# Jira MCP 401 Unauthorized with a scoped (granular) Atlassian API token

**TL;DR:** Point JIRA_URL at the scoped-token host: https://api.atlassian.com/ex/jira/YOUR-CLOUD-ID instead of https://YOUR-SITE.atlassian.net. Granular scoped tokens are rejected on the classic site URL; that path only accepts full API tokens. Find your cloud ID in the Atlassian admin or via the tenancy API, then restart the server.

## The error

```
401 Unauthorized on Jira API calls through the MCP server with a valid granular scoped API token (classic YOUR-SITE.atlassian.net URL)
```

## Fix it

1. Confirm your token is a granular scoped token, not a classic API token.
   Expected: The token was created under the granular scopes screen.
2. Find your cloud ID (Atlassian admin, or the accessible-resources API).
   Expected: You have the cloud-id value.
3. Set JIRA_URL to https://api.atlassian.com/ex/jira/YOUR-CLOUD-ID in the server env.
   Expected: The env value uses the ex/jira path.
4. Restart the MCP client and retry a Jira call.
   Expected: Calls return 200 instead of 401.

## When this applies

Jira Cloud calls through mcp-atlassian 401 with a fresh granular scoped token on the classic atlassian.net URL.

## When this does NOT apply

Classic API tokens work on the classic URL; if yours 401s there it is expired or wrong. OAuth setups use a different auth path.

## Tool compatibility

sooperset/mcp-atlassian, Jira Cloud with granular API tokens

## Also seen as

- Jira MCP scoped token unauthorized
- granular API token 401 Jira MCP
- api.atlassian.com ex jira cloud-id

## Why it happens

Atlassian validates granular scoped tokens only on the api.atlassian.com/ex/jira/YOUR-CLOUD-ID host. The classic site host does not know those tokens, so it 401s even though the token is valid.

## Edge cases

- Confluence needs the parallel ex/confluence host with its own cloud ID.
- The cloud ID differs per site; multi-site setups need per-site URLs.
- Rotating the token does not help; the URL is the problem.