Our Jira Cloud integration through the Atlassian Rovo MCP Server (https://mcp.atlassian.com/v1/mcp/authv2) was working correctly for several weeks, then began failing with 401 errors on every Jira tool without any configuration changes on our side. The breakage appears to coincide with the "New toolsets available" rollout shown in our Atlassian Administration Rovo MCP settings.
Setup
Symptoms
- atlassianUserInfo works and returns correct user details
- getAccessibleAtlassianResources works and returns the site with these scopes: read:jira:agent-interface, search:jira:agent-interface, write:jira:agent-interface
- Every Jira data tool fails with the same error, including getVisibleJiraProjects, searchJiraIssuesUsingJql, and notably the new Rovo "search" tool itself:
401 Unauthorized; scope does not match
- Example correlation IDs: CIT:c3c9217b-409d-4ad2-84ab-44c34208319a (getAccessibleAtlassianResources, success), CIT:48f4a963-7cae-4a6a-ac38-04c28ebf97de (search tool, 401), CIT:a4c3f314-60ac-4b88-959f-58d0592a25f2 (401), CIT:823972b6-6cb1-4093-be24-2abe111965d9 (401)
What we have verified
- Org admin Rovo MCP settings show Permissions fully allowed: Read 8/8, Write 8/8, Search 3/3
- Domains allowlist is intact and unchanged from when the integration worked
- Revoked all prior Credential Manager grants at id.atlassian.com, deleted and recreated the MCP tool and connection in Copilot Studio, and completed a fresh consent (all 12 permissions accepted). Only one clean grant now exists, carrying only the agent-interface scopes listed above
- The consent screen shows Read, Search, and Write all selected
The apparent contradiction
The server issues a token whose scopes are exclusively the new agent-interface set, yet the tools on that same server, including the new search tool that should require exactly search:jira:agent-interface, reject the token with "scope does not match."