Skip to main content
Glama
tinyc0der

atlassian-browser-mcp

by tinyc0der

atlassian-browser-mcp

License: GPL-3.0 Python 3.11+ GitHub stars mcp-atlassian GeiserX/atlassian-browser-mcp MCP server

MCP server that wraps the upstream mcp-atlassian toolset with browser-cookie authentication. Cookies are captured from your real Chrome by a bundled Chrome extensionno Playwright, no browser automation. Works for Atlassian Cloud (*.atlassian.net) and Server/Data Center behind corporate SSO (Okta, SAML, etc.) where API tokens are not available.

How it works

Capturing cookies and serving data are separate, and there is no browser automation anywhere — this is what keeps the MCP server from hanging:

  1. Capture cookies with the Chrome extension. Load chrome-extension/ unpacked. After a one-time atlassian-cli install-host, open a Jira/Confluence tab and click Sync cookies — cookies for the current tab’s domain go to a local Native Messaging host that writes per-service jars.

  2. The MCP server serves data only. It reads the saved cookies via a custom requests.Session subclass and never opens a browser. On a missing/expired session it fails fast with an AuthRequiredError telling you to re-sync — it does not block.

⚠️ Earlier versions launched a Playwright login browser from inside the server. Because the server is detached and async, that blocked tool calls for minutes (often forever) and could deadlock Playwright's sync API on the event loop. Moving capture to the extension removes that failure mode — and removes the need to read Chrome's on-disk cookie DB, which Chrome 127+ "app-bound" encryption blocks.

The server monkey-patches JiraClient and ConfluenceClient constructors in mcp-atlassian to inject the browser-cookie session, giving full parity with the upstream tool surface.

Related MCP server: jira-mcp

Files

File

Purpose

atlassian_browser_mcp_full.py

MCP entrypoint. Patches upstream clients, registers atlassian_login tool, runs the MCP server

atlassian_browser_auth.py

Shared auth core: BrowserCookieSession, saved-jar loading, write_storage_state/probe_live, SSO detection. Never opens a browser

atlassian_cli.py + atlassian-cli

Command-line front-end (install-host, import, Jira/Confluence get/search). See AGENT_USAGE.md

atlassian_cookie_import.py

Shared cookie → jar import + liveness probe (CLI and native host)

atlassian_native_host.py + atlassian-native-host

Chrome Native Messaging host for one-click Sync

chrome-extension/

Manifest V3 extension: Sync current-tab cookies via native host — see chrome-extension/README.md

run-atlassian-browser-mcp.sh

MCP launcher: creates venv, installs deps via uv, runs compatibility check, starts server

pyproject.toml

Dependency pins

Reusing your real Chrome session (the Chrome extension)

Modern Chrome (127+) encrypts cookies with an app-bound key that can't be read off disk, so the reliable way to reuse your Chrome SSO session is the bundled extension — it reads cookies from Chrome's live cookie store, no password or MFA re-prompt:

  1. export JIRA_URL=… CONFLUENCE_URL=… then ./atlassian-cli install-host (registers the native host; freezes URLs for Chrome-launched processes).

  2. chrome://extensions → enable Developer modeLoad unpacked → select chrome-extension/ → reload after install-host.

  3. Open a Jira/Confluence tab, click the extension → Sync cookies.

Cookie jars are never auto-deleted on an auth failure. Jira and Confluence keep separate jars; on Atlassian Cloud they share one host, so a single sync covers both. See chrome-extension/README.md for details and the managed-Chrome caveat.

CLI usage

export JIRA_URL="https://yourco.atlassian.net"
export CONFLUENCE_URL="https://yourco.atlassian.net"   # Cloud: same host

./atlassian-cli install-host                               # once per machine
# then: open Jira/Confluence tab → extension → Sync cookies

./atlassian-cli jira get PROJ-123 --comments
./atlassian-cli jira search 'project = PROJ AND status = "In Progress"'
./atlassian-cli confluence get 123456789 --markdown -o page.md
./atlassian-cli confluence search 'release process' --space DEV

Usage

./run-atlassian-browser-mcp.sh

MCP server configuration

Add to your Claude Code, Cursor, or other MCP client configuration:

{
  "mcpServers": {
    "atlassian": {
      "command": "/path/to/atlassian-browser-mcp/run-atlassian-browser-mcp.sh",
      "env": {
        "JIRA_URL": "https://yourco.atlassian.net",
        "CONFLUENCE_URL": "https://yourco.atlassian.net"
      }
    }
  }
}

The server never opens a browser. Capture cookies once with the extension Sync (or import); all MCP tool calls then proceed using the saved session, and a missing/expired session fails fast with a clear re-sync message.

Environment variables

Variable

Default

Description

JIRA_URL

(required)

Jira base URL (e.g. https://yourco.atlassian.net)

CONFLUENCE_URL

(required)

Confluence base URL (e.g. https://yourco.atlassian.net). For Cloud (*.atlassian.net) the /wiki context path is appended automatically

ATLASSIAN_BROWSER_AUTH_ENABLED

true

Enable browser-cookie auth (set false to fall back to token auth)

ATLASSIAN_STORAGE_STATE

./.atlassian-browser-state-{service}.json

Cookie-jar file. Per-service by default; an explicit value is still namespaced per service

ATLASSIAN_SSO_MARKERS

(auto)

Comma-separated URL/text markers for SSO redirect detection. Defaults cover Okta, ADFS, Azure AD, PingOne, Google SAML

ATLASSIAN_BROWSER_USER_AGENT

(Chrome 136)

Custom User-Agent string for API requests and liveness probes

TOOLSETS

all

Which upstream toolsets to enable

Requirements

  • Python 3.11+

  • uv (for dependency management)

  • Google Chrome (or another Chromium-family browser) to run the extension and capture the session

  • Network access to your Atlassian instance

Troubleshooting

Symptom

Cause

Fix

Tools return AuthRequiredError / "not authenticated"

No saved session (jar missing or expired)

Extension Sync (after install-host), or atlassian-cli import <file>

import reports HTTP 401/302 (not live)

Exported cookies are already expired

Sign into Jira/Confluence in Chrome, re-Export, and import again

No cookies match your hosts on import

JIRA_URL/CONFLUENCE_URL don't match the exported cookies' domain

Fix the env vars to point at the same instance you exported from

"Load unpacked" is greyed out

Managed/corporate Chrome blocks unpacked extensions

Ask IT to allowlist the extension, or pack & self-host it (see chrome-extension/README.md)

"Upstream compatibility check failed"

mcp-atlassian version changed its internal API

Pin to a compatible version or update the wrapper

Available Tools

1 tool
atlassian_loginA

Report how to authenticate. Cookies are captured OUT-OF-BAND.

This tool intentionally does NOT open a browser or drive Playwright (removed entirely): a sync browser login inside the async-dispatched MCP server deadlocks the event loop and hung the server. Instead, capture cookies with the Chrome extension (chrome-extension/) and load them via the CLI:

atlassian-cli import ~/Downloads/atlassian-cookies.json

Once the jar is saved, the server's tools reuse it automatically — no browser is ever opened from within the server.

ParametersJSON Schema
NameRequiredDescriptionDefault
urlNo
targetNojira

Output Schema

ParametersJSON Schema
NameRequiredDescription

No output parameters

TDQS

A4.1/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries full burden. It explicitly explains that the tool does not open a browser, captures cookies out-of-band, and details the deadlock problem. It also mentions automatic reuse of cookies, providing comprehensive behavioral disclosure beyond what annotations would cover.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is front-loaded with the key message ('Report how to authenticate. Cookies are captured OUT-OF-BAND.') and provides necessary context without excessive verbosity. A few sentences could be trimmed, but each sentence contributes to understanding the tool's unique behavior.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no annotations and low schema coverage, the description thoroughly explains the authentication flow, why browser login is avoided, and the steps to authenticate. It omits details about return values, but an output schema exists (not shown) which may compensate. Overall, it is mostly complete for agent use.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Input schema has 0% description coverage, and the description does not explain the parameters 'url' and 'target'. While it mentions Jira and Confluence, it fails to describe what 'url' represents or how 'target' influences behavior. The description does not compensate for the missing schema descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states the tool 'reports how to authenticate,' which is a clear purpose. It distinguishes itself by explaining that it does not open a browser but provides out-of-band instructions. However, the exact nature of the 'report' (e.g., returning status or instructions) is implicit, leaving some ambiguity.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly states when not to use the tool ('does not open a browser') and provides an alternative method (cookie capture via Chrome extension and CLI import). It explains the deadlock issue, offering strong guidance on proper usage versus alternative approaches.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 1 tool updatev1.2.0
    • First observedatlassian_login

TDQS

A3.8/5.0
Disambiguation5/5

With only one tool, there is no possibility of confusion between tools, so disambiguation is perfect.

Naming Consistency5/5

Since there is only one tool, naming consistency is trivially maintained.

Tool Count1/5

A single informational tool is extremely insufficient for a server intended to browse Atlassian services, indicating a severe mismatch in scope.

Completeness1/5

The tool only provides authentication instructions, lacking any actual browsing or interaction capabilities, making the surface severely incomplete.

Maintenance

ActivitySlowing
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    This MCP server enables interaction with Atlassian products (Jira and Confluence), with additional tools for uploading attachments, embedding images, and commenting with images. It supports both Cloud and Server/Data Center deployments.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    An MCP server that lets AI assistants create, search, and manage Jira issues using Chrome browser session cookies for authentication, eliminating the need for API tokens.
    98
    Apache 2.0

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/tinyc0der/atlassian-cookie-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server