Jira and Confluence MCP in Codex CLI and Gemini CLI

Set up the Atlassian Rovo MCP Server in Codex CLI and Gemini CLI: the config.toml and settings.json entries, the browser sign-in, API tokens for machines without one, approval settings, and a short section on Copilot CLI.

7 min read

To use Jira and Confluence from Codex CLI, run codex mcp add atlassian --url https://mcp.atlassian.com/v2/mcp and then codex mcp login atlassian, which opens Atlassian’s consent screen in your browser. In Gemini CLI, add the same address under mcpServers in settings.json with the httpUrl key, start Gemini and run /mcp auth atlassian. Both then reach Jira, Confluence and the other Atlassian Cloud apps your account can see, with your own permissions. For a machine with no browser, Atlassian also accepts an API token in a header, but only if an organisation admin has switched that on. The rest of this guide gives each file, validated, and the approval settings that keep writes on ask.

What the server’s tools can do is covered in what the Jira MCP server can do, the Claude Code setup in Jira MCP with Claude Code, and Confluence specifically in Confluence MCP. This post is only about the two CLIs, plus Copilot CLI at the end.

The server in four facts

  • One address: https://mcp.atlassian.com/v2/mcp. Atlassian’s getting-started guide gives it for every client, and ?tools=all on the end for gateways that need the full tool list up front.
  • OAuth 2.1 by default. Actions respect your existing Atlassian permissions, and the server works with Atlassian Cloud sites only.
  • API tokens as an alternative, for non-interactive use, if your organisation admin has enabled them.
  • Older addresses are going. Atlassian’s repository notes that the /v1/sse endpoint stopped being supported after 30 June 2026 and that new setups should use /v2/mcp. If a guide or a dotfile still says /v1/sse or wraps the server in mcp-remote, replace it.

Sign-in from a terminal works because the CLIs receive the OAuth redirect on your own machine. Atlassian’s list of supported domains (opens in a new tab) includes localhost and 127.0.0.1 by default. An admin can remove them to restrict access, and then a CLI sign-in fails at the consent step; the fix is on the Atlassian Administration side, not in your config.

Codex CLI

Atlassian’s own repository (opens in a new tab) gives the Codex command. Run it once, then sign in:

Terminal
codex mcp add atlassian --url https://mcp.atlassian.com/v2/mcp
codex mcp login atlassian
codex mcp list

The command writes a table to ~/.codex/config.toml, which the Codex CLI, its IDE extension and the ChatGPT desktop app share. A project can have its own .codex/config.toml, read only when you trust the project. Written by hand, with approvals, it looks like this:

~/.codex/config.toml
[mcp_servers.atlassian]
url = "https://mcp.atlassian.com/v2/mcp"
default_tools_approval_mode = "prompt"
startup_timeout_sec = 20
tool_timeout_sec = 90

OpenAI’s Codex MCP reference (opens in a new tab) lists the approval values as auto, prompt, writes and approve, with per-tool overrides under tools.<tool>.approval_mode. prompt asks before every call. writes asks only for tools the server does not mark as read-only. Atlassian’s server lists a set of primary tools directly, such as getJiraIssue, searchJiraIssuesUsingJql and createJiraIssue, and reaches the rest through discover and then executeRead, executeWrite or executeDestructive, so decide per tool rather than per server. enabled_tools and disabled_tools go further and hide tools from the model; leaving executeDestructive out of the model’s reach is a reasonable default for a coding agent. Check the tool names /mcp shows before you write either list.

Codex without a browser

Atlassian’s token options are a personal API token sent as Basic with your email and token base64-encoded, or a service account API key sent as Bearer. Codex reads either from the environment, so nothing secret goes in the file. bearer_token_env_var names a variable holding a bearer token; env_http_headers maps a header to a variable holding its whole value:

~/.codex/config.toml (token, no browser)
# Service account key: sent as "Authorization: Bearer <key>"
[mcp_servers.atlassian]
url = "https://mcp.atlassian.com/v2/mcp"
bearer_token_env_var = "ATLASSIAN_MCP_KEY"

# Or a personal API token: set ATLASSIAN_MCP_AUTH to "Basic <base64 of email:token>"
# [mcp_servers.atlassian]
# url = "https://mcp.atlassian.com/v2/mcp"
# env_http_headers = { "Authorization" = "ATLASSIAN_MCP_AUTH" }

Atlassian lists the trade-offs (opens in a new tab): code search and Teams tools need OAuth, a token is not tied to one site so the agent must pass the site ID where a tool asks for it, and token connections are governed by your IP allowlist rather than the domain rules. Give the token only the agent-interface scopes the job needs.

Gemini CLI

Gemini CLI reads servers from mcpServers in ~/.gemini/settings.json for you or .gemini/settings.json in a project. Gemini CLI’s MCP guide (opens in a new tab) is specific about the keys: httpUrl is for a streamable HTTP server and url is for an SSE one. Atlassian’s server is streamable HTTP, so:

~/.gemini/settings.json
{
  "mcpServers": {
    "atlassian": {
      "httpUrl": "https://mcp.atlassian.com/v2/mcp",
      "timeout": 60000,
      "trust": false
    }
  }
}

Or let the CLI write it: gemini mcp add --scope user --transport http atlassian https://mcp.atlassian.com/v2/mcp. Without --scope user it goes into the project file, which is the default. Start Gemini and run /mcp auth atlassian; the CLI discovers Atlassian’s OAuth endpoints, registers itself and opens your browser, then stores the token in ~/.gemini/mcp-oauth-tokens.json and refreshes it. /mcp list shows the status.

  • Keep trust false. When it is true, Gemini skips every confirmation for that server. When a call does ask, choose “Always allow this tool” only for reads; “Always allow this server” is the same as trust.
  • includeTools and excludeTools narrow what the model sees, and excludeTools wins when a tool is in both.
  • Gemini’s sign-in needs a browser on the same machine and a redirect to localhost. It will not work in a bare SSH session or a container.
  • Gemini checks the iss parameter on the redirect, per RFC 9207. A sign-in that ends in “Missing issuer parameter in response” is that check, not a typo in your file.
  • Atlassian’s repository also ships a Gemini extension manifest. It declares the server with url, which Gemini’s guide describes as the SSE key; if the extension will not connect, the hand-written httpUrl entry above is the documented one.

Gemini without a browser

Pass the token as a header: gemini mcp add --scope user --transport http --header "Authorization: Bearer <key>" atlassian https://mcp.atlassian.com/v2/mcp, or Basic with the base64 value for a personal token. Gemini’s guide describes variable expansion for a server’s env block, not for headers, so the value lands in the file as written. Keep it in your user settings, never in a project file you commit.

One change affects who can run Gemini CLI at all. Gemini CLI’s authentication page (opens in a new tab) says that for unpaid-tier and Google One users, Gemini CLI was replaced by Antigravity CLI on 18 June 2026. Organisation accounts, Gemini API keys and Vertex AI still sign in. Which one fits is covered in Gemini CLI best practices.

Copilot CLI, briefly

Copilot CLI takes the same server in one line: copilot mcp add --transport http atlassian https://mcp.atlassian.com/v2/mcp. It writes ~/.copilot/mcp-config.json, opens the browser for OAuth on first use, and /mcp auth atlassian repeats the sign-in when it expires. For a token, add --header "Authorization: Bearer <key>". Every MCP call asks for approval until you allow it with --allow-tool. The details, including the config file and fixes, are in adding MCP servers to Copilot CLI.

A first session

  • “Which Atlassian sites can you see, and who am I signed in as?” Two always-available tools answer this, and it tells you which site the rest of the session uses.
  • “List the open bugs assigned to me in project PAY, and show the JQL you used.”
  • “Find the Confluence page for the payments runbook and summarise the rollback steps.”
  • “Comment on PAY-142 with the commit hash and what this branch changed.” A write: approve it and check it in Jira.

Some calls, such as Rovo search and Teamwork Graph, consume Rovo credits. Atlassian’s own guidance for any client applies here too: least privilege, review high-impact changes before confirming, and watch the audit log.

A board beside Jira, or instead of it

Through this server a terminal agent holds all of your Jira and Confluence rights on every site you approve. fenbs connects to the same three CLIs with https://fenbs.ai/api/mcp: codex mcp add fenbs --url https://fenbs.ai/api/mcp, an httpUrl entry in Gemini’s settings.json, or copilot mcp add. The assistant holds your role on one board, narrowed by the scopes you tick, and every change is recorded under its name. For CI, a token issued by hand under Settings carries a name, scopes and an optional expiry, and FENBS_TOKEN=… npx -y fenbs-mcp bridges it for stdio-only clients. fenbs has no sprints, epics, due dates or Jira importer, and sets no tool annotations yet, so a writes approval mode asks for every fenbs call. See Codex CLI, Gemini CLI and fenbs vs Jira.

Related

What the tools do: what the Jira MCP server can do. Confluence pages and spaces: Confluence MCP. Every Codex command: Codex CLI commands. The consent screen: how MCP sign-in works.

Questions people ask.

How do I add the Atlassian MCP server to Codex CLI?

Run codex mcp add atlassian with the url option set to https://mcp.atlassian.com/v2/mcp, then codex mcp login atlassian and approve on Atlassian’s consent screen. The entry is saved in ~/.codex/config.toml.

Which key does Gemini CLI use for the Atlassian server?

httpUrl, because the Rovo MCP Server is a streamable HTTP server. Gemini CLI uses url for SSE servers. Put the entry under mcpServers in ~/.gemini/settings.json and sign in with /mcp auth atlassian.

Can Codex or Gemini CLI use an Atlassian API token?

Yes, if your organisation admin has enabled API token authentication. Send a personal token as Basic with your email and token base64-encoded, or a service account key as Bearer. Some tools, such as code search and Teams, still need OAuth.

Does the old /v1/sse address still work?

No. Atlassian says the /v1/sse endpoint is no longer supported after 30 June 2026. Use https://mcp.atlassian.com/v2/mcp for new setups.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.