Jira MCP 401 Unauthorized with a scoped (granular) Atlassian API token
Fixes the Atlassian MCP server 401ing on Jira Cloud when using a granular scoped API token. Use when the token is fresh but every Jira call 401s on the classic URL. Not for expired tokens or OAuth flows.
Jira MCP 401 Unauthorized with a scoped (granular) Atlassian API token
TL;DR: Point JIRA_URL at the scoped-token host: https://api.atlassian.com/ex/jira/YOUR-CLOUD-ID instead of https://YOUR-SITE.atlassian.net. Granular scoped tokens are rejected on the classic site URL; that path only accepts full API tokens. Find your cloud ID in the Atlassian admin or via the tenancy API, then restart the server.
The error
401 Unauthorized on Jira API calls through the MCP server with a valid granular scoped API token (classic YOUR-SITE.atlassian.net URL)Fix it
- Confirm your token is a granular scoped token, not a classic API token.
Expected: The token was created under the granular scopes screen.
- Find your cloud ID (Atlassian admin, or the accessible-resources API).
Expected: You have the cloud-id value.
- Set JIRA_URL to https://api.atlassian.com/ex/jira/YOUR-CLOUD-ID in the server env.
Expected: The env value uses the ex/jira path.
- Restart the MCP client and retry a Jira call.
Expected: Calls return 200 instead of 401.
When this applies
Jira Cloud calls through mcp-atlassian 401 with a fresh granular scoped token on the classic atlassian.net URL.
When this does NOT apply
Classic API tokens work on the classic URL; if yours 401s there it is expired or wrong. OAuth setups use a different auth path.
Tool compatibility
sooperset/mcp-atlassian, Jira Cloud with granular API tokens
Also seen as
- Jira MCP scoped token unauthorized
- granular API token 401 Jira MCP
- api.atlassian.com ex jira cloud-id
Why it happens
Atlassian validates granular scoped tokens only on the api.atlassian.com/ex/jira/YOUR-CLOUD-ID host. The classic site host does not know those tokens, so it 401s even though the token is valid.
Edge cases
- Confluence needs the parallel ex/confluence host with its own cloud ID.
- The cloud ID differs per site; multi-site setups need per-site URLs.
- Rotating the token does not help; the URL is the problem.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.