Field-by-field comparison

Compare the evidence before choosing an MCP.

Each signal stays separate, missing facts remain visible, and the column order follows your selection.

MCPs in this comparison

Uncheck an MCP to remove it. Comparing two or three keeps each signal in its own row.

Open canonical comparison link

Comparable alternatives

Shown only when capability or industry context overlaps.

Side-by-side MCP evidence comparison
Evidence fieldMicrosoft 365 MCP ServerWatchlist candidateAtlassian Remote MCPMCP100 Selected
Task fit
Best for
  • Using Microsoft 365 email, calendar, OneDrive, documents, and personal productivity workflows through a self-hosted MCP
  • Organization Microsoft Graph workflows that need explicit Teams, meetings, SharePoint Sites and Lists, or user-management capabilities with deliberately narrowed access
  • Searching and summarizing Jira and Confluence knowledge
  • Creating and updating Jira work items or Confluence content with approval
  • Connecting supported AI clients to Atlassian Cloud without self-hosting a server
Not ideal for
  • A SharePoint-only deployment or a narrowly scoped integration when the broad configurable Graph surface is unnecessary
  • Unsupervised access to sensitive mail, files, meetings, tenant data, or write operations
  • Atlassian Server or Data Center deployments
  • Organizations that do not allow enterprise content to pass through an external AI client
  • Headless use when organization administrators do not permit API-token authentication
Avoid when
  • You cannot use a dedicated Microsoft identity, narrow allowed scopes/tools, and review the permissions required for the selected Microsoft 365 workload
  • You need a fully reviewed universal tool contract or verified maintainer-transfer and rollback evidence before deployment
  • The AI client is not approved for the Jira, Confluence, Bitbucket, Compass, or connected third-party data involved
  • Existing Atlassian user permissions are too broad for agent use
  • Write and bulk actions cannot require review
Provenance
Provenance details

Community implementation

Softeria · Publisher source ↗

First-party MCP

Atlassian · Publisher source ↗

Maintenance
Maintenance details

Repo: Aug 24, 2026

Package: Aug 24, 2026

Repo: Not documented

Package: Not documented

Popularity evidence
GitHub stars

958

GitHub stars · checked 2026-09-08

Not documented
Package downloads / 30 days

173,619

package downloads / 30 days · checked 2026-09-08

No reliable download data
External adoption evidence
  • GitHub: repository stars: 932Exact attributable signal.GitHub: repository stars · Admission snapshot · checked 2026-08-24T12:00:00.000ZEvidence source ↗
  • npm: package downloads: 171,749Exact attributable signal.npm: package downloads · Rolling 30 days · checked 2026-08-24T12:00:00.000ZEvidence source ↗
Not documented
Client coverage
Client coverage detailsNot documented
Claude CodeStreamable HTTP
Claude DesktopStreamable HTTP
CodexStreamable HTTP
VS CodeStreamable HTTP
CursorStreamable HTTP
OpenCodeStreamable HTTP
Client coverage noteLocal stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server.
Access and data
AuthenticationThe documented options include Device Code Flow for local stdio, OAuth Authorization Code Flow for HTTP, a caller-supplied MS365_MCP_OAUTH_TOKEN, and a custom Microsoft Entra application for organization or production deployment. Use a dedicated identity, restrict consented Graph scopes, remove the MCP entry and local credentials when access is no longer needed, and revoke Microsoft authorization or tokens through the applicable account or Entra controls.OAuth 2.1 browser authorization is the default and recommended method. Admin-enabled, scoped personal API tokens support headless use and are required for Jira Service Management and Bitbucket Cloud tools; Compass tools require OAuth.
CostThe MIT-licensed npm package has no separate package purchase price documented. Access still depends on the Microsoft account, service access, licenses, tenant permissions, and admin consent required by the chosen workload; self-hosted HTTP deployments can also incur normal hosting, container, and secret-management costs.The core connection has no separately stated MCP fee. Users need applicable Atlassian Cloud products and an AI client. Beta tools are currently free; Atlassian says some may later be billed in Rovo credits with notice, and Teamwork Graph calls are expected to consume credits at general availability.
PermissionsThe MCP can read and write Microsoft Graph resources including email, calendar, OneDrive files, SharePoint Sites and Lists, Teams/chats/meetings, contacts, users, OneNote, Planner, To Do, and Excel. Organization-mode SharePoint can request broad Sites.Read.All, Sites.ReadWrite.All, and Sites.Manage.All scopes; use --allowed-scopes, --enabled-tools, --read-only, and Sites.Selected where the documented operation supports them.Tools are grouped by product and read, write, or search intent. Organization admins grant or revoke permission groups, and calls also honor the connected user's Jira, Confluence, Jira Service Management, Bitbucket, Compass, project, space, IP-allowlist, and OAuth or API-token scopes.
Data handlingThe local MCP handles Microsoft Graph request and response data. Documented local MSAL token caching is encrypted, while the headless fallback still depends on directory access controls. The HTTP deployment documents stateless per-request bearer-token Graph requests. Structured audit logging is enabled for Graph-reaching tool calls and can include principals, tool names, outcomes, resource identifiers, and recipient counts or domains; response bodies are not recorded by that structured log, and separate operational logging can record tool parameters. Token and PII redaction is documented as configurable rather than an absolute data-boundary guarantee.The Atlassian-hosted server retrieves and returns authorized Atlassian Cloud content to the external MCP client. Teamwork Graph tools can aggregate relationships across Atlassian products and connected third-party apps and may use AI processing. Traffic uses HTTPS/TLS, and Atlassian records tool-use events in the organization audit log.
Limitations
Tradeoffs
  • Personal and organization modes provide broad Microsoft Graph coverage, but the exposed surface changes with org mode, presets, enabled tools, allowed scopes, authentication mode, and read-only settings.
  • Sites.Selected and tool/scope filtering can reduce direct SharePoint access, while tenant-wide SharePoint discovery requires broader scopes.
  • A pinned self-hosted npm install avoids a moving latest tag, but full maintainer-transfer and rollback evidence has not been verified.
  • The hosted service honors existing product permissions and provides audit events, but it can expose broad enterprise knowledge to the connected AI client.
  • OAuth 2.1 is recommended; API tokens support headless workflows but require admin enablement and careful scope management.
  • Some Teamwork Graph and search tools are Beta and may later consume paid Rovo credits.
  • Rovo MCP v2 adds additional supported Atlassian apps through a documented upgrade path; v1 remains documented and is not described as shut down.
Risk contextThis broad Microsoft Graph MCP can expose sensitive business email, files, SharePoint content, Teams/chats/meetings, contacts, and tenant information, and it includes material write and delete operations. Destructive-operation confirmation is documented as off by default; default organization-mode SharePoint permissions can be broad, and HTTP Dynamic Client Registration is enabled by default unless disabled. Use read-only mode, presets/tool filtering, allowed scopes, Sites.Selected when applicable, dedicated identities, and explicit review before enabling writes or tenant-wide discovery. GHSA-9w34-3f56-vwmh affected versions through 0.136.0; reviewed version 0.146.1 is above the documented 0.137.0 fixed version. This patched advisory is not a general security certification.The integration can read and modify enterprise work and knowledge across several Atlassian products. Approve client domains, use least privilege, restrict permission groups and token scopes, retain write confirmation, review audit logs, and evaluate the external AI client's data policy. This review does not claim MCP100 execution testing.
Evidence date
Editorial review2026-08-24T12:00:00.000Z2026-09-05
Candidate evidence2026-08-24T12:00:00.000Z2026-09-05T00:00:00.000Z

Popularity, maintenance, fit, permissions, and client support are independent evidence fields.

Read the evidence method →
Compare MCPs | MCP100 Index