Developer
News and Updates
Get Support
Sign in
Get Support
Sign in
DOCUMENTATION
Cloud
Data Center
Resources
Sign in
Sign in
DOCUMENTATION
Cloud
Data Center
Resources
Sign in
Last updated Sep 2, 2026

Authentication and authorization

The Atlassian Rovo MCP Server uses OAuth 2.1 as its primary authentication mechanism, providing a secure and standardized way for users to authorize access to resources via an interactive consent flow.

In addition, if enabled by your organization admin, the server supports authentication via API token for machine-to-machine and other non-interactive scenarios - for example, backend services, CI/CD pipelines, bots, and automated agents. Authentication via API token lets MCP clients authenticate without a browser-based OAuth consent screen.

Regardless of the method, every action respects the authenticated user's existing access controls and permissions. Access is granted only to data the user already has permission to view, and OAuth and API token authentication both honor configured scopes and Atlassian permissions.

Supported authentication methods

MethodDescriptionAuth header
OAuth 2.1Interactive full OAuth flow, with token validation and user context enrichment.Authorization: Bearer <access_token>
API tokenNon-interactive machine-to-machine authentication using a personal API token or a service account API key. Requires admin enablement.Authorization: Basic <base64(email:api_token)> or Authorization: Bearer <api_key>

Choosing an authentication method

Use OAuth 2.1 when:

  • An interactive user can complete the consent flow.
  • You need fine-grained, user-level consent and context.
  • You're building an interactive application or integration.

Use authentication via API token when:

  • No user is present - for example, backend services, CI/CD, or automation.
  • You need a non-interactive, machine-to-machine scenario.
  • Your organization can securely manage token storage and rotation.
  • Your organization admin has enabled it.

OAuth 2.1 remains the recommended option for interactive, user-driven scenarios.

Admin controls

If your organization admin has disabled authentication via API token, MCP clients won't be able to connect using a token and will need to use OAuth 2.1 instead. Some tool sets, such as Jira Service Management, are only available via API token authentication, so admin enablement is required to use them. Others, such as code search and Teams tools, are only available via OAuth 2.1.

Some permission groups - including delete_jira and manage_jira - are disabled by default and must be enabled by an admin. See Supported tools for the availability of each group.

Security best practices

MCP clients can perform actions across connected apps with your existing permissions. Use least privilege, review high-impact changes before confirming, and monitor audit logs for unusual activity.

Next steps

Rate this page: