MCP Read and Write Tools
The Atlassian Rovo MCP server's tool interface, through which connected external AI clients can search and read Atlassian data and create or modify Atlassian content, subject to the connecting user's Atlassian permissions and organization-level MCP Read, Write and Search permissions.
Recorded characteristics
- Function
- Atlassian documents the Rovo MCP server as allowing tools such as AI assistants and developer environments to securely access and interact with Atlassian data, bringing Jira work items, Confluence pages and Teamwork Graph context into external AI tools and chat interfaces. Atlassian states that this enables AI tools to perform actions such as searching for work items, summarising pages, or bulk-creating new content via natural language commands. Atlassian's getting-started documentation additionally describes summarising and searching Jira, Jira Service Management, Confluence, Bitbucket, Projects and Goals, retrieving Loom recordings, and creating and updating work items or pages using natural language, with examples including moving a work item to another status and adding a comment. Connection is made to a hosted MCP server endpoint from MCP-compatible clients.
- Data access
- Atlassian documentation establishes interaction with data in Jira, Confluence and Compass (domain and permission controls are described in those terms), and describes bringing Jira work items, Confluence pages and Teamwork Graph context into connected tools. The getting-started page additionally lists Jira Service Management, Bitbucket, Projects, Goals and Loom recordings as reachable through the v2 server. Atlassian states that MCP clients act with the connecting user's existing permissions, so accessible data is bounded by that user's access rather than by tenant-wide access. Organisation-level MCP Read and Search permissions further determine whether the server may view, read or search data across Atlassian apps, and can be configured per app.
- Actions
- Can take actions
- External actions
- Unknown
- Human confirmation
- Not established
- Permission basis
- Mixed
- Administrative control
- Organisation admins configure a dedicated Permissions tab in Atlassian Administration under Rovo > Rovo MCP server, controlling Read (view and read data), Write (create and modify data) and Search (search data across apps), with statuses Allowed, Blocked or Partially allowed, per-app configuration through Edit details, and an option to apply a setting automatically to future additions. Atlassian states these permissions take precedence over Connected Apps or individual Marketplace app permissions, and that changes take effect immediately without restart or reconnection. Separately, admins control which AI tool domains may connect over OAuth 2.1 (Atlassian-supported domains are allowed by default and can be blocked as a whole list; custom trusted domains can be added or deleted), and whether tools may authenticate with an API token. Organisation IP allowlists apply to MCP requests. A data security policy control, Prevent Atlassian Rovo MCP server access, is also documented. Audit logging records every tool invocation with tool name, action and the user who performed it, and Rovo credit usage is visible in Atlassian Administration insights.
- Default state
- Not established
- Availability
- Documented for Atlassian cloud organisations using Jira, Confluence and Compass, accessed through a hosted Atlassian Rovo MCP server endpoint. Atlassian states the server supports any app with MCP support and names examples including OpenAI ChatGPT, Claude, Docker, GitHub Copilot CLI, Google Gemini and Amazon Quick Suite, with client-specific setup instructions. Atlassian documents an MCP v2 server and a documented migration path from v1, stating that existing v1 usage will automatically expose and use v2 tools from 1 March 2027. Availability of individual controls varies: MCP tool invocation logging is documented as available for all tiers, while OAuth-app installation audit visibility is documented as requiring Guard Standard.
- Licensing
- Atlassian documents that calls made through Rovo MCP to retrieve data or generate insights consume Rovo credits from the same shared organisation pool used by Rovo Chat, Studio, Agents and Teamwork Graph, with consumption depending on context volume and reasoning depth and subject to Rovo usage limits. Atlassian does not publish a separate MCP-server licence in the reviewed documentation.
- External model or provider
- Not established / client-dependent. The Rovo MCP server is an interface consumed by external AI clients; the language model used depends on the connecting client. Atlassian names example clients but does not identify a model or model provider for this capability.
- Limitations and uncertainty
- Atlassian's documentation does not establish a server-enforced per-action confirmation gate before write operations; its guidance to review high-impact changes before confirming is advisory, and any confirmation prompt shown is a behaviour of the external MCP client rather than of Atlassian's server. OAuth consent occurs at connection time, not per action. The runtime language model and any client-side safeguards are client-dependent and outside Atlassian's documented control. Authentication modes differ materially: OAuth 2.1 connections are scoped to the user's existing Atlassian permissions and are subject to domain allowlists, while API-token connections do not use domain allowlists, are governed by IP allowlists and the scopes granted to the token or key, may run under a service or technical account, and may not produce per-end-user audit entries. Some AI tools use their own outbound IP addresses, so IP allowlists may block calls unless the tool's ranges are added. Whether the MCP server can act on systems outside Atlassian applications is not established by the reviewed documentation. Product coverage differs between the security documentation (Jira, Confluence, Compass) and the getting-started page (which also lists Jira Service Management, Bitbucket, Projects, Goals and Loom), and the tool set is changing between v1 and v2.
Evidence
- Understand Atlassian Rovo MCP server
Supports: Function · Data access · Actions · External actions · Human confirmation · Permission basis · Default state · Limitations · Primary source
Atlassian states the Rovo MCP server allows tools such as AI assistants and developer environments to securely access and interact with Atlassian data, enabling actions such as searching work items, summarising pages or bulk-creating content.
Atlassian states the server brings Jira work items, Confluence pages and Teamwork Graph context into connected AI tools, across Jira, Confluence and Compass.
Atlassian states AI tools can perform actions such as bulk-creating new content via natural language commands.
Documented actions are described within Jira, Confluence and Compass; the documentation does not establish whether the server can act on systems outside Atlassian applications.
Atlassian advises users to review high-impact changes before confirming, but documents no server-enforced confirmation step before individual write operations; OAuth consent occurs at connection time.
OAuth 2.1 access is scoped to the user's existing permissions in Atlassian, and tool calls proceed subject to normal Atlassian app permissions.
Atlassian documents default domain allowance and OAuth 2.1 as the default authentication method, but does not state an operational default for the MCP tool capability itself.
Tool calls must satisfy domain settings for OAuth tools, organisation IP allowlists, and an allowed authentication method; some AI tools use their own outbound IP addresses which may be blocked.
- Get started with the Atlassian Rovo MCP server
Supports: Function · Data access · Actions · Availability · Licensing · External model · Primary source
Atlassian describes summarising and searching Jira, Jira Service Management, Confluence, Bitbucket, Projects and Goals, and creating and updating work items or pages using natural language.
Getting-started documentation lists additional reachable content including Bitbucket, Projects, Goals and Loom recordings.
Examples include creating and updating work items or pages, moving a work item to another status and adding a comment.
Atlassian states the server supports any MCP-capable app, names example clients, publishes the v2 server endpoint, and documents automatic v2 tool exposure for v1 usage from 1 March 2027.
Calls made through Rovo MCP consume Rovo credits from the shared organisation pool, based on context volume and reasoning depth, subject to Rovo usage limits.
The server is consumed by external AI clients such as ChatGPT, Claude, Gemini and Copilot CLI; Atlassian does not identify a model or provider for this capability.
- Configure Atlassian Rovo MCP server permission
Supports: Data access · Actions · Permission basis · Admin controls · Primary source
Read and Search permissions control whether the MCP server can view, read and search data across Atlassian apps, configurable per app.
The Write permission controls whether the server can create and modify data in Atlassian apps, and can be used to prevent the MCP server from creating or editing content.
Organisation-level MCP Read, Write and Search permissions are separately evaluated at tool-call time; a blocked permission returns an access-denied error to the AI client and changes take effect immediately.
Permissions tab in Atlassian Administration controls Read, Write and Search with Allowed, Blocked or Partially allowed statuses, per-app editing, and precedence over Connected Apps and Marketplace app permissions.
- Control Atlassian Rovo MCP server settings
Supports: Permission basis · Admin controls · Primary source
API-token connections are not governed by domain allowlists and are instead governed by IP allowlists and the scopes granted to their tokens or keys.
Admins can block Atlassian-supported domains, add or delete trusted domains, and enable or disable API-token authentication; IP allowlists apply independently.
- Available Atlassian Rovo MCP server domains
Supports: Admin controls · Primary source
Atlassian-supported domains are allowed by default as a single list and custom authorized domains can be added.
- Monitor Atlassian Rovo MCP server activity
Supports: Admin controls · Limitations · Primary source
Every tool invocation through the server is recorded in the organisation audit log with tool name, action and user; API-token use may attribute actions to a service account.
API-token authentication may run tool calls under a service or technical account, so per-end-user audit entries may not appear.