Administration & Configuration

Managing Endpoint Approvals

This page explains the endpoint approvals (network approvals, egress approvals, approved domains): why every LLM address needs one, why they count per product, and how you approve, check, re-approve, replace and revoke addresses on the Endpoint approvals page.

What this does

AnyLLM reaches no external address that you have not approved yourself — the well-known providers included. There is no pre-approved provider list: the section Reachable without approval at the bottom of the page is empty by design and reads No LLM endpoint is pre-approved — every endpoint you configure needs your approval, the well-known providers included. and The app manifest declares no external address at all. Every destination — LLM endpoints and your search service alike — is reachable only after you approve it here. That way it is visible and provable at any time where requests can flow.

Approvals are granted through Atlassian's confirmation dialog. Normally you do not need this page to create them: saving a connection (or a search service) with a new address opens the dialog automatically. You need the page to grant the approval in the other product, to check the state, and to replace, revoke or re-approve addresses.

Who can do this

Endpoint approvals are meant to be managed by Jira administrators:

  • On the Jira settings page all actions are available.
  • On the Confluence settings page the app checks whether the signed-in person also has Jira administration. Without it, the page shows Only Jira administrators may change endpoint approvals. Your account has no Jira admin permission, so the actions on this page are disabled. — the form, the buttons in the tables and the Approve now button of the pending notice are disabled.
  • If that check itself fails, the page shows Your Jira admin permission could not be verified from Confluence — the actions stay enabled. Note that endpoint approvals are meant to be managed by Jira administrators. and the actions stay usable.

Independently of this, Atlassian's confirmation dialog requires administration of the product in which the settings page is open.

Before you start

  • The address is an https address. Only scheme, host and port matter — https://llm.my-company.com/v1 and https://llm.my-company.com are the same approval.
  • Open Settings → Endpoint approvals in the product for which you want to grant, check or change approvals (route: Opening the Settings and Initial Setup).

How approvals work per product

AnyLLM is one installation for Jira and Confluence, and the list of approved domains is kept once for the whole installation — it looks the same on both settings pages. The administrator's consent in Atlassian's dialog, however, counts per product: an address approved on the Jira page can still be blocked for requests from Confluence until the dialog has been confirmed there too. The lead text of the page says it in one sentence: Approvals apply per product: grant them once in Jira and once in Confluence.

The table Approval status per product shows both states side by side, with the columns Domain, Jira and Confluence:

CellMeaning
approvedthe dialog was confirmed in that product
not approvedno consent recorded for that product
blocked {date}in that product a request recently failed because the approval is missing — the block is newer than the last approval there

In the column of the product whose page you have open, a cell that needs action carries the button Approve now; it opens Atlassian's dialog for this product. In the other product's column it reads Approve in Jira ↗ or Approve in Confluence ↗ and takes you to that product's settings page. Below the table: Approvals for {p} can only be granted on the {p} admin page. and the link Open approvals in {p} ↗. The table also lists domains that were only ever approved in the other product.

Approval status per product: each domain with its state in Jira and Confluence; missing approvals are granted in the other product's admin page.

Approving an address

Purpose — allow the installation to talk to an address that no saved connection uses yet, for example before you move a server. Addresses of saved connections and of the search service are approved when you save them — you do not need to add them here.

Steps

  1. Under Approve an endpoint URL, enter the address in the field Endpoint URL (https), e.g. https://llm.my-company.com. The hint below the field reads Only scheme, host and port matter — the path is ignored. Approving opens an Atlassian confirmation dialog.
  2. Click Approve now (it shows Approving … while working).
  3. Confirm Atlassian's dialog AnyLLM: self-hosted LLM endpoints (…) — it lists all domains of the app's approval group, not only the new one.
Approve an endpoint URL: enter the https address and click Approve now — only scheme, host and port matter; Atlassian shows a confirmation dialog.

Expected result — the message Endpoint domains approved.; the address appears in the table Approved endpoint URLs and as approved in this product's column of Approval status per product.

Notes

  • At most 10 domains can be approved per installation; the header of the list shows {count} of 10 domains. When the limit is reached, the page says The limit of 10 approved domains is reached. Revoke one below to approve another — replacing an existing domain still works. and Approve now is disabled; an attempt to exceed it reports Atlassian allows at most 10 approved domains per installation. Revoke one you no longer need, then try again.
  • If the dialog is declined, the page reports Approval was declined or failed — these domains stay blocked. Your configuration is unchanged.

Checking approvals

The table Approved endpoint URLs ({count} of 10 domains) has the columns Domain, Status and Actions and shows one status per entry:

StatusMeaning
used by a saved connectiona saved connection or the search service points to this address
no connection uses this — safe to revokenothing uses the address — for example approved manually and never referenced

If nothing is approved yet, the table says Nothing approved yet. Only the built-in provider domains below are reachable. — and because the built-in list is empty, nothing is reachable at all.

Approval status per product (see above) tells you where the consent is still missing. A cell blocked {date} clears in only two ways: a successful Test connection on the Connections page in that product, or Re-approve in this product / Approve now there — the new approval is then newer than the block. Ordinary chat requests do not clear it, even when they succeed.

Approved endpoint URLs: every approved domain with its status and the actions Replace and Revoke; the counter shows how many of the 10 slots are used.

Re-approving in this product

Purpose — renew the consent for the product you are in without changing the list. Use it when requests are blocked in a product although the address appears approved — typically because the consent was never given in this product, for example after a reinstallation.

Where you find it

  • as a warning at the top of the page, shown automatically when a block is newer than the product's approval: Requests to {host} were blocked in {p} although the address appears approved. The domain list is shown installation-wide, but the admin consent counts per product — it may never have been granted in {p}. "Re-approve in this product" opens the Atlassian confirmation dialog here. with the button Re-approve in this product;
  • as Approve now in a cell of the Approval status per product table;
  • as a link line under the form, shown whenever at least one domain is approved: Requests blocked although the address appears approved here? Then the consent may be missing for this product: Re-approve in this product.

Steps

  1. Click Re-approve in this product. The page shows Requesting approval ….
  2. Confirm Atlassian's dialog.

Expected resultApproval confirmed for this product.; a blocked cell of this product disappears. If the dialog is declined: Re-approving failed or was declined — nothing changed.

Replacing or revoking an approval

Replace — for moving a server without a gap:

  1. Click Replace in the row. The form title changes to Replace endpoint URL and the field is pre-filled; Cancel aborts.
  2. Enter the new address and click Approve now; confirm the dialog.

The new address is approved, and the old one is removed from the list afterwards. Replacing also works when the limit of 10 domains is reached. Then switch the connection over on Connections and repeat the consent in the other product.

Revoke — for addresses that are no longer needed:

  1. Click Revoke in the row. The button changes to Really revoke? — or, if a saved connection uses the address, to Revoke anyway — a connection breaks.
  2. Click it again to confirm. The page shows Revoking ….

Expected resultApproval revoked.; the row disappears. If it fails: Revoking failed — the approval is still in place.

⚠️ Warning: After a revocation all requests to this address fail immediately, in both products. The connection and its key stay saved and work again after a new approval.

Automatic revocation after saving connections

You rarely need Revoke for a move: after every successful Save connections (and after Save on Modules or General, which saves the same configuration) the app automatically revokes approved addresses that no saved connection and no search service uses any more. If the server rejects the save, approvals granted during that save are withdrawn again. The usual sequence is therefore: change the endpoint of the connection, save, confirm the dialog — and then grant the consent in the other product.

The pending-approval notice

If saved addresses lack an approval in the current product — typically after importing a configuration — a yellow notice appears above the tabs on every settings page: These endpoint domains are configured but not yet approved for this installation: … Until you approve them, requests to them are blocked — this typically happens after importing a configuration. Click Approve now (then Approving …) and confirm the dialog. Result: Endpoint domains approved.; if declined: Approval was declined or failed — these domains stay blocked. Your configuration is unchanged. The notice requests the approval for the saved addresses without touching the configuration.

Pending-approval notice on the settings home: configured endpoint domains not yet approved for this installation, with the Approve now button.

When approvals are unavailable

If Atlassian's approval function is not active for your site, the section Approved endpoint URLs is replaced by Customer-managed egress is not available for this installation — these domains stay blocked until it is enabled., and no pending notice appears. Saving connections then reports Saved, but the network approval could not be requested — customer-managed egress is not available for this installation. Calls to your self-hosted endpoint will be blocked until it is enabled. in red although the configuration was saved. In this state every address stays blocked and the chat cannot be used. Contact your vendor (maplee).

Common problems

MessageCauseSolution
Not a valid URL.typo or incomplete addressenter the full address; https:// is prepended if you leave it out
Only https is allowed — API keys travel on this connection.http:// entereduse https
This domain is already approved.the entry already existsnothing to do — check the Approval status per product table instead
This domain is already reachable without approval.the address is on the app's built-in list of pre-approved domainsdoes not occur in the shipped version, because that list is empty
Atlassian allows at most 10 approved domains per installation. …limit reachedrevoke an unused address or use Replace
Approval was declined or failed — these domains stay blocked. Your configuration is unchanged.dialog declined or failedtry again and confirm the dialog
Customer-managed egress is not available for this installation — …Atlassian's approval function is missingcontact your vendor (maplee)
The chat says The endpoint {host} is not approved for {p} yet — endpoint approvals apply per product. …consent missing in that productopen the settings in that product and click Approve now
An address shows approved but requests are blockedconsent never given in this productRe-approve in this product
blocked {date} does not disappear after a successful chatchat requests never clear the entryrun Test connection in that product or re-approve
The actions on the Confluence page are disabledno Jira administrationask a Jira administrator
Revoking failed — the approval is still in place.Atlassian rejected the revocationreload the page and try again

Rendered from the app’s own interface with sample data; the Jira/Confluence frame around it is not shown.

Documentation baseline: app version 0.2.0 · 2026-08-30