Administration & Configuration
Managing Endpoint Approvals
This page explains the endpoint approvals (network approvals, egress approvals, approved domains): why every LLM address needs one, why they count per product, and how you approve, check, re-approve, replace and revoke addresses on the Endpoint approvals page.
What this does
AnyLLM reaches no external address that you have not approved yourself — the well-known providers included. There is no pre-approved provider list: the section Reachable without approval at the bottom of the page is empty by design and reads No LLM endpoint is pre-approved — every endpoint you configure needs your approval, the well-known providers included. and The app manifest declares no external address at all. Every destination — LLM endpoints and your search service alike — is reachable only after you approve it here. That way it is visible and provable at any time where requests can flow.
Approvals are granted through Atlassian's confirmation dialog. Normally you do not need this page to create them: saving a connection (or a search service) with a new address opens the dialog automatically. You need the page to grant the approval in the other product, to check the state, and to replace, revoke or re-approve addresses.
Who can do this
Endpoint approvals are meant to be managed by Jira administrators:
- On the Jira settings page all actions are available.
- On the Confluence settings page the app checks whether the signed-in person also has Jira administration. Without it, the page shows Only Jira administrators may change endpoint approvals. Your account has no Jira admin permission, so the actions on this page are disabled. — the form, the buttons in the tables and the Approve now button of the pending notice are disabled.
- If that check itself fails, the page shows Your Jira admin permission could not be verified from Confluence — the actions stay enabled. Note that endpoint approvals are meant to be managed by Jira administrators. and the actions stay usable.
Independently of this, Atlassian's confirmation dialog requires administration of the product in which the settings page is open.
Before you start
- The address is an
httpsaddress. Only scheme, host and port matter —https://llm.my-company.com/v1andhttps://llm.my-company.comare the same approval. - Open Settings → Endpoint approvals in the product for which you want to grant, check or change approvals (route: Opening the Settings and Initial Setup).
How approvals work per product
AnyLLM is one installation for Jira and Confluence, and the list of approved domains is kept once for the whole installation — it looks the same on both settings pages. The administrator's consent in Atlassian's dialog, however, counts per product: an address approved on the Jira page can still be blocked for requests from Confluence until the dialog has been confirmed there too. The lead text of the page says it in one sentence: Approvals apply per product: grant them once in Jira and once in Confluence.
The table Approval status per product shows both states side by side, with the columns Domain, Jira and Confluence:
| Cell | Meaning |
|---|---|
| approved | the dialog was confirmed in that product |
| not approved | no consent recorded for that product |
| blocked {date} | in that product a request recently failed because the approval is missing — the block is newer than the last approval there |
In the column of the product whose page you have open, a cell that needs action carries the button Approve now; it opens Atlassian's dialog for this product. In the other product's column it reads Approve in Jira ↗ or Approve in Confluence ↗ and takes you to that product's settings page. Below the table: Approvals for {p} can only be granted on the {p} admin page. and the link Open approvals in {p} ↗. The table also lists domains that were only ever approved in the other product.
Approving an address
Purpose — allow the installation to talk to an address that no saved connection uses yet, for example before you move a server. Addresses of saved connections and of the search service are approved when you save them — you do not need to add them here.
Steps
- Under Approve an endpoint URL, enter the address in the field Endpoint URL (https), e.g.
https://llm.my-company.com. The hint below the field reads Only scheme, host and port matter — the path is ignored. Approving opens an Atlassian confirmation dialog. - Click Approve now (it shows Approving … while working).
- Confirm Atlassian's dialog AnyLLM: self-hosted LLM endpoints (…) — it lists all domains of the app's approval group, not only the new one.
Expected result — the message Endpoint domains approved.; the address appears in the table Approved endpoint URLs and as approved in this product's column of Approval status per product.
Notes
- At most 10 domains can be approved per installation; the header of the list shows {count} of 10 domains. When the limit is reached, the page says The limit of 10 approved domains is reached. Revoke one below to approve another — replacing an existing domain still works. and Approve now is disabled; an attempt to exceed it reports Atlassian allows at most 10 approved domains per installation. Revoke one you no longer need, then try again.
- If the dialog is declined, the page reports Approval was declined or failed — these domains stay blocked. Your configuration is unchanged.
Checking approvals
The table Approved endpoint URLs ({count} of 10 domains) has the columns Domain, Status and Actions and shows one status per entry:
| Status | Meaning |
|---|---|
| used by a saved connection | a saved connection or the search service points to this address |
| no connection uses this — safe to revoke | nothing uses the address — for example approved manually and never referenced |
If nothing is approved yet, the table says Nothing approved yet. Only the built-in provider domains below are reachable. — and because the built-in list is empty, nothing is reachable at all.
Approval status per product (see above) tells you where the consent is still missing. A cell blocked {date} clears in only two ways: a successful Test connection on the Connections page in that product, or Re-approve in this product / Approve now there — the new approval is then newer than the block. Ordinary chat requests do not clear it, even when they succeed.
Re-approving in this product
Purpose — renew the consent for the product you are in without changing the list. Use it when requests are blocked in a product although the address appears approved — typically because the consent was never given in this product, for example after a reinstallation.
Where you find it
- as a warning at the top of the page, shown automatically when a block is newer than the product's approval: Requests to {host} were blocked in {p} although the address appears approved. The domain list is shown installation-wide, but the admin consent counts per product — it may never have been granted in {p}. "Re-approve in this product" opens the Atlassian confirmation dialog here. with the button Re-approve in this product;
- as Approve now in a cell of the Approval status per product table;
- as a link line under the form, shown whenever at least one domain is approved: Requests blocked although the address appears approved here? Then the consent may be missing for this product: Re-approve in this product.
Steps
- Click Re-approve in this product. The page shows Requesting approval ….
- Confirm Atlassian's dialog.
Expected result — Approval confirmed for this product.; a blocked cell of this product disappears. If the dialog is declined: Re-approving failed or was declined — nothing changed.
Replacing or revoking an approval
Replace — for moving a server without a gap:
- Click Replace in the row. The form title changes to Replace endpoint URL and the field is pre-filled; Cancel aborts.
- Enter the new address and click Approve now; confirm the dialog.
The new address is approved, and the old one is removed from the list afterwards. Replacing also works when the limit of 10 domains is reached. Then switch the connection over on Connections and repeat the consent in the other product.
Revoke — for addresses that are no longer needed:
- Click Revoke in the row. The button changes to Really revoke? — or, if a saved connection uses the address, to Revoke anyway — a connection breaks.
- Click it again to confirm. The page shows Revoking ….
Expected result — Approval revoked.; the row disappears. If it fails: Revoking failed — the approval is still in place.
⚠️ Warning: After a revocation all requests to this address fail immediately, in both products. The connection and its key stay saved and work again after a new approval.
Automatic revocation after saving connections
You rarely need Revoke for a move: after every successful Save connections (and after Save on Modules or General, which saves the same configuration) the app automatically revokes approved addresses that no saved connection and no search service uses any more. If the server rejects the save, approvals granted during that save are withdrawn again. The usual sequence is therefore: change the endpoint of the connection, save, confirm the dialog — and then grant the consent in the other product.
The pending-approval notice
If saved addresses lack an approval in the current product — typically after importing a configuration — a yellow notice appears above the tabs on every settings page: These endpoint domains are configured but not yet approved for this installation: … Until you approve them, requests to them are blocked — this typically happens after importing a configuration. Click Approve now (then Approving …) and confirm the dialog. Result: Endpoint domains approved.; if declined: Approval was declined or failed — these domains stay blocked. Your configuration is unchanged. The notice requests the approval for the saved addresses without touching the configuration.
When approvals are unavailable
If Atlassian's approval function is not active for your site, the section Approved endpoint URLs is replaced by Customer-managed egress is not available for this installation — these domains stay blocked until it is enabled., and no pending notice appears. Saving connections then reports Saved, but the network approval could not be requested — customer-managed egress is not available for this installation. Calls to your self-hosted endpoint will be blocked until it is enabled. in red although the configuration was saved. In this state every address stays blocked and the chat cannot be used. Contact your vendor (maplee).
Common problems
| Message | Cause | Solution |
|---|---|---|
| Not a valid URL. | typo or incomplete address | enter the full address; https:// is prepended if you leave it out |
| Only https is allowed — API keys travel on this connection. | http:// entered | use https |
| This domain is already approved. | the entry already exists | nothing to do — check the Approval status per product table instead |
| This domain is already reachable without approval. | the address is on the app's built-in list of pre-approved domains | does not occur in the shipped version, because that list is empty |
| Atlassian allows at most 10 approved domains per installation. … | limit reached | revoke an unused address or use Replace |
| Approval was declined or failed — these domains stay blocked. Your configuration is unchanged. | dialog declined or failed | try again and confirm the dialog |
| Customer-managed egress is not available for this installation — … | Atlassian's approval function is missing | contact your vendor (maplee) |
| The chat says The endpoint {host} is not approved for {p} yet — endpoint approvals apply per product. … | consent missing in that product | open the settings in that product and click Approve now |
| An address shows approved but requests are blocked | consent never given in this product | Re-approve in this product |
| blocked {date} does not disappear after a successful chat | chat requests never clear the entry | run Test connection in that product or re-approve |
| The actions on the Confluence page are disabled | no Jira administration | ask a Jira administrator |
| Revoking failed — the approval is still in place. | Atlassian rejected the revocation | reload the page and try again |
Related topics
Rendered from the app’s own interface with sample data; the Jira/Confluence frame around it is not shown.
Documentation baseline: app version 0.2.0 · 2026-08-30