Developer
News and Updates
Get Support
Sign in
Get Support
Sign in
DOCUMENTATION
Cloud
Data Center
Resources
Sign in
Sign in
DOCUMENTATION
Cloud
Data Center
Resources
Sign in
Last updated Sep 2, 2026

Configuring authentication via API token

If enabled by your organization admin, authentication via API token lets MCP clients send credentials directly in the request header, without an interactive OAuth consent screen. Use this option for non-interactive or machine-to-machine scenarios. See Supported tools for the tools available across Atlassian apps and the scope each permission group requires.

There are two options: a personal API token using Basic auth, or a service account API key using a Bearer token.

Personal API token (Basic auth)

Use this option when you want to authenticate MCP using a personal API token created by a user.

Step 1. Create a personal API token

Create a personal API token with the required scopes, and note the email address of the user who owns the token.

The server uses the agent-interface scopes. Select the scopes for the apps and permission groups you intend to use:

AppScopes
Jiraread:jira:agent-interface, write:jira:agent-interface, search:jira:agent-interface, delete:jira:agent-interface, manage:jira:agent-interface
Confluenceread:confluence:agent-interface, write:confluence:agent-interface, search:confluence:agent-interface
Bitbucket Cloudread:bitbucket:agent-interface, write:bitbucket:agent-interface
Jira Service Managementread:ops-alert:jira-service-management, write:ops-alert:jira-service-management, read:ops-config:jira-service-management, read:jira-user
Loomread:loom:agent-interface, write:loom:agent-interface
Rovo Searchsearch:rovo:agent-interface
Teamwork Graphread:all:twg, write:all:twg
Goalsread:goals:agent-interface, write:goals:agent-interface
Projectsread:projects:agent-interface, write:projects:agent-interface
Focus areasread:focus:agent-interface, write:focus:agent-interface
Talentread:talent:agent-interface, write:talent:agent-interface

To open the token creation screen with these scopes pre-selected, use this link.

Step 2. Base64-encode the credentials

Create a base64-encoded string in the format email:api_token:

1
2
3
# Format: email:api_token
echo -n "your.email@example.com:YOUR_API_TOKEN_HERE" | base64

This produces a base64-encoded string representing email:api_token.

Step 3. Configure your MCP client

Add the following configuration to your MCP client's mcp.json:

1
2
3
4
5
6
7
8
9
10
11
{
  "mcpServers": {
    "atlassian-rovo-mcp": {
      "url": "https://mcp.atlassian.com/v2/mcp",
      "headers": {
        "Authorization": "Basic BASE64_ENCODED_EMAIL_AND_TOKEN"
      }
    }
  }
}

Replace BASE64_ENCODED_EMAIL_AND_TOKEN with the value from Step 2.

Service account API key (Bearer token)

Step 1. Obtain a service account API key

An admin creates a service account and generates an API key with the appropriate scopes. Store the key securely in your CI/CD system or secrets manager.

Step 2. Configure your MCP client

1
2
3
4
5
6
7
8
9
10
11
{
  "mcpServers": {
    "atlassian-rovo-mcp": {
      "url": "https://mcp.atlassian.com/v2/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_API_KEY_HERE"
      }
    }
  }
}

Replace YOUR_API_KEY_HERE with your service account API key.

Verify your setup

You can confirm authentication is working with a quick request. A 200 OK response confirms authentication is working:

1
2
3
4
5
6
7
8
# Test with API token (Basic auth)
curl -I https://mcp.atlassian.com/v2/mcp \
  -H "Authorization: Basic <your_base64_encoded_credentials>"

# Test with service account (Bearer auth)
curl -I https://mcp.atlassian.com/v2/mcp \
  -H "Authorization: Bearer <your_api_key>"

Limitations

  • Admin enablement required. Authentication via API token must be enabled by your organization admin. If it is disabled, MCP clients must use OAuth 2.1 instead.
  • Limited tool availability. Some tools are unavailable because their required app scopes can't currently be selected when creating a personal API token or an API key. Code search and Teams tools require OAuth 2.1.
  • No bounded cloud ID. Unlike OAuth access tokens, API tokens aren't bound to a specific cloud ID, so clients must explicitly pass cloudId where a tool requires it.
  • No domain allowlist validation. Because there is no redirect URI, tools using API tokens aren't restricted by domain allowlists and are governed only by your IP allowlist configuration.
  • OAuth 2.1 remains the recommended option for interactive, user-driven scenarios.

Troubleshooting

Tool calls fail with a permission or scope error

Your token may be missing a required scope. Recreate the token with the agent-interface scopes that match the permission groups you're calling, then reconfigure your client.

Next steps

Rate this page: