Atlassian MCP setup: connecting Claude, ChatGPT or your own agent to Jira safely
MCP, the Model Context Protocol, lets an AI assistant call tools in another system: Claude, ChatGPT or your own agent can search Jira, read Confluence, create issues. Connecting takes minutes. Connecting it so the agent sees only what it should, does only what it is allowed to, and leaves a record of every action is my part.
Key takeaways
- Scope comes first: decide which projects, spaces and actions the agent needs before choosing any server or token.
- The agent should act as an identity with the least access the job needs, never as an admin account borrowed for convenience.
- Every write an agent makes should land in a log someone reads, with enough detail to reverse it.
What the setup covers
- Scoping. Which assistant, which users, which projects and spaces, read or write, and what must never be reachable.
- Authentication and permissions. OAuth or API tokens tied to a dedicated identity, with Jira and Confluence permissions set for that identity alone.
- Least privilege. Write tools switched off unless a use case needs them; restricted projects and spaces kept out of reach.
- Testing. Prompts that try to reach what the agent should not, run before anyone relies on it.
- An audit trail of agent actions. What the agent read and changed, on whose request, kept where your team can review it.
Where do-it-yourself stops
Following a vendor guide gets a server running. It does not tell you that the token you used inherits every project its owner can see, that an agent with create-issue rights will happily file fifty duplicates from one ambiguous prompt, or that nothing records which change came from a human and which from a model. Those are configuration questions about your Jira, and they are where I spend the time.
When an MCP connection is the wrong call
If the goal is answering questions inside issues, Atlassian’s own AI may already do it with no integration at all; the Rovo guide maps where its limits are. And if your permissions are already a mess, connect nothing yet: the Jira readiness assessment fixes the ground before an agent stands on it.
From a connection to a deployment
A working, scoped MCP connection is often the first step of a larger build: an agent that triages JSM requests, drafts answers from Confluence, or keeps configuration in line. When that is the plan, the setup becomes the first week of an FDE deployment instead of a separate project.
This is often part of an FDE engagement. Before an agent can route tickets or answer from your knowledge base, the configuration underneath has to be right. The AI Readiness Audit finds out what needs fixing first, in two weeks, for a fixed $3,500.
Questions
Which assistants can you connect?
How long does it take?
What does it cost?
Tell me which assistant you want connected and what it should be able to do; I will come back with a scope and a fixed price.
Fixed scope
Fixed scope, fixed price