Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

Atlassian MCP OAuth fails: unauthorized_client: redirect_uri is not registered (v2 endpoint)

Ouverte
#4,901 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

Évaluation

Difficulté
4/5
Temps estimé
3-5 jours
Accessibilité débutants
45/100
Type d'issue
Bug
Clarté
Plutôt claire
Activité
Active
Domaine
api, authentication, cli

Piste de recherche

Reproduce the flow using ~/.copilot/mcp-config.json and the Atlassian v2 endpoint, then inspect ~/.copilot/logs/process-*.log and ~/.copilot/mcp-oauth-config/. Compare the authorization request with the expected DCR or CIMD behavior. Done means authentication completes successfully against the Atlassian MCP server without the redirect_uri error.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

triage

Title

Atlassian MCP OAuth fails: unauthorized_client: redirect_uri is not registered (v2 endpoint)

Affected version

1.0.86 (also observed on prior builds per related issues #4490, #2536)

Environment

  • OS: macOS
  • MCP server config (~/.copilot/mcp-config.json):
    {
      "mcpServers": {
        "atlassian": {
          "type": "http",
          "url": "https://mcp.atlassian.com/v2/mcp",
          "tools": ["*"]
        }
      }
    }
    

Description

When authenticating to the Atlassian MCP server (https://mcp.atlassian.com/v2/mcp), the OAuth flow fails on Atlassian's side with:

https://id.atlassian.com/error?error=unauthorized_client&error_description=redirect_uri%20is%20not%20registered%20for%20client:%20http://127.0.0.1:<random-port>/

The client_id used appears to differ from — or its declared metadata does not include — the dynamic loopback redirect_uri (http://127.0.0.1:<random-port>/) that Copilot CLI generates for each auth attempt.

By contrast, VS Code's Atlassian/Rovo Dev MCP integration succeeds using a Client ID Metadata Document (CIMD) approach: its client_id is a URL (https://vscode.dev/oauth/client-metadata.json) whose fetched JSON document lists VS Code's trusted redirect URIs. Atlassian's authorization server fetches this metadata document to validate the redirect_uri instead of requiring prior Dynamic Client Registration (DCR).

Local log excerpts (~/.copilot/logs/process-*.log) confirm the flow:

[ERROR] [rust:rmcp::transport::worker] worker quit with fatal: Transport channel closed, when Client(OAuthChallenge { www_authenticate_header: "...https://mcp.atlassian.com/.well-known/oauth-protected-resource/v2/mcp...", response: McpOAuthHttpResponse { status_code: 401, ... } })
[ERROR] Connecting to atlassian...
[ERROR] Opening browser for atlassian authentication...

No client-registration record is persisted locally (~/.copilot/mcp-oauth-config/ only contains a PKCE .verifier file), suggesting Copilot CLI attempts a fresh DCR (or static client_id) each time rather than caching/reusing a CIMD-style registration — and whatever it sends doesn't match what Atlassian's server expects.

Steps to reproduce

  1. Configure Atlassian HTTP MCP server pointing to https://mcp.atlassian.com/v2/mcp.
  2. Run /mcp → select atlassian → attempt to authenticate.
  3. Browser opens https://auth.atlassian.com/authorize?...&redirect_uri=http://127.0.0.1:<random-port>/....
  4. Atlassian immediately redirects to an error page: unauthorized_client: redirect_uri is not registered for client: http://127.0.0.1:<random-port>/.

Expected behavior

OAuth flow completes successfully, matching VS Code's behavior against the same Atlassian MCP endpoint.

Suggested fix

  • Adopt the same Client ID Metadata Document (CIMD) pattern VS Code uses: host/declare a client-metadata.json for Copilot CLI listing its expected loopback redirect URI pattern, and use that document's URL as client_id.
  • Alternatively, verify whether Atlassian's /register (DCR) endpoint is being called at all before /authorize, and confirm the registered redirect_uris match the one sent in the subsequent authorize request.

Related issues

  • github/copilot-cli#4490 (RFC 8414 issuer mismatch, v1.0.80)
  • github/copilot-cli#2536 (re-auth required on every launch)
Langage dominant
Shell
Étoiles
11.2k
Forks
1.9k
Merge moyen
14 h 16 min
PR mergées (30 j)
6

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de github/copilot-cli

Toutes les issues de github/copilot-cli

Issues similaires

Plus d'issues Shell/Bash

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.