If enabled by your organization admin, authentication via API token lets MCP clients send credentials directly in the request header, without an interactive OAuth consent screen. Use this option for non-interactive or machine-to-machine scenarios. See Supported tools for the tools available across Atlassian apps and the scope each permission group requires.
There are two options: a personal API token using Basic auth, or a service account API key using a Bearer token.
Use this option when you want to authenticate MCP using a personal API token created by a user.
Create a personal API token with the required scopes, and note the email address of the user who owns the token.
The server uses the agent-interface scopes. Select the scopes for the apps and permission groups you intend to use:
| App | Scopes |
|---|---|
| Jira | read:jira:agent-interface, write:jira:agent-interface, search:jira:agent-interface, delete:jira:agent-interface, manage:jira:agent-interface |
| Confluence | read:confluence:agent-interface, write:confluence:agent-interface, search:confluence:agent-interface |
| Bitbucket Cloud | read:bitbucket:agent-interface, write:bitbucket:agent-interface |
| Jira Service Management | read:ops-alert:jira-service-management, write:ops-alert:jira-service-management, read:ops-config:jira-service-management, read:jira-user |
| Loom | read:loom:agent-interface, write:loom:agent-interface |
| Rovo Search | search:rovo:agent-interface |
| Teamwork Graph | read:all:twg, write:all:twg |
| Goals | read:goals:agent-interface, write:goals:agent-interface |
| Projects | read:projects:agent-interface, write:projects:agent-interface |
| Focus areas | read:focus:agent-interface, write:focus:agent-interface |
| Talent | read:talent:agent-interface, write:talent:agent-interface |
To open the token creation screen with these scopes pre-selected, use this link.
Create a base64-encoded string in the format email:api_token:
1 2 3# Format: email:api_token echo -n "your.email@example.com:YOUR_API_TOKEN_HERE" | base64
This produces a base64-encoded string representing email:api_token.
Add the following configuration to your MCP client's mcp.json:
1 2 3 4 5 6 7 8 9 10 11{ "mcpServers": { "atlassian-rovo-mcp": { "url": "https://mcp.atlassian.com/v2/mcp", "headers": { "Authorization": "Basic BASE64_ENCODED_EMAIL_AND_TOKEN" } } } }
Replace BASE64_ENCODED_EMAIL_AND_TOKEN with the value from Step 2.
An admin creates a service account and generates an API key with the appropriate scopes. Store the key securely in your CI/CD system or secrets manager.
1 2 3 4 5 6 7 8 9 10 11{ "mcpServers": { "atlassian-rovo-mcp": { "url": "https://mcp.atlassian.com/v2/mcp", "headers": { "Authorization": "Bearer YOUR_API_KEY_HERE" } } } }
Replace YOUR_API_KEY_HERE with your service account API key.
You can confirm authentication is working with a quick request. A 200 OK response confirms authentication is working:
1 2 3 4 5 6 7 8# Test with API token (Basic auth) curl -I https://mcp.atlassian.com/v2/mcp \ -H "Authorization: Basic <your_base64_encoded_credentials>" # Test with service account (Bearer auth) curl -I https://mcp.atlassian.com/v2/mcp \ -H "Authorization: Bearer <your_api_key>"
cloudId where a tool requires it.Your token may be missing a required scope. Recreate the token with the agent-interface scopes that match the permission groups you're calling, then reconfigure your client.
Rate this page: