Atlassian · Atlassian Rovo MCP Server

MCP Read and Write Tools

The Atlassian Rovo MCP server's tool interface, through which connected external AI clients can search and read Atlassian data and create or modify Atlassian content, subject to the connecting user's Atlassian permissions and organization-level MCP Read, Write and Search permissions.

Recorded characteristics

Function
Atlassian documents the Rovo MCP server as allowing tools such as AI assistants and developer environments to securely access and interact with Atlassian data, bringing Jira work items, Confluence pages and Teamwork Graph context into external AI tools and chat interfaces. Atlassian states that this enables AI tools to perform actions such as searching for work items, summarising pages, or bulk-creating new content via natural language commands. Atlassian's getting-started documentation additionally describes summarising and searching Jira, Jira Service Management, Confluence, Bitbucket, Projects and Goals, retrieving Loom recordings, and creating and updating work items or pages using natural language, with examples including moving a work item to another status and adding a comment. Connection is made to a hosted MCP server endpoint from MCP-compatible clients.
Data access
Atlassian documentation establishes interaction with data in Jira, Confluence and Compass (domain and permission controls are described in those terms), and describes bringing Jira work items, Confluence pages and Teamwork Graph context into connected tools. The getting-started page additionally lists Jira Service Management, Bitbucket, Projects, Goals and Loom recordings as reachable through the v2 server. Atlassian states that MCP clients act with the connecting user's existing permissions, so accessible data is bounded by that user's access rather than by tenant-wide access. Organisation-level MCP Read and Search permissions further determine whether the server may view, read or search data across Atlassian apps, and can be configured per app.
Actions
Can take actions
External actions
Unknown
Human confirmation
Not established
Permission basis
Mixed
Administrative control
Organisation admins configure a dedicated Permissions tab in Atlassian Administration under Rovo > Rovo MCP server, controlling Read (view and read data), Write (create and modify data) and Search (search data across apps), with statuses Allowed, Blocked or Partially allowed, per-app configuration through Edit details, and an option to apply a setting automatically to future additions. Atlassian states these permissions take precedence over Connected Apps or individual Marketplace app permissions, and that changes take effect immediately without restart or reconnection. Separately, admins control which AI tool domains may connect over OAuth 2.1 (Atlassian-supported domains are allowed by default and can be blocked as a whole list; custom trusted domains can be added or deleted), and whether tools may authenticate with an API token. Organisation IP allowlists apply to MCP requests. A data security policy control, Prevent Atlassian Rovo MCP server access, is also documented. Audit logging records every tool invocation with tool name, action and the user who performed it, and Rovo credit usage is visible in Atlassian Administration insights.
Default state
Not established
Availability
Documented for Atlassian cloud organisations using Jira, Confluence and Compass, accessed through a hosted Atlassian Rovo MCP server endpoint. Atlassian states the server supports any app with MCP support and names examples including OpenAI ChatGPT, Claude, Docker, GitHub Copilot CLI, Google Gemini and Amazon Quick Suite, with client-specific setup instructions. Atlassian documents an MCP v2 server and a documented migration path from v1, stating that existing v1 usage will automatically expose and use v2 tools from 1 March 2027. Availability of individual controls varies: MCP tool invocation logging is documented as available for all tiers, while OAuth-app installation audit visibility is documented as requiring Guard Standard.
Licensing
Atlassian documents that calls made through Rovo MCP to retrieve data or generate insights consume Rovo credits from the same shared organisation pool used by Rovo Chat, Studio, Agents and Teamwork Graph, with consumption depending on context volume and reasoning depth and subject to Rovo usage limits. Atlassian does not publish a separate MCP-server licence in the reviewed documentation.
External model or provider
Not established / client-dependent. The Rovo MCP server is an interface consumed by external AI clients; the language model used depends on the connecting client. Atlassian names example clients but does not identify a model or model provider for this capability.
Limitations and uncertainty
Atlassian's documentation does not establish a server-enforced per-action confirmation gate before write operations; its guidance to review high-impact changes before confirming is advisory, and any confirmation prompt shown is a behaviour of the external MCP client rather than of Atlassian's server. OAuth consent occurs at connection time, not per action. The runtime language model and any client-side safeguards are client-dependent and outside Atlassian's documented control. Authentication modes differ materially: OAuth 2.1 connections are scoped to the user's existing Atlassian permissions and are subject to domain allowlists, while API-token connections do not use domain allowlists, are governed by IP allowlists and the scopes granted to the token or key, may run under a service or technical account, and may not produce per-end-user audit entries. Some AI tools use their own outbound IP addresses, so IP allowlists may block calls unless the tool's ranges are added. Whether the MCP server can act on systems outside Atlassian applications is not established by the reviewed documentation. Product coverage differs between the security documentation (Jira, Confluence, Compass) and the getting-started page (which also lists Jira Service Management, Bitbucket, Projects, Goals and Loom), and the tool set is changing between v1 and v2.

Evidence