Jira MCP With Claude Code: Setup, What It Can Do and Its Limits
How to connect Claude Code to Jira through Atlassian’s own remote MCP server: the one command, the browser sign-in, the first prompts worth trying, how permissions work, and the limits to know before you rely on it.
Updated 7 min read
To use Jira from Claude Code, add Atlassian’s hosted MCP server with one command, claude mcp add --transport http atlassian https://mcp.atlassian.com/v2/mcp, then run /mcp inside a Claude Code session and sign in to your Atlassian account in the browser. After that, Claude Code can search Jira with JQL, read work items, create and edit them, move them through your workflow and comment on them, all with your own Jira permissions. It works with Atlassian Cloud sites only. The rest of this guide covers each step, the first prompts worth trying, and the limits.
Atlassian calls it the Atlassian Rovo MCP Server. It is one server for several Atlassian Cloud apps, including Jira, Confluence, Jira Service Management and Bitbucket Cloud, so connecting it for Jira also gives Claude Code the Confluence tools your account can use. If you want the full list of Jira tools and what each permission group allows, that is in the companion piece, what the Jira MCP server can do. If MCP itself is new to you, start with what MCP is.
Before you start
- An Atlassian Cloud site (an address ending in
atlassian.net). Atlassian’s documentation describes the server as a cloud-hosted service for Atlassian Cloud apps; Jira Data Center and Server are not covered. - Claude Code installed and signed in.
- A browser on the same machine, for the OAuth sign-in. If you are on a remote machine over SSH, see the headless section below.
- Your organisation allowing it. Atlassian admins can block the AI tools and domains that may connect, and can apply IP allowlists to MCP requests. If sign-in is refused, ask your Atlassian admin before you troubleshoot anything else.
Step 1: add the server
claude mcp add --transport http atlassian https://mcp.atlassian.com/v2/mcp
This is the command in Atlassian’s own setup instructions (opens in a new tab). atlassian is only the local name; call it jira if you prefer. The server speaks the streamable HTTP transport, which is what --transport http selects. An older endpoint ending in /v1/sse is being retired, so if you find a guide that uses it, use /v2/mcp instead.
By default Claude Code adds the server in local scope: available to you, in the current project only, stored in ~/.claude.json. Two other scopes are worth knowing:
--scope usermakes it available in every project on your machine. Sensible if you use Jira across several repositories.--scope projectwrites it to.mcp.jsonat the project root, for committing. Each teammate still signs in with their own account, and Claude Code asks for approval before using a server it found in that file.
Step 2: sign in
- Start Claude Code in your project and type
/mcp. - Choose the Atlassian server. It will show as needing authentication. Pick the option to authenticate.
- Your browser opens on Atlassian. Sign in as you normally would and review the consent screen: which app is asking, which site, and what it may do. Approve if it matches what you expect.
- Back in Claude Code,
/mcpshould show the server connected with a tool count next to it.
This is standard MCP OAuth: Claude Code gets a token for that server and you never handle it. Claude Code’s documentation (opens in a new tab) says these tokens are stored securely and refreshed automatically. What happens during that browser step, and what to check on the consent screen, is explained in how MCP sign-in works. You can also sign in from the shell without opening a session with claude mcp login atlassian.
Step 3: first prompts to try
Start read-only, so you can see how it interprets your site before it changes anything. These work well as a first session:
- “Which Atlassian sites can you see, and who am I signed in as?” This confirms the connection and the account.
- “List the Jira projects I can access.”
- “Find the open bugs assigned to me in project PAY, newest first.” Claude Code will write the JQL for you, and you can ask it to show the query.
- “Summarise PAY-412, including its comments and what changed recently.”
Then try one write you can check by eye: “Create a bug in PAY titled ‘Retry job double-charges on timeout’ with these steps to reproduce”, or “Move PAY-412 to In Review and comment with the commit hash.” Status changes go through your project’s real workflow transitions, so a move that your workflow does not allow will fail the same way it would for you in the browser.
Permissions: whose rights does it use?
Yours. Atlassian’s documentation (opens in a new tab) says every action respects the authenticated user’s existing permissions and the server never grants access beyond what the user already has. If you cannot see a project in the browser, Claude Code cannot see it either. The other side of that is worth saying plainly: whatever your account can change, the assistant can change too, within the tools that are switched on.
There are two layers above that. Atlassian groups the tools by intent (opens in a new tab) (read, write, search, delete, manage), and the delete and project-management groups are disabled by default until an admin enables them. And Claude Code has its own permission prompts: in Manual mode it asks before an MCP tool call (recent versions start in auto mode instead), and you can pre-approve tools in your settings. Rules take the form mcp__<server>__<tool>, so with the server named atlassian a rule such as mcp__atlassian__searchJiraIssuesUsingJql covers one tool. Pre-approve searches and reads; leave anything that edits or transitions on ask until you trust the prompts you are giving it.
{
"permissions": {
"allow": [
"mcp__atlassian__getJiraIssue",
"mcp__atlassian__searchJiraIssuesUsingJql"
]
}
}Running it without a browser
On a machine without a display, claude mcp login atlassian prints the sign-in address instead of opening a browser; open it on your own machine and paste the redirect URL back, as Claude Code’s documentation describes. For CI or other automation, Atlassian also supports API token authentication (opens in a new tab), but only if an organisation admin has enabled it. A personal API token is sent as HTTP Basic (your email and the token, base64-encoded) and a service account key as a Bearer token. Claude Code passes either with --header when you add the server. Atlassian notes that some tools, such as code search and Teams, need OAuth and are not available with a token.
Limits to know
- Cloud only. There is no Data Center or Server version of this hosted server.
- Tools appear in two stages. The server lists a small set of primary tools up front and lets the client find the rest through a
discovertool. If Claude Code seems not to know a tool exists, ask it to look for one; if you run it behind a gateway that needs the full list, Atlassian documents a?tools=allparameter. - Some calls cost Rovo credits. Atlassian says certain tools, such as Teamwork Graph and search, consume Rovo credits from the organisation’s pool, up to 10 per call depending on the context retrieved. Check with your admin if your organisation watches that usage.
- Large results fill context. Claude Code warns when one MCP tool result passes 10,000 tokens and caps output at 25,000 by default (raise it with
MAX_MCP_OUTPUT_TOKENS). Ask for narrower JQL rather than raising the cap. - Sandboxing. If you run Claude Code with its sandbox on, Atlassian says attachment and whiteboard tools need
api.media.atlassian.comand*.frontend.public.atl-paas.netinnetwork.allowedDomains. - It works with exactly your account’s rights. There is no separate assistant identity with narrower permissions. Atlassian admins can filter the organisation’s audit log (opens in a new tab) for Rovo MCP user actions.
Removing or resetting it
claude mcp logout atlassian # clear this machine's sign-in claude mcp remove atlassian # remove the server entirely
The same “Clear authentication” option is in the server’s menu under /mcp. Clearing the client side removes the token from your machine; your Atlassian admin controls access on the Atlassian side.
If Jira is more than you need
Jira is built for software organisations with workflows, sprints and many projects, and the MCP server exposes all of that. If what you actually want is a simpler board your assistant works on as a member, with a role of its own rather than all of your rights, and a signed history of what it changed, that is what fenbs is for. The fair comparison is on fenbs vs Jira, and the Claude Code setup is on its integration page.
Related
The Jira tool list and permission groups: what can the Jira MCP server do. What to check on any consent screen: how MCP sign-in works. Habits for any MCP connection: MCP security best practices.