Steve Docs

JA

How-To Guides

Confluence Integration with Steve

Connect Confluence to Steve through Atlassian's Rovo MCP server โ€” enable API token authentication, add the connector, and scope its tools

Steve Documentation Team
external-mcpconfluenceatlassianconnectorsauthenticationpmm

Overview

Confluence connects to Steve as an external MCP connector pointed at Atlassian's Rovo MCP server. Once it's connected, Steve can search your spaces and pull page content into battle cards, Canvas blocks, and Insights replies.

One URL, one API token, one email โ€” plus one toggle your Atlassian org admin has to flip first. That toggle is where almost every failed setup stops.

Who it's for: ๐Ÿ“ฃ PMM / Steve org manager โ€” with an Atlassian organization admin for Step 1.

What you'll need

RequirementNotes
Steve organization manager roleThe Connectors tab is org-manager only
An Atlassian org adminOnly they can turn on Allow API token authentication (Step 1)
Atlassian account emailThe email that owns the API token
An Atlassian API tokenCreated in Step 2
Confluence Cloudmcp.atlassian.com serves Cloud sites only โ€” Server and Data Center aren't supported

The connection details

SettingValue
Remote MCP server URLhttps://mcp.atlassian.com/v1/mcp
Account emailThe Atlassian account that owns the token
TokenThe Atlassian API token
Auth header Steve sendsAuthorization: Basic base64(email:token)

Steve switches to HTTP Basic automatically for any atlassian.com URL, because that's the only mode in which Atlassian returns its full toolset. The older /v1/sse endpoint is deprecated โ€” use /v1/mcp.


Step 1: Turn on API token authentication (Atlassian org admin)

This is the actual blocker. Rovo MCP ships with OAuth 2.1 on and Allow API token authentication off. Steve authenticates with an API token, so until an org admin turns this on, every attempt fails at the first request โ€” no tools, no connector.

  1. Sign in to admin.atlassian.com.
  2. Select the organization (if there's more than one).
  3. Go to Rovo โ†’ Rovo MCP server.
  4. In the Authentication section, turn Allow API token authentication on.

The same page is also reachable at Security โ†’ Rovo MCP server.

Screenshot of admin.atlassian.com showing the Rovo MCP server page with the Authentication section and the Allow API token authentication toggle switched on

Caption: Rovo โ†’ Rovo MCP server โ†’ Authentication. Allow API token authentication must be on before Steve can connect.

Confirm it's on before moving to Step 2 โ€” a correct token against an org with this setting off still fails, and the error looks identical to a bad token.

Step 2: Create the API token

  1. Sign in as the account Steve should use, and open id.atlassian.com/manage-profile/security/api-tokens.
  2. Click Create API token. If you're offered scopes, include the Confluence read scopes (add write scopes only if Steve should create or edit pages).
  3. Name it something recoverable, for example Steve MCP connector.
  4. Copy the token now โ€” Atlassian shows it once.

Use a shared service account, not your personal one. The token inherits that account's Confluence permissions โ€” Steve sees exactly the spaces and pages that account can see, and nothing else. A personal token breaks the day that person leaves.

Step 3: Add the connector in Steve

  1. Open Settings โ†’ Connectors (or /settings#connectors).
  2. Click Add Connector.
  3. Fill in the dialog:
FieldValue
NameConfluence
Remote MCP server URLhttps://mcp.atlassian.com/v1/mcp
Account emailThe email that owns the token โ€” this field appears automatically for atlassian.com URLs
TokenThe API token from Step 2
DescriptionOptional, e.g. Product wiki + release notes
Advanced settingsLeave empty โ€” no OAuth client ID or secret is needed
  1. Click Add.

Screenshot of the Add custom connector dialog filled in for Confluence, showing Name "Confluence", the mcp.atlassian.com/v1/mcp URL, the Account email field, and a masked Token

Caption: The Account email field only appears once the URL is an Atlassian one. Both it and the token are required.

Steve connects, calls tools/list, and saves the connector as Connected โ€” you'll see a toast such as "Confluence connected ยท 25 tools discovered". The token is encrypted at rest and never returned to the browser.

Step 4: Make it active

A connected connector still does nothing until it's scoped. On the connector's detail panel:

  1. Used in projects โ†’ + Add โ†’ tick the projects that should use Confluence.
  2. Used in features โ†’ + Add โ†’ pick from Battle Card creation, Canvas, Insights replies.
  3. Tool permissions โ†’ allow what Steve needs, block the rest.

Full detail on each of these is in Configure & Manage.

Suggested tool permissions

ToolWhat it doesSuggested
searchConfluenceUsingCqlSearches pages by CQL queryโœ“ Allow
getConfluenceSpacesLists the spaces the account can seeโœ“ Allow
getPagesInConfluenceSpaceLists pages in a spaceโœ“ Allow
getConfluencePageReads one page's contentโœ“ Allow
createConfluencePageCreates a new pageโŠ˜ Block unless intended
updateConfluencePageEdits an existing pageโŠ˜ Block unless intended
createConfluenceFooterCommentComments on a pageโŠ˜ Block unless intended

Rovo MCP also exposes Jira, Compass, and Bitbucket tools on the same connection. Block whatever you don't want in scope, or set the fallback dropdown to Always denied and allow only the rows above.

Screenshot of the Tool permissions section for the Confluence connector, showing Confluence read tools set to Allow and the write tools set to Block

Caption: Read tools allowed, write tools blocked โ€” a safe default for a documentation source.

A useful generation prompt

Add this to the connector's Generation prompt box so Steve reaches for the wiki at the right moment:

"Use searchConfluenceUsingCql to check the product wiki before answering positioning or pricing questions. Cite the page title and URL for every claim taken from Confluence."


Troubleshooting

What you seeCauseFix
Authentication failed on AddAPI token auth is off for the Atlassian orgStep 1 โ€” org admin turns Allow API token authentication on
Authentication failed with the toggle already onWrong email, wrong token, or a revoked tokenRe-create the token; confirm the email owns it
Connected, but no Confluence toolsThe account has no access to Confluence, or can't see any spaceGrant the account Confluence access and space permissions
Couldn't reach this MCP serverNetwork egress to mcp.atlassian.com is blockedAllow the host through your proxy or firewall

"Authentication failed" right after clicking Add

Check Step 1 first โ€” it's the cause more often than the token is. Then confirm the Account email is the account that created the token, and that the token hasn't been revoked.

Connected, but Steve never cites Confluence

The connector is probably not scoped. Confirm it has a project chip and a feature chip for the surface you're using, and that the read tools are set to Allow.

Tools disappeared after an Atlassian change

Open the โ‹ฏ menu โ†’ Test connection. It re-validates the credentials and refreshes the tool list, keeping your Allow/Block choices.

The connector sits in "Needs attention"

Connectors in that group are skipped at generation time. Test connection surfaces the current error; work it back through the table above.

Expected Outcome

  • โœ… Allow API token authentication is on in the Atlassian org's Rovo MCP server settings
  • โœ… The Confluence connector shows under Connected with its tools listed
  • โœ… At least one project chip and one feature chip on the connector
  • โœ… Confluence read tools are Allow; write tools are Block unless you want them

Next Steps