ST-2026-119 · Authentication & identity
Atlassian Rovo MCP moves Dynamic Client Registration to a new OAuth server
From 27 May 2026, Rovo MCP Dynamic Client Registration uses Atlassian Identity; cached client IDs and discovery documents from the former server are not recognised.
Previous state
Rovo MCP DCR clients used the previous OAuth server and could retain its client_id and discovery state.
Current state
Requests to the Rovo MCP endpoint use Atlassian Identity for DCR OAuth; clients retaining stale registration or discovery state can fail authentication.
Affected users
Who needs to care
Rovo MCP clients implementing Dynamic Client Registration OAuth and caching client IDs or authorization-server discovery documents.
Required response
What to do
Discard stale registration and discovery state, rediscover the protected resource and OAuth server and obtain a registration recognised by the new provider.
Evidence boundary
What the source does not prove
This is an OAuth-server and cached-state cutover, not the later Rovo MCP v2 preview and not evidence that every client failed.
Lifecycle history
Dated event sequence
- Cutover announced
Atlassian provided an interim authv2 test route.
- Atlassian Identity cutover
The production MCP endpoint began using the new DCR OAuth server.
Evidence ledger
First-party sources
- 01Atlassian Developer — Atlassian Rovo MCP changelog
Official authentication changelog · 2026-04-27
Open official source ↗