API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-119 · Authentication & identity

Atlassian Rovo MCP moves Dynamic Client Registration to a new OAuth server

From 27 May 2026, Rovo MCP Dynamic Client Registration uses Atlassian Identity; cached client IDs and discovery documents from the former server are not recognised.

Atlassian Rovo MCPDCROAuthAtlassian Identitydiscovery

Previous state

Rovo MCP DCR clients used the previous OAuth server and could retain its client_id and discovery state.

Current state

Requests to the Rovo MCP endpoint use Atlassian Identity for DCR OAuth; clients retaining stale registration or discovery state can fail authentication.

Who needs to care

Rovo MCP clients implementing Dynamic Client Registration OAuth and caching client IDs or authorization-server discovery documents.

What to do

Discard stale registration and discovery state, rediscover the protected resource and OAuth server and obtain a registration recognised by the new provider.

What the source does not prove

This is an OAuth-server and cached-state cutover, not the later Rovo MCP v2 preview and not evidence that every client failed.

Lifecycle history

Dated event sequence

  1. Cutover announced

    Atlassian provided an interim authv2 test route.

  2. Atlassian Identity cutover

    The production MCP endpoint began using the new DCR OAuth server.

Evidence ledger

First-party sources

  1. 01
    Atlassian Developer — Atlassian Rovo MCP changelog

    Official authentication changelog · 2026-04-27

    Open official source ↗