Unexpected MCP Apps (GitHub, Sentry, New Relic, Notion) Appearing in Connected Apps
Platform Notice: Cloud Only - This article only applies to Atlassian apps on the cloud platform.
Summary
Administrators may notice new entries such as GitHub MCP (read-only), Sentry MCP (read-only), New Relic MCP (read-only), and Notion MCP (read-only) appearing under Site settings > Connected Apps. These apps appear automatically and are not manually installed by an administrator.
Diagnosis
You see apps with the suffix "MCP (read-only)" in your Connected Apps list.
There is no record of these apps being installed in the Audit Log.
The apps are listed as "read-only" and appear to be system-provisioned.
Cause
These entries are platform-level read-only Model Context Protocol (MCP) servers provisioned by Atlassian as part of the Atlassian Rovo feature set.
They are registered automatically via a "just-in-time" or "lazy loading" process. They surface in the Connected Apps list the first time a user in your organization completes the secure OAuth 2.1 consent flow to connect an external AI client (like Claude, ChatGPT, or VS Code) to your Atlassian Cloud site using the Atlassian Rovo MCP Server.
Because these are system-provisioned integrations rather than manual Marketplace installations, no installation event is recorded in the audit log.
Solution
Administrators have full oversight and control over these connections through Atlassian Administration.
1. Monitor Activity
To see when and which users authorized these connections:
Go to Atlassian Administration > Insights > Audit log.
Filter the log for "Rovo MCP" to view user authorization events.
2. Manage Permissions
You can restrict or disable access to these MCP servers:
Navigate to Atlassian Administration > Rovo > Rovo MCP server > Permissions.
Adjust access by permission type (Read, Write, Search) or by specific product.
You can also disable the MCP server entirely for your organization if required.
Note: The permissions set in the Rovo MCP server tab take precedence over any settings found directly within the Connected Apps page.
Related Articles
Was this helpful?