Unexpected MCP Apps (GitHub, Sentry, New Relic, Notion) Appearing in Connected Apps

Platform Notice: Cloud Only - This article only applies to Atlassian apps on the cloud platform.

Summary

Administrators may notice new entries such as GitHub MCP (read-only), Sentry MCP (read-only), New Relic MCP (read-only), and Notion MCP (read-only) appearing under Site settings > Connected Apps. These apps appear automatically and are not manually installed by an administrator.

Diagnosis

  • You see apps with the suffix "MCP (read-only)" in your Connected Apps list.

  • There is no record of these apps being installed in the Audit Log.

  • The apps are listed as "read-only" and appear to be system-provisioned.

Cause

These entries are platform-level read-only Model Context Protocol (MCP) servers provisioned by Atlassian as part of the Atlassian Rovo feature set.

They are registered automatically via a "just-in-time" or "lazy loading" process. They surface in the Connected Apps list the first time a user in your organization completes the secure OAuth 2.1 consent flow to connect an external AI client (like Claude, ChatGPT, or VS Code) to your Atlassian Cloud site using the Atlassian Rovo MCP Server.

Because these are system-provisioned integrations rather than manual Marketplace installations, no installation event is recorded in the audit log.

Solution

Administrators have full oversight and control over these connections through Atlassian Administration.

1. Monitor Activity

To see when and which users authorized these connections:

  1. Go to Atlassian Administration > Insights > Audit log.

  2. Filter the log for "Rovo MCP" to view user authorization events.

2. Manage Permissions

You can restrict or disable access to these MCP servers:

  1. Navigate to Atlassian Administration > Rovo > Rovo MCP server > Permissions.

  2. Adjust access by permission type (Read, Write, Search) or by specific product.

  3. You can also disable the MCP server entirely for your organization if required.

    Note: The permissions set in the Rovo MCP server tab take precedence over any settings found directly within the Connected Apps page.

Related Articles

Updated on August 19, 2026

Still need help?

The Atlassian Community is here for you.