Atlassian Data CenterCAUTION
MCP servers for the Atlassian products (Bitbucket, Confluence, JIRA) of the Data Center version
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/b1ff-atlassian-dc-mcp)
[](https://mseep.ai/app/2a87ecc6-e53a-4a21-b63e-ede9b6a2bc4a)
Note: This is a community-maintained project and is not affiliated with, endorsed by, or supported by Atlassian. Use at your own discretion.
This project provides a Model Context Protocol (MCP) integration for Atlassian Data Center products, including Jira, Confluence, and Bitbucket.
Quick Setup
Each package ships an interactive setup subcommand that stores your credentials in the most secure place available on your OS. Run it once per product:
npx @atlassian-dc-mcp/jira setup npx @atlassian-dc-mcp/confluence setup npx @atlassian-dc-mcp/bitbucket setup
The setup CLI prompts for host, API base path, default page size, and API token. Before saving, it validates obvious input mistakes and performs a timed authenticated request to the selected Atlassian product, so a bad host, base path, or token is caught during setup.
CLI flags and non-interactive mode
Setup accepts flags so you can prefill values or skip prompts entirely (useful for scripted bootstrap, CI, or remote sessions). Run npx @atlassian-dc-mcp/ setup --help for the full list.
In interactive mode, any flag you pass prefills its prompt (so e.g. --host skips the host prompt but still asks for the rest). In --non-interactive mode, setup resolves anything
8b5cac96ae81OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add bitbucket --env BITBUCKET_API_TOKEN=${BITBUCKET_API_TOKEN} -- npx -y @atlassian-dc-mcp/[email protected]Exposed tools (51)
33 read · 16 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
bitbucket_canMergePullRequest | read | Check whether a pull request can be merged. Read-only: returns canMerge, whether the pull request is conflicted, and any merge-check vetoes (e.g. missing approvals, unresolved tasks, failed builds). Use this before bitbucket_mergePullRequest to see what is blocking a merge. |
bitbucket_createBranch | write | Create a branch in a Bitbucket repository, forked from a branch, tag or commit. Use this before bitbucket_createPullRequest when the source branch does not exist yet. The response contains the new branch |
bitbucket_createPullRequest | read | |
bitbucket_declinePullRequest | read | Decline (close without merging) a pull request. IMPORTANT: you MUST first call bitbucket_getPullRequest to get the current |
bitbucket_getBranchDiff | read | Get the diff between two branches, tags or commits — including branches that have no pull request yet. Returns the same comparison as the Bitbucket |
bitbucket_getCommits | read | Get commits for a Bitbucket repository |
bitbucket_getDashboardPullRequests | read | Get pull requests from the Bitbucket dashboard across all repositories. Useful for finding all PRs where you are the author, reviewer, or participant without specifying a project or repository. |
bitbucket_getFileContent | read | Get the raw content of a file in a Bitbucket repository, at a branch, tag or commit. Use this to read a source file without cloning the repository. |
bitbucket_getInboxPullRequests | read | Get pull requests from the authenticated user |
bitbucket_getPR_CommentsAndAction | read | Get comments for a Bitbucket pull request and other actions, like approvals |
bitbucket_getProject | read | Get a specific Bitbucket project by key |
bitbucket_getProjects | read | Get a list of Bitbucket projects |
bitbucket_getPullRequest | read | Get a specific pull request by ID. Returns full details including title, description, reviewers, participants, author, source/target branches, current state, and version (needed for bitbucket_updatePullRequest). |
bitbucket_getPullRequestChanges | read | Get the changes for a Bitbucket pull request |
bitbucket_getPullRequestDiff | read | Get text diff for a specific file in a Bitbucket pull request. Returns plain text diff format. Note: Before getting diff, use getPullRequestChanges to understand what files were changed in the PR |
bitbucket_getPullRequests | read | Get pull requests for a Bitbucket repository |
bitbucket_getRepositories | read | Get repositories for a Bitbucket project |
bitbucket_getRepository | read | Get a specific Bitbucket repository |
bitbucket_getRequiredReviewers | write | Get required reviewers for pull request creation. Returns a set of users who are required reviewers for pull requests created from the given source repository and ref to the given target ref in this repository. |
bitbucket_getUser | read | Get a Bitbucket user by their slug, or search for users by name/email to discover their slug. Use this to resolve userSlug for bitbucket_submitPullRequestReview when it is not already known from a comment response or PR participant list. |
bitbucket_mergePullRequest | write | Merge a pull request. IMPORTANT: you MUST first call bitbucket_getPullRequest to get the current |
bitbucket_postPullRequestComment | read | |
bitbucket_reopenPullRequest | read | Reopen a declined pull request, restoring it to OPEN. IMPORTANT: you MUST first call bitbucket_getPullRequest to get the current |
bitbucket_searchCode | read | Search code across Bitbucket. The query supports search modifiers like |
bitbucket_submitPullRequestReview | write | Submit a pull request review, publishing all pending (draft) comments and setting the reviewer |
bitbucket_updatePullRequest | write | Update the title, description, reviewers, destination branch or draft status of an existing pull request. IMPORTANT: You MUST first call bitbucket_getPullRequest to get the current |
bitbucket_updatePullRequestComment | write | Update an existing pull request comment. Use to edit text, change severity, change task state, or resolve/reopen the comment thread. On a BLOCKER (task) comment, state: |
confluence_createContent | write | Create new content in ${confluenceInstanceType} |
confluence_downloadAttachment | read | Download one or more attachments from a Confluence content (page) in the ${confluenceInstanceType}. Returns the file content inline (base64 or text). Useful for inspecting a file or moving it elsewhere (e.g. re-uploading to a Jira issue).${downloadSaveEnabled ? |
confluence_getContent | read | Get Confluence content by ID from the ${confluenceInstanceType} |
confluence_searchContent | read | Search for content in ${confluenceInstanceType} using CQL |
confluence_searchSpace | read | Search for spaces in ${confluenceInstanceType} |
confluence_updateContent | write | Update existing content in ${confluenceInstanceType}. Optionally move the page by setting parentId. |
confluence_uploadAttachment | write | Upload a local file as an attachment to a Confluence content (page) in the ${confluenceInstanceType}. The file must live under the server-configured upload directory; the path is given relative to that directory. |
jira_createIssue | write | Create a new JIRA issue in the ${jiraInstanceType} |
jira_downloadAttachment | read | |
jira_getIssue | read | Get details of a JIRA issue by its key from the ${jiraInstanceType} |
jira_getIssueComments | read | Get comments of a JIRA issue by its key from the ${jiraInstanceType} |
jira_getIssueDevelopmentInfo | read | Get linked development information (pull requests, commits, or branches) shown in the Development panel of a JIRA issue in the ${jiraInstanceType}. Defaults to pull requests from Bitbucket. |
jira_getIssueLinkTypes | read | Get the list of available issue link types (e.g. Blocks, Relates, Duplicate) in the ${jiraInstanceType}. Use this to discover valid link type names before calling jira_linkIssues. |
jira_getTransitions | read | Get available status transitions for a JIRA issue in the ${jiraInstanceType}. Returns a list of transitions with their IDs, names, and target statuses. |
jira_linkIssues | write | Create a link between two JIRA issues in the ${jiraInstanceType}. Direction is easy to invert vs the Jira UI: inwardIssueKey is the issue that DISPLAYS the outward phrase (e.g. |
jira_postIssueComment | write | Post a comment on a JIRA issue in the ${jiraInstanceType} |
jira_searchIssues | read | Search for JIRA issues using JQL in the ${jiraInstanceType} |
jira_transitionIssue | read | Transition a JIRA issue to a new status in the ${jiraInstanceType}. Use jira_getTransitions first to get available transition IDs. |
jira_unlinkIssues | destructive | Delete an existing link between two JIRA issues in the ${jiraInstanceType}. Requires the issue link id (found in the |
jira_unwatchIssue | destructive | Remove yourself (the authenticated user) as a watcher from a JIRA issue in the ${jiraInstanceType}. Only the calling user can be removed; there is no way to unwatch on behalf of someone else. |
jira_updateIssue | write | Update an existing JIRA issue in the ${jiraInstanceType} |
jira_updateIssueComment | write | Update the body of an existing comment on a JIRA issue in the ${jiraInstanceType}. Use jira_getIssueComments to find the comment id. |
jira_uploadAttachment | write | Upload a local file as an attachment to a JIRA issue in the ${jiraInstanceType}. The file must live under the server-configured upload directory; the path is given relative to that directory. |
jira_watchIssue | write | Add yourself (the authenticated user) as a watcher on a JIRA issue in the ${jiraInstanceType}. Only the calling user can be added; there is no way to watch on behalf of someone else. |
Trust audit
CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (15)
token: 'CONFLUENCE_API_TOKEN',
token: 'CONFLUENCE_API_TOKEN',
token: 'CONFLUENCE_API_TOKEN',
token: 'CONFLUENCE_API_TOKEN',
jira_unlinkIssues, jira_unwatchIssue
const dest = await resolveDownloadDestination({ requestedName: '../../etc/passwd', side: side() });import { EnvFileSource, ATLASSIAN_DC_MCP_CONFIG_FILE_ENV_VAR } from '../../sources/env-file.js';import type { ProductDefinition } from '../../source.js';import { HomeFileSource, getHomeFilePath, HOME_DIR_NAME } from '../../sources/home-file.js';import type { ProductDefinition } from '../../source.js';@types/node, jest, lerna, nodemon, ts-node, typescript
@atlassian-dc-mcp/common, @modelcontextprotocol/sdk, dotenv, zod, @modelcontextprotocol/inspector, @types/jest, lerna, nodemon
@modelcontextprotocol/sdk, @types/node, nodemon, ts-node
@atlassian-dc-mcp/common, @modelcontextprotocol/sdk, dotenv, zod, @modelcontextprotocol/inspector, nodemon, ts-node
@atlassian-dc-mcp/common, @modelcontextprotocol/sdk, dotenv, zod, @modelcontextprotocol/inspector, nodemon, ts-node
Gates applied: no_behavioural_pass.
8b5cac96ae81full audit observations/trust-audit/mcp-server/b1ff__atlassian-data-center.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 8b5cac96ae81 | CAUTION | C | 79 | first audit |
Questions
What is the Atlassian Data Center MCP server?
MCP servers for the Atlassian products (Bitbucket, Confluence, JIRA) of the Data Center version
What tools does Atlassian Data Center expose?
51 in total: 33 read-only, 16 that write, and 2 that can delete or overwrite (jira_unlinkIssues, jira_unwatchIssue). Every one is listed on this page with its risk.
Is Atlassian Data Center safe to connect to an agent?
With care. The audit graded it C (79/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Atlassian Data Center need?
It reads BITBUCKET_API_TOKEN, CONFLUENCE_API_TOKEN and JIRA_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Atlassian Data Center run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @atlassian-dc-mcp/jira at 0.35.0.
How current is this page?
The grade is for one exact copy of the source (8b5cac96ae81), read on 2026-10-07. The repository is watched and re-audited when it changes.