Prevent Atlassian MCP server access
The Atlassian MCP server control lets you choose whether AI agents and assistants can read your organization's Jira and Confluence data through the Atlassian Model Context Protocol (MCP). Use this control in a data security policy to allow or block AI access to content your organization wants to protect.
Data security policies are enforced only for OAuth authentication methods, not API token authentication methods.
Who can do this? |
The Atlassian MCP server lets AI agents read Jira work items and Confluence pages on a user's behalf. This control lets you allow or block that access at an organization, site, content object, or classification level.
The control works alongside your existing user permissions, not instead of them. Blocking MCP access doesn't change what users can do directly in Jira or Confluence. It only prevents covered content from being read through the Atlassian MCP server.
Changing this control can affect AI agents and workflows that rely on reading content through MCP. Agents that expect certain content to be available may no longer return complete results.
How do I use this control?
You can choose to prevent or allow anonymous access for your organization. You can also customize your control with overrides if you wish to be more specific. Apply a default configuration to a policy control
Once activated, the control takes effect within a short time as the policy propagates.
What will my users experience?
The information on this page describes what your users will experience when you apply a control to your organization. If you add overrides, make sure you test the results to maintain the level of security you require. Configure an override for a control
When the Atlassian MCP server access control is set to Blocked:
In Jira:
AI agents can't read Jira work items covered by this control through MCP.
Covered work items aren't returned in searches, including JQL searches run by an AI agent through MCP.
If an agent requests a specific covered work item, it isn't returned. The agent receives a "does not exist or you don't have permission" response.
The block applies even when the underlying user has permission to view the work item directly in Jira.
In Confluence:
AI agents can't read Confluence pages, spaces, or classified content covered by this control through MCP.
Even when blocked, MCP servers may still be able to:
get and list global templates in Confluence
create a space
get the current user's personal space
list Confluence spaces
watch or stop watching Confluence labels
When the Atlassian MCP server access control is set to Allowed:
The user's existing permissions control what the AI agent can access. Agents can read the same Jira and Confluence content that the user can access, subject to their permissions.
What this control doesn't affect
Users viewing or working with content directly in Jira or Confluence.
Access through custom MCP servers. This control covers the Atlassian MCP server only.
REST APIs used by Atlassian app features.
Other data security policy controls, such as data export, attachment download, public links, and Marketplace and custom app access. Those controls are governed separately.
Existing user permissions. Blocking MCP access doesn't remove or change what users can do in Jira or Confluence.
Was this helpful?