AgentGate setup guide
AgentGate puts one policy gateway between your AI clients (Claude, GitHub Copilot, Cursor, custom agents and MCP clients) and Jira Cloud and Confluence Cloud. This guide takes about 15 minutes.
1. Install AgentGate
- Install AgentGate from the Atlassian Marketplace in Jira. Install it in Confluence too if your agents use Confluence.
- Open Jira settings → Apps → AgentGate (Confluence: Confluence administration → AgentGate). The Overview tab shows the Jira and Confluence connections. Atlassian sends AgentGate a short-lived app token on install and every 5 minutes.
- Mark each connection as production or sandbox. Clients that are allowed only in sandbox cannot touch a production site.
2. Register an approved client
In the Clients tab, add one client per AI tool and organization, for example "Claude Enterprise — Acme Platform team":
- Organization: the AI vendor organization or team that owns the client.
- Environments: production, sandbox or both.
- Allowed groups: only members of these Atlassian groups can use credentials of this client.
- Allowed IP ranges: for example the egress ranges of your agent runners (CIDR, for example
203.0.113.0/24). - Mode:
enforceordry_run(every change of this client is only previewed). - Budgets: concurrent calls, requests per minute and requests per day.
3. Write policies
In the Policies tab, rules are checked by priority (lowest number first) and the first match decides. Each rule matches product, Jira projects, Confluence spaces, tools, read/write access, clients and environment. Effects:
| Effect | What happens |
|---|---|
| allow | The call runs. |
| deny | The call is refused with a clear reason. Search results in denied projects or spaces are withheld. |
| dry_run | Writes are previewed (exact REST request, before and after values) but not applied. |
| require_approval | Writes are queued; an administrator approves or rejects them in the Approvals tab. |
Without a matching rule, the defaults in Settings apply (default: reads allowed, writes need approval).
4. Issue a credential and connect the client
In the Clients tab choose Issue credential: pick the user, the lifetime (1 hour to 7 days by default), read or read/write access and the tools. The secret is shown once. AgentGate stores only its SHA-256 hash.
MCP endpoint: https://agentgate-ai-governance.apps.elektraset.com/mcp (Streamable HTTP, stateless, JSON responses).
Claude Code:
claude mcp add --transport http agentgate https://agentgate-ai-governance.apps.elektraset.com/mcp --header "Authorization: Bearer agw_..."
Cursor, VS Code / GitHub Copilot and other clients that read an mcpServers JSON file:
{
"mcpServers": {
"agentgate": {
"type": "http",
"url": "https://agentgate-ai-governance.apps.elektraset.com/mcp",
"headers": { "Authorization": "Bearer agw_..." }
}
}
}
Keep the credential in a file with mode 0600 or in the client's secret store, not on a command line.
5. Tools
| Tool | Access | What it does |
|---|---|---|
| jira_search_issues | read | JQL search (results filtered by policy) |
| jira_get_issue | read | Read one issue |
| jira_create_issue | write | Create an issue |
| jira_update_issue | write | Change summary, description, labels |
| jira_add_comment | write | Comment on an issue |
| jira_transition_issue | write | Move an issue to another status |
| confluence_search | read | CQL search (results filtered by policy) |
| confluence_get_page | read | Read one page |
| confluence_create_page | write | Create a page |
| confluence_update_page | write | Replace a page body (new version) |
| confluence_add_comment | write | Add a footer comment |
| gateway_whoami | — | Show client, scope, budgets and usage |
| gateway_approval_status | — | Check a queued change |
Every write tool accepts dryRun: true to preview the change.
6. Test safely
The Playground tab runs any tool as any registered client. Reads run for real; writes are always previewed and never applied. Use it to check a policy before you give an agent a credential.
7. Make AgentGate the only path (recommended)
AgentGate can only govern traffic that goes through it. In Atlassian Administration → Security → Rovo MCP server, turn off API-token authentication and block the AI domains that should use AgentGate instead; use your organization IP allowlist. Tell users to remove personal API tokens from agent configs.
8. Audit evidence
The Audit tab searches all events by actor, client, tool, target, decision and outcome. Export CSV and Export JSON create a download link that is valid for 10 minutes. Request and response payloads are redacted (secrets removed, e-mail addresses masked, long text cut).