Troubleshooting "Invalid Token" or "Invalid Context" errors when connecting to the Atlassian Remote MCP Server

Platform Notice: Cloud Only - This article only applies to Atlassian apps on the cloud platform.

Summary

When connecting an MCP client (such as Claude, Cursor, or VS Code) to the Atlassian Remote MCP Server, some users may encounter "invalid token" or "invalid context provided" errors during authentication. This article covers the most common causes and step-by-step troubleshooting steps.

Symptoms

  • One or more users are unable to authenticate to the Atlassian MCP Server from an MCP client (e.g. Claude)

  • The error message displayed is "invalid token" or "invalid context provided"

  • Other users on the same domain or organisation can connect successfully

  • The issue persists after clearing browser cache, using incognito mode, or trying a different browser

Solution

Common Causes and Fixes

1. Using the deprecated MCP endpoint

After 30 June 2026, the old SSE endpoint https://mcp.atlassian.com/v1/sse is no longer supported. Using it will result in "invalid context" errors.

Fix: Update your MCP client configuration to use the new endpoint:

https://mcp.atlassian.com/v1/mcp/authv2

See Getting started with the Atlassian Remote MCP Server for full setup instructions.

2. Device clock out of sync

Most common cause of user-specific failures. MCP authentication uses time-sensitive tokens. If a user's device clock is even a few minutes off, the token will be rejected — even if the same endpoint works perfectly for other users on the same team

Fix:

  1. Have the affected user visit https://time.is and compare their device time to the displayed time.

  2. If the device clock is off by more than a few seconds, enable automatic time synchronisation:

    • Windows: Settings → Time & Language → Date & Time → "Set time automatically"

    • macOS: System Settings → General → Date & Time → "Set time and date automatically"

  3. Once the clock is corrected, retry the MCP connection in a fresh browser session.

We have experienced cases where a device clock was four minutes behind. This was enough to cause "invalid token" errors while everyone else on the same domain connected successfully. Fixing the clock resolved the issue immediately.

3. Stale session or cached credentials

A corrupted local session can cause token errors even after switching to the correct endpoint.

Fix:

  1. Log out of both Atlassian and the MCP client (e.g. Claude).

  2. Clear browser cookies and cache.

  3. Retry the connection in a new incognito/private browser window.

4. OAuth domain not allowlisted (less common)

If the error appears for all users on a domain (not just one), the domain may not be allowlisted in the Atlassian Admin console.

Fix:

  1. Log in to Atlassian Administration → Rovo → Rovo MCP Server.

  2. Navigate to Domain settings and verify the organisation's domain is listed.

  3. If it appears but the issue persists, try removing and re-adding the domain entry to force a backend refresh.

Troubleshooting Checklist

Step

Action

1

Confirm the new endpoint https://mcp.atlassian.com/v1/mcp/authv2 is configured in the MCP client

2

Check device clock accuracy at time.is — must be within a few seconds

3

Clear cookies/cache and retry in a fresh incognito/private browser window

4

Verify the organisation's domain is allowlisted in Atlassian Admin → Rovo → Rovo MCP Server

If the Issue Persists

If the steps above do not resolve the issue, collect a HAR file from a failed connection attempt and contact Atlassian Support.

Instructions for generating a HAR file: Generate HAR files and analyze web requests for Atlassian support.

Related Resources

Updated on September 25, 2026

Still need help?

The Atlassian Community is here for you.