
Or Weis
Authentication vs. Authorization in MCP: What Atlassian Rovo Shows About OAuth, API Tokens, and Tool Calls
Atlassian Rovo's MCP server makes a precise security tradeoff visible: OAuth 2.1 handles identity and consent; API tokens handle non-interactive automation. Neither governs what agents can actually do at tool-call time. Here is what that gap looks like in practice.













