Approved clients only
Register each AI client and organization. Restrict by environment (production or sandbox), user group and source IP range. Suspend a client in one click.
Short-lived scoped credentials
Credentials last 1 hour to 7 days, are bound to one client, one user and a tool scope, and are stored only as hashes. No personal API tokens in agent configs.
Project, space and tool policies
Allow, deny, dry-run or require approval per project, space, tool and read/write access. Search results outside allowed projects are withheld.
Budgets that protect your site
Per-client concurrency, requests per minute and daily budgets, with clear denial messages and retry hints for the agent.
Dry-run and approvals
Preview every mutation with the exact REST request and before/after values. Queue risky changes for an administrator to approve in Jira.
Audit evidence
Every call records actor, client, tool, target, policy decision and outcome, with redacted payloads. Search in Jira and export CSV or JSON.
How it connects
Install AgentGate in Jira and Confluence. Atlassian sends the gateway short-lived app tokens (at most 4 hours) through Forge Remote — the gateway never asks for passwords, API tokens or refresh tokens. Your AI clients connect to the MCP endpoint https://agentgate-ai-governance.apps.elektraset.com/mcp with a credential that an administrator issues.
To make AgentGate the only path, turn off API-token access and block unapproved domains in the Atlassian Rovo MCP server settings, and use your IP allowlist. See the setup guide.