Skip to content

Atlassian MCP OAuth fails: unauthorized_client: redirect_uri is not registered (v2 endpoint) #4901

Description

@bart-rijnders

Title

Atlassian MCP OAuth fails: unauthorized_client: redirect_uri is not registered (v2 endpoint)

Affected version

1.0.86 (also observed on prior builds per related issues #4490, #2536)

Environment

  • OS: macOS
  • MCP server config (~/.copilot/mcp-config.json):
    {
      "mcpServers": {
        "atlassian": {
          "type": "http",
          "url": "https://mcp.atlassian.com/v2/mcp",
          "tools": ["*"]
        }
      }
    }

Description

When authenticating to the Atlassian MCP server (https://mcp.atlassian.com/v2/mcp), the OAuth flow fails on Atlassian's side with:

https://id.atlassian.com/error?error=unauthorized_client&error_description=redirect_uri%20is%20not%20registered%20for%20client:%20http://127.0.0.1:<random-port>/

The client_id used appears to differ from — or its declared metadata does not include — the dynamic loopback redirect_uri (http://127.0.0.1:<random-port>/) that Copilot CLI generates for each auth attempt.

By contrast, VS Code's Atlassian/Rovo Dev MCP integration succeeds using a Client ID Metadata Document (CIMD) approach: its client_id is a URL (https://vscode.dev/oauth/client-metadata.json) whose fetched JSON document lists VS Code's trusted redirect URIs. Atlassian's authorization server fetches this metadata document to validate the redirect_uri instead of requiring prior Dynamic Client Registration (DCR).

Local log excerpts (~/.copilot/logs/process-*.log) confirm the flow:

[ERROR] [rust:rmcp::transport::worker] worker quit with fatal: Transport channel closed, when Client(OAuthChallenge { www_authenticate_header: "...https://mcp.atlassian.com/.well-known/oauth-protected-resource/v2/mcp...", response: McpOAuthHttpResponse { status_code: 401, ... } })
[ERROR] Connecting to atlassian...
[ERROR] Opening browser for atlassian authentication...

No client-registration record is persisted locally (~/.copilot/mcp-oauth-config/ only contains a PKCE .verifier file), suggesting Copilot CLI attempts a fresh DCR (or static client_id) each time rather than caching/reusing a CIMD-style registration — and whatever it sends doesn't match what Atlassian's server expects.

Steps to reproduce

  1. Configure Atlassian HTTP MCP server pointing to https://mcp.atlassian.com/v2/mcp.
  2. Run /mcp → select atlassian → attempt to authenticate.
  3. Browser opens https://auth.atlassian.com/authorize?...&redirect_uri=http://127.0.0.1:<random-port>/....
  4. Atlassian immediately redirects to an error page: unauthorized_client: redirect_uri is not registered for client: http://127.0.0.1:<random-port>/.

Expected behavior

OAuth flow completes successfully, matching VS Code's behavior against the same Atlassian MCP endpoint.

Suggested fix

  • Adopt the same Client ID Metadata Document (CIMD) pattern VS Code uses: host/declare a client-metadata.json for Copilot CLI listing its expected loopback redirect URI pattern, and use that document's URL as client_id.
  • Alternatively, verify whether Atlassian's /register (DCR) endpoint is being called at all before /authorize, and confirm the registered redirect_uris match the one sent in the subsequent authorize request.

Related issues

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions