We're connecting an internal AI agent to Rovo MCP via Okta Cross-App Access(XAA) / ID-JAG. Okta mints the ID-JAG correctly (audience`https://auth.atlassian.com`, resource `https://mcp.atlassian.com/v2/mcp`,`oauth-id-jag+jwt` type). We're stuck redeeming it for the Atlassian accesstoken Rovo MCP actually requires.
Both grant types that server's metadata advertises fail for this client:
- `jwt-bearer` → `invalid_client: grant_type is not enabled for client`- `token-exchange` → `invalid_request: subject_token_type is not supported` (tried `id-jag`, `jwt`, `id_token`, `access_token`)
**Question:** which grant type is our client meant to use to redeem an ID-JAG for a Rovo MCP access token, and does our client need to be explicitly enabled/enrolled for it (e.g. the Enterprise-ManagedAuthorization for Rovo MCP beta)?