If you encounter problems configuring or connecting CloudBees CI MCP Router, use this guidance to identify the cause and resolve the issue.
OAuth requests are rejected after configuration
If OAuth requests are rejected after configuration, check the following common misconfigurations:
-
Issuer mismatch: The Trusted issuer on the resource server and the
OAUTH_ISSUERof the CloudBees CI MCP Router must both match the Issuer URL of the authorization server exactly, includinghttps://and any trailing path. -
Audience mismatch: Each controller and the CloudBees CI MCP Router must appear in the Allowed audiences list of the authorization server, and the Accepted audience of each instance must be its own address.
-
Keys unreachable: controllers fetch the signing keys from the issuer’s public HTTPS
/jwksendpoint by default. If a controller genuinely cannot reach that address, set the Internal JWKS URL on the authorization server to an internally reachable HTTPS address.
If the issue persists, contact CloudBees Support.
An OAuth signing key may be compromised
If you suspect the authorization server’s OAuth signing key material has been exposed, refer to Force-remove a compromised OAuth signing key to force-remove the compromised key from the JSON Web Key Set (JWKS) immediately, rather than waiting for scheduled rotation.
OAuth requests are failing: debug logging (UI)
If OAuth requests are failing, enable FINE-level logging for the CloudBees OAuth Resource Server plugin (cloudbees-oauth-resource) on the operations center or controller that is rejecting the request.
This produces detailed bearer token validation traces, including bearer_reject lines when a request is passed through without a valid bearer token.
To enable debug logging in the UI:
-
In the operations center or controller, navigate to .
-
Select + Add recorder.
-
On the New log recorder screen, enter a name (for example,
oauth-resource) and select Create. -
Under Loggers, select +Add.
-
For Logger, enter
com.cloudbees.jenkins.plugins.oauth.resource. -
Set Log level to FINE.
-
-
Select Save.
Logs are displayed in real time on the recorder page and written to the Jenkins log.
FINE logging is verbose. Disable it once you have identified the issue.
OAuth requests are failing: debug logging (Configuration as Code)
If OAuth requests are failing, enable FINE-level logging for the CloudBees OAuth Resource Server plugin (cloudbees-oauth-resource) on the operations center or controller that is rejecting the request.
This produces detailed bearer token validation traces, including bearer_reject lines when a request is passed through without a valid bearer token.
To enable debug logging using Configuration as Code (CasC):
-
In the CasC bundle for the operations center or controller, add the following to your
jenkins.yamlfile:unclassified: log: recorders: - name: oauth-resource loggers: - name: com.cloudbees.jenkins.plugins.oauth.resource level: FINE -
Apply the bundle to your operations center and controllers. For more information, refer to Update a CasC bundle.
Logs are displayed in real time on the recorder page and written to the Jenkins log.
FINE logging is verbose. Disable it once you have identified the issue.