A secure, TypeScript-based MCP gateway that enables AI agents to interact with Jira through controlled, audited tool calls without exposing credentials.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.JIRA_ALLOW_ISSUE_DELETESJIRA_API_TOKEN— replace-meJIRA_APPROVAL_MODE— Use console for local development, webhook for production approval workflows, or none to deny approval-gated actions.JIRA_AUDIT_LOG_FILEJIRA_AUDIT_LOG_MODE— Use console for local development, file for local append-only logs, webhook for centralized audit ingestion, or none to disable audit logging.JIRA_AUTH_MODE— Use scoped by default. Use classic only for quick local development, prototyping, or compatibility fallback.JIRA_BASE_URL— Use your Jira site URL, usually https://your-company.atlassian.net. Open Jira in your browser and copy the origin before /jira or /browse.JIRA_CLOUD_IDJIRA_DEFAULT_PROJECT— Use the Jira project key shown in issue keys, such as PROJ from PROJ-123.JIRA_DEPLOYMENT_TYPEJIRA_EMAIL— Assignment defaults: whenever a tool has an assignee option and the caller omits it, the gateway assigns work to the Jira account configured by .JIRA_MAX_SEARCH_RESULTSJIRA_OAUTH_ACCESS_TOKENJIRA_REQUIRE_APPROVAL_FOR_HIGH_RISKJIRA_WEBHOOK_APPROVAL_URLJIRA_WEBHOOK_AUDIT_URL[](https://m8ven.ai/mcp/yauchinlam-jira-agent-gateway-x1pyi3)