Skip to content

Atlassian MCP OAuth authentication broken in 1.0.80 (RFC 8414 §3.3 regression) #4490

Description

@ChandrasekarCK

Describe the bug

Authentication failed: MCPOAuthError: Incompatible authorization server: authorization server advertised an issuer that does not match the URL its metadata was discovered from (RFC 8414 §3.3); refusing to connect.

Affected version

1.0.80 (worked in 1.0.78)

Steps to reproduce the behavior

  1. Configure Atlassian HTTP MCP in  mcp-config.json  with type  http  and URL  https://mcp.atlassian.com/v1/mcp 
  2. Run  /mcp  → select Atlassian → attempt to authenticate
  3. Authentication fails immediately — browser OAuth redirect never launches

Expected behavior

OAuth browser redirect opens and authentication completes (worked in 1.0.78)

Additional context

Version: 1.0.80 (worked in 1.0.78)
OS: Windows 11
MCP Server: Atlassian HTTP MCP ( https://mcp.atlassian.com/v1/mcp )

Activity

  1. added
    area:authenticationLogin, OAuth, device auth, token management, and keychain integration
    area:mcpMCP server configuration, discovery, connectivity, OAuth, policy, and registry
    and removed on Aug 15, 2026
  2. patrickzel commented on Aug 16, 2026

    @patrickzel

    This is the same issue as in #4439.

  3. akevdmeer commented on Aug 18, 2026

    @akevdmeer

    This also breaks agentgateway's support for MCP OAuth with Entra ID. Please make this check configurable.

  4. akevdmeer commented on Aug 18, 2026

    @akevdmeer

    See modelcontextprotocol/typescript-sdk#2344 and its skipIssuerValidation option.

  5. pskoett commented on Aug 19, 2026

    @pskoett

    Same RFC 8414 §3.3 failure on SAP LeanIX MCP (Copilot 1.0.80). Unlike Atlassian, there is no working authv2 URL.

    Official / generic endpoint:

    • MCP: https://mcp.leanix.net/services/mcp-server/v1/mcp
    • advertised authorization_servers: https://mcp.leanix.net/services/mcp-server/v1
    • AS metadata issuer: https://mcp.leanix.net
  6. IrynaKulakova commented on Aug 24, 2026

    @IrynaKulakova

    Fixed in 1.0.81 (first build: cli-1.0.81-1).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:authenticationLogin, OAuth, device auth, token management, and keychain integrationarea:mcpMCP server configuration, discovery, connectivity, OAuth, policy, and registry

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions