github / github/copilot-cli

Atlassian MCP server auto-connects without completing OAuth flow (Sign in button disappears)

Open
#4,086 1 comment 0 reactions 0 assignees View on GitHub
area:authentication area:mcp triaged
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

## Description

The Atlassian MCP server (https://mcp.atlassian.com/v1/mcp) shows a green checkmark (connected) in MCP Settings without completing the OAuth browser flow. No atlassian-* tools are loaded in sessions.

## Expected behavior

Clicking 'Sign in' or toggling the server on should open a browser for OAuth authorization (like LeanIX and Lucid do).

## Actual behavior

- The 'Sign in' button flashes briefly and disappears
- Green checkmark appears immediately without browser redirect
- No OAuth token is saved (no .tokens.json file in ~/.copilot/mcp-oauth-config/)
- Sessions do not have access to any Atlassian tools

## Steps to reproduce

1. Add Atlassian MCP to a plugin .mcp.json:
```
"atlassian": { "type": "http", "url": "https://mcp.atlassian.com/v1/mcp" }
```
2. Open MCP Settings
3. Toggle Atlassian on
4. Observe: green checkmark appears without browser opening

## Root cause hypothesis

Atlassian MCP endpoint responds to discovery/health-check requests with HTTP 200 without requiring authentication. The app interprets this as 'connected' and skips the OAuth flow. Other MCP servers (LeanIX, Lucid) correctly require auth on these requests.

## Workaround

Using Atlassian REST API directly with personal API tokens.

## Environment

- Copilot CLI version: 1.0.69
- OS: Windows 11
- Plugin: custom plugin with Atlassian MCP config
- Other MCP servers working correctly: LeanIX, Lucid, QMD (local)

Contributor guide

Open the contributing guide

Research direction

Start with the MCP Settings flow and the plugin .mcp.json configuration, then reproduce the Atlassian endpoint behavior described in the issue. Compare its discovery and authentication handling with LeanIX and Lucid; done means Sign in opens the OAuth browser flow, a token is saved, and Atlassian tools load in sessions.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, cli
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.