Atlassian MCP setup: connecting Claude, ChatGPT or your own agent to Jira safely

MCP, the Model Context Protocol, lets an AI assistant call tools in another system: Claude, ChatGPT or your own agent can search Jira, read Confluence, create issues. Connecting takes minutes. Connecting it so the agent sees only what it should, does only what it is allowed to, and leaves a record of every action is my part.

Key takeaways

  • Scope comes first: decide which projects, spaces and actions the agent needs before choosing any server or token.
  • The agent should act as an identity with the least access the job needs, never as an admin account borrowed for convenience.
  • Every write an agent makes should land in a log someone reads, with enough detail to reverse it.

What the setup covers

  1. Scoping. Which assistant, which users, which projects and spaces, read or write, and what must never be reachable.
  2. Authentication and permissions. OAuth or API tokens tied to a dedicated identity, with Jira and Confluence permissions set for that identity alone.
  3. Least privilege. Write tools switched off unless a use case needs them; restricted projects and spaces kept out of reach.
  4. Testing. Prompts that try to reach what the agent should not, run before anyone relies on it.
  5. An audit trail of agent actions. What the agent read and changed, on whose request, kept where your team can review it.

Where do-it-yourself stops

Following a vendor guide gets a server running. It does not tell you that the token you used inherits every project its owner can see, that an agent with create-issue rights will happily file fifty duplicates from one ambiguous prompt, or that nothing records which change came from a human and which from a model. Those are configuration questions about your Jira, and they are where I spend the time.

When an MCP connection is the wrong call

If the goal is answering questions inside issues, Atlassian’s own AI may already do it with no integration at all; the Rovo guide maps where its limits are. And if your permissions are already a mess, connect nothing yet: the Jira readiness assessment fixes the ground before an agent stands on it.

From a connection to a deployment

A working, scoped MCP connection is often the first step of a larger build: an agent that triages JSM requests, drafts answers from Confluence, or keeps configuration in line. When that is the plan, the setup becomes the first week of an FDE deployment instead of a separate project.

This is often part of an FDE engagement. Before an agent can route tickets or answer from your knowledge base, the configuration underneath has to be right. The AI Readiness Audit finds out what needs fixing first, in two weeks, for a fixed $3,500.

Questions

Which assistants can you connect?
Claude, ChatGPT and internal agents built on any model, as long as they speak MCP. The Jira and Confluence side is the same work in every case.
How long does it take?
Usually days rather than weeks: most of the time goes into scoping and testing, not the connection itself.
What does it cost?
A fixed price, quoted after a short call once the scope is clear. If it becomes part of a deployment, it is included in that price.

Tell me which assistant you want connected and what it should be able to do; I will come back with a scope and a fixed price.

Fixed scope

Fixed scope, fixed price

Book a call

About the author

Ben Friedman runs Viter, a forward-deployed AI engineering service. He has spent over ten years running Atlassian and operations tooling, including as internal Jira lead at Aroundtown, and holds the ACP-610, ACP-620 and ACP-120 certifications. He builds JAMES, the AI Jira administrator.