Connections are added inside an Access bundle. At
claude.ai/admin-settings/claude-tag, open Access bundles in the left navigation, click into a bundle (or Create one), and go to its Credentials tab.Create the credential in Atlassian
Create a dedicated Atlassian account for Claude (for exampleclaude@yourcompany.example.com) and add it to the Jira projects and Confluence spaces it should reach. The connection can read whatever this account can read, so a dedicated account keeps Claude’s reach to exactly what you grant it.
Sign in as that account and create an API token at id.atlassian.com/manage-profile/security/api-tokens. Atlassian shows the token once; store it somewhere you can retrieve it. Atlassian API tokens expire, with a maximum lifetime of one year, so plan to create a new token and update the connection before the old one lapses.
Create the API token without scopes. Atlassian accepts tokens with scopes, including service account tokens, only at its
api.atlassian.com gateway, not at your site’s hostname, so the preset can’t use them.api.atlassian.com under Allowed websites. Then restrict the connection to the path prefixes /ex/jira/<cloud-id>/ and /ex/confluence/<cloud-id>/, because the cloud ID in a gateway request’s path chooses which Atlassian site the request reaches. Atlassian documents tokens with scopes, service account tokens, and how to find your site’s cloud ID.
Add the connection to a bundle
On the bundle’s Credentials tab, click Connect next to Jira & Confluence. The form asks for the dedicated account’s email address and the API token from Atlassian. In the host field, replace the prefilled*.atlassian.net with your own site’s hostname, such as your-domain.atlassian.net. The form rejects the wildcard because it would let the credential reach any Atlassian site, not just yours.
The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See how Agent Proxy works.
Atlassian Data Center (self-hosted) isn’t covered by the preset because it authenticates with a personal access token sent as a Bearer header. Add a Data Center instance as a custom connection with the Bearer credential type and your instance’s hostname under Allowed websites. The instance must be reachable from the public internet.
Verify the connection
In a channel under the bundle’s scope, in a new thread, ask Claude to fetch one issue or page by key or URL. The call lands under the dedicated account in Atlassian’s audit log.Related resources
- Custom connection: for a setup the preset doesn’t cover, such as a self-hosted Data Center instance
- Give Claude access: the full connection model and how to scope a dedicated account