The Atlassian Rovo MCP Server uses OAuth 2.1 as its primary authentication mechanism, providing a secure and standardized way for users to authorize access to resources via an interactive consent flow.
In addition, if enabled by your organization admin, the server supports authentication via API token for machine-to-machine and other non-interactive scenarios - for example, backend services, CI/CD pipelines, bots, and automated agents. Authentication via API token lets MCP clients authenticate without a browser-based OAuth consent screen.
Regardless of the method, every action respects the authenticated user's existing access controls and permissions. Access is granted only to data the user already has permission to view, and OAuth and API token authentication both honor configured scopes and Atlassian permissions.
| Method | Description | Auth header |
|---|---|---|
| OAuth 2.1 | Interactive full OAuth flow, with token validation and user context enrichment. | Authorization: Bearer <access_token> |
| API token | Non-interactive machine-to-machine authentication using a personal API token or a service account API key. Requires admin enablement. | Authorization: Basic <base64(email:api_token)> or Authorization: Bearer <api_key> |
Use OAuth 2.1 when:
Use authentication via API token when:
OAuth 2.1 remains the recommended option for interactive, user-driven scenarios.
If your organization admin has disabled authentication via API token, MCP clients won't be able to connect using a token and will need to use OAuth 2.1 instead. Some tool sets, such as Jira Service Management, are only available via API token authentication, so admin enablement is required to use them. Others, such as code search and Teams tools, are only available via OAuth 2.1.
Some permission groups - including delete_jira and manage_jira - are disabled by default and must be enabled by an admin. See Supported tools for the availability of each group.
MCP clients can perform actions across connected apps with your existing permissions. Use least privilege, review high-impact changes before confirming, and monitor audit logs for unusual activity.
Rate this page: