
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@atlassian-dc-mcp/confluence
Advanced tools
Community-maintained MCP server for Atlassian Confluence Data Center. Not affiliated with Atlassian.
This package provides a Machine Comprehension Protocol (MCP) server for interacting with Atlassian Confluence Data Center edition.
The easiest way to configure this server is the built-in setup subcommand:
npx @atlassian-dc-mcp/confluence setup
It prompts for host, API base path, default page size, and API token, then stores them in the most secure place available:
atlassian-dc-mcp, account confluence-token); host / base path / page size in ~/.atlassian-dc-mcp/confluence.env (mode 0600).~/.atlassian-dc-mcp/confluence.env with POSIX mode 0600 (read/write for your user only).%USERPROFILE%\.atlassian-dc-mcp\confluence.env. Node passes the mode bits but Windows ignores them, so the file inherits the ACL of your user profile directory (typically readable only by your user, SYSTEM, and Administrators).After setup, you can launch the server without any environment variables:
{
"mcpServers": {
"atlassian-confluence-dc": {
"command": "npx",
"args": ["-y", "@atlassian-dc-mcp/confluence"]
}
}
}
Environment variables still override stored values — see Configuration sources below.
For CI, remote sessions, or shell scripts, pass values as flags and add --non-interactive to skip prompts:
npx @atlassian-dc-mcp/confluence setup --non-interactive \
--host confluence.example.com \
--token "$CONFLUENCE_TOKEN"
Available flags: --host/-H, --api-base-path/-b, --token/-t, --default-page-size/-s, --non-interactive/-n, --help/-h. In --non-interactive mode, missing values fall back to existing configuration and the run exits non-zero if a host (or full-URL --api-base-path) and token cannot be resolved. An existing token is reused when --token is omitted. Run npx @atlassian-dc-mcp/confluence setup --help for full usage.
Install dependencies:
npm install
Create a .env file in the packages/confluence directory, or put the same values in a shared dotenv file and set ATLASSIAN_DC_MCP_CONFIG_FILE to its absolute path:
# Either CONFLUENCE_HOST or CONFLUENCE_API_BASE_PATH must be set
CONFLUENCE_HOST=your-confluence-instance.atlassian.net
CONFLUENCE_API_TOKEN=your-personal-access-token
# Optional: Use one of the following approaches:
# 1. If your Confluence instance hosted on the subpath:
# CONFLUENCE_API_BASE_PATH=https://your-confluence-instance.atlassian.net/sub-path
# 2. Or continue using CONFLUENCE_HOST with the default API path (/rest):
# CONFLUENCE_HOST=your-confluence-instance.atlassian.net
# Optional: default page size for paginated search tools (fallback: 25)
CONFLUENCE_DEFAULT_PAGE_SIZE=25
Shared file example:
CONFLUENCE_HOST=your-confluence-instance.atlassian.net
CONFLUENCE_API_TOKEN=your-personal-access-token
CONFLUENCE_DEFAULT_PAGE_SIZE=25
Start the server with:
ATLASSIAN_DC_MCP_CONFIG_FILE=/absolute/path/to/atlassian-dc-mcp.env npm run dev
Windows example:
set ATLASSIAN_DC_MCP_CONFIG_FILE=C:\Users\your-user\AppData\Roaming\atlassian-dc-mcp.env
npm run dev
Note: You have two options for configuring the API URL:
Set CONFLUENCE_API_BASE_PATH to the full API URL (e.g., "https://host.com/rest/api" or "https://host.com/wiki/rest/api").
When this is set, the CONFLUENCE_HOST variable is ignored.
Set CONFLUENCE_HOST only, which will use the default API path (/rest).
Confluence uses /rest as a path part always, so it will be added automatically, no need to add it manually.
See Configuration sources for the full precedence chain.
By default this server is an API-only client: the attachment tools never read from or write to the local filesystem, and confluence_uploadAttachment is not even registered. confluence_downloadAttachment is always available but can only return file bytes inline (base64/text) — it cannot touch local disk.
Local filesystem access is opt-in and confined to operator-configured directories that the model cannot choose:
# Enable each direction separately (default: false)
CONFLUENCE_ATTACHMENTS_UPLOAD_ENABLED=true
CONFLUENCE_ATTACHMENTS_DOWNLOAD_ENABLED=true
# Allowed roots (os path-separator list). Uploads may only read from these,
# downloads may only write into the first configured download root.
CONFLUENCE_ATTACHMENTS_UPLOAD_ROOTS=/srv/confluence-exchange/in
CONFLUENCE_ATTACHMENTS_DOWNLOAD_ROOTS=/srv/confluence-exchange/out
# Convenience: a single dedicated exchange directory used as both roots
CONFLUENCE_ATTACHMENTS_DIR=/srv/confluence-exchange
# Hard per-file size limits in bytes (default: 25 MiB)
CONFLUENCE_ATTACHMENTS_MAX_UPLOAD_BYTES=26214400
CONFLUENCE_ATTACHMENTS_MAX_DOWNLOAD_BYTES=26214400
Guardrails applied when enabled:
.. segments are rejected, and a path that escapes a root through a symlinked directory is refused.To create a personal access token:
Each key is resolved by walking these sources in priority order and taking the first non-empty value:
| Priority | Source | Reads | Written by setup |
|---|---|---|---|
| 100 | process.env (CONFLUENCE_HOST, CONFLUENCE_API_BASE_PATH, CONFLUENCE_API_TOKEN, CONFLUENCE_DEFAULT_PAGE_SIZE) | all keys | — |
| 80 | env file — ATLASSIAN_DC_MCP_CONFIG_FILE (absolute path) or ./.env | all keys | — |
| 60 | home file — ~/.atlassian-dc-mcp/confluence.env on macOS/Linux, %USERPROFILE%\.atlassian-dc-mcp\confluence.env on Windows (mode 0600 on POSIX; Windows inherits the user-profile ACL) | all keys | host, apiBasePath, defaultPageSize (always); token (non-darwin or keychain fallback) |
| 40 | macOS Keychain — service atlassian-dc-mcp, account confluence-token | token only | token (darwin only) |
setup always writes non-secret fields to the home file and tries the keychain first for the token. If a higher-priority source shadows the value being saved, setup prints a warning so you can unset the env var.
Start the MCP server:
npm run build
npm start
Or for development with auto-reload:
npm run dev
Run the test suite from the package directory:
npm run test
Or from the repository root:
npm run test --workspace=@atlassian-dc-mcp/confluence
Get Confluence Data Center content by ID.
Parameters:
contentId (string, required): The ID of the content to retrieveexpand (string, optional): Comma-separated list of properties to expand (e.g., "body.storage,version")bodyMode (storage | text | none, optional): Response shape for the content body. Defaults to storage for backward compatibility.maxBodyChars (number, optional): Maximum number of characters to keep when bodyMode=textbodyStart (number, optional): Character offset to start the text body slice when bodyMode=text. Non-negative values start from the beginning; negative values start from the end, e.g. -2000 returns the last 2000 characters.Search for content in Confluence Data Center using CQL.
Parameters:
cql (string, required): Confluence Query Language search stringlimit (number, optional): Maximum number of results to return. Defaults to CONFLUENCE_DEFAULT_PAGE_SIZE or 25.start (number, optional): Start index for paginationexpand (string, optional): Comma-separated list of properties to expandexcerpt (none | highlight, optional): Excerpt mode for search results. Defaults to none.Create new content in Confluence Data Center.
Parameters:
title (string, required): Title of the contentspaceKey (string, required): Space key where content will be createdtype (string, default: "page"): Content type (page, blogpost, etc)content (string, required): Content body in Confluence Data Center's storage format (XML-based storage format)parentId (string, optional): ID of the parent page (if creating a child page)output (ack | full, optional): Return a compact acknowledgement or the full API response. Defaults to ack.Update existing content in Confluence Data Center.
Parameters:
contentId (string, required): ID of the content to updatetitle (string, optional): New title of the contentcontent (string, optional): New content body in Confluence Data Center's storage format (XML-based)version (number, required): New version number (must be incremented from current version)versionComment (string, optional): Comment for this versionoutput (ack | full, optional): Return a compact acknowledgement or the full API response. Defaults to ack.Search for Confluence spaces by name text.
Parameters:
searchText (string, required): Text to search for in space names or descriptionslimit (number, optional): Maximum number of results to return. Defaults to CONFLUENCE_DEFAULT_PAGE_SIZE or 25.start (number, optional): Start index for paginationexpand (string, optional): Comma-separated list of properties to expandexcerpt (none | highlight, optional): Excerpt mode for search results. Defaults to none.Upload a local file as an attachment to a Confluence content (page). Only registered when filesystem uploads are enabled (see Attachment filesystem access).
Parameters:
contentId (string, required): ID of the content (page) to attach the file tosourcePath (string, required): Path to the file to upload, relative to a server-configured upload directory. Absolute paths and .. segments are rejected; symlinks and non-regular files are refused.filename (string, optional): Override for the attachment filename (defaults to the basename of sourcePath)comment (string, optional): Comment describing the attachmentminorEdit (boolean, optional): If true, no notification email is sent to watchershidden (boolean, optional): If true, no notification email or activity stream entry is generatedallowDuplicated (boolean, optional): Allow upload even if an attachment with the same filename already existsversionIfExists (boolean, optional): If true and an attachment with the same filename already exists, upload as a new version instead of failingDownload one or more attachments from a Confluence content (page). Returns the file content inline (base64 or text) — useful for inspecting a file or moving it elsewhere (e.g. re-uploading to a Jira issue). When filesystem downloads are enabled (see Attachment filesystem access), it can also save into the server-configured download directory.
Parameters:
contentId (string, required): ID of the content (page) whose attachment(s) to downloadfilename (string, optional): Exact filename of a single attachment to download. If omitted, all attachments on the content are downloaded.returnContent (none | base64 | text, optional): Whether to embed the file bytes in the response. Defaults to none.maxInlineBytes (number, optional): Maximum bytes to embed inline when returnContent is base64/text. Larger files are omitted from the inline content. Defaults to 1 MiB.save (boolean, optional): Save the attachment(s) into the server-configured download directory. Requires filesystem downloads to be enabled; existing files are never overwritten. (Only available when downloads are enabled.)saveName (string, optional): File name (no directories) to use when saving a single attachment; defaults to the attachment's own name. (Only available when downloads are enabled.)FAQs
Community-maintained MCP server for Atlassian Confluence Data Center. Not affiliated with Atlassian.
The npm package @atlassian-dc-mcp/confluence receives a total of 6,317 weekly downloads. As such, @atlassian-dc-mcp/confluence popularity was classified as popular.
We found that @atlassian-dc-mcp/confluence demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.