.com/atlassian-ai-gateway/docs/get-started-with-the-atlassian-remote-mcp-server/",
"https://support.atlassian.com/atlassian-ai-gateway/docs/configure-authentication-via-api-token/",
"https://support.atlassian.com/atlassian-ai-gateway/docs/configure-oauth-2-1/"
],
"health_check": "Connect to the Rovo MCP endpoint, verify authorized Atlassian site identity and the granted permission groups, then run a bounded read query for one known issue or page without creating or modifying content.",
"uninstall": {
"instructions": "Remove the Atlassian Rovo MCP entry from the client and revoke the authorized application connection in Atlassian account settings, or revoke the API token or service-account key; preserve all Jira, Confluence, Jira Service Management, Bitbucket, and Loom data.",
"removes_user_data": false
}
}