Skip to main content
Connect Your AI

Connection troubleshooting

Work top to bottom: quick checks, then the specific symptom you are seeing.

Written By Christopher Scaminaci

Last updated 3 days ago

Work top to bottom: quick checks, then the specific symptom you are seeing.

Quick checks first

Endpoint addresses in this page are written as US examples. Your workspace's region decides its real hostname, so copy the address from MCP Setup in the portal. See Your region and your endpoint.

  1. Is the URL exactly the one from MCP Setup? Copy it from the Standard endpoint card, including the /mcp path. A US workspace sees https://mcp.stackjack.io/mcp. A hand-typed or wrong-region address fails as a network or credential error rather than as a helpful message.

  2. Can this machine reach the server at all? Open the health address — your endpoint hostname with /health instead of /mcp, so https://mcp.stackjack.io/health in the US — in a browser or with curl.

    Read the result narrowly. A healthy response proves only that this one request reached the server and got an answer. It does not prove that MCP transport works, that your credentials are accepted, that your connector credentials are valid, or that every dependency behind the endpoint is up. Do not stop investigating a network or service problem because /health is green: a proxy that allows only some paths, a blocked port, or a fault behind the MCP route all leave it green. Treat it as step one, then keep going through this page and collect the error message and its correlation ID.

  3. Are you on the main endpoint? Establish the connection on the Standard endpoint FIRST. The compact host is a catalog-tuning address for afterwards — it always serves its smaller, searchable catalog, whatever your organization has chosen, and switching hosts mid-diagnosis adds a second variable to a connection that has never worked.

  4. Is the transport right? If your tool asks, choose Streamable HTTP (sometimes labeled just "HTTP"). Do not pick SSE or stdio.

"401 Unauthorized" on requests

A 401 means the request's credentials were rejected. Causes, roughly in order of likelihood:

CauseWhat happenedFix
Tool has no valid credentials yetA first 401 is normal for the sign-in method — it carries the information that tells the tool to open the browser sign-inLet the tool prompt you to sign in; if it does not, re-add the server
Wrong or stale secretTypo in the Client ID/secret or API key, or the secret was rotatedRe-enter the current value; ask an admin for the new secret if it was rotated
Credential used in the wrong laneAn API key sent as Basic auth, or a Client ID + Secret sent as an API keyMatch the credential type to the header format — see authentication options
Credential revokedAn admin revoked the client or API keyCreate/obtain a new credential
Your membership was revokedResponse says "Linked user access has been revoked"Ask an admin — if intended to be restored, they reactivate you on the Team page and you sign the tool in again
App authorization revoked (shared apps)An admin revoked that app for you (on the Team page → your member row → Connected apps)Ask an admin to reinstate it
Idle session expiredThe connection sat unused for 30+ daysSign in again from the tool
Workspace deactivatedEverything fails for everyoneContact StackJack support

Errors during the browser sign-in

These appear as "access denied" results in your AI tool after the browser hop, each with a human-readable description:

MessageMeaningWhat to do
"No StackJack account found for this identity…"Your sign-in identity is not linked to any StackJack workspaceSign up at https://portal.stackjack.io/signup, or ask your team admin to invite you
"Your access to this tenant has been revoked. Ask your admin to send a new invite."You were a member and were removedOnly an admin can restore you
"You are not a member of this StackJack tenant. Ask your team admin to invite you first."Your identity resolved to the workspace but has no membershipAsk an admin for an invite
"This client is already linked to a different StackJack account. Reconnect with a fresh client registration."The tool is reusing a registration that belongs to another userRemove the StackJack server from the tool and add it again so it registers fresh

If sign-in completed but your tool connected with almost no tools and stackjack_session_info reports pending_approval, you self-registered and are awaiting admin approval — see Self-registration and approving new members.

invalid_client or unauthorized_client

These two OAuth error codes look alike and come from different places.

invalid_client is StackJack refusing the client your AI tool presented. It appears in four shapes:

Error descriptionWhenWhat to do
"Unknown or inactive client…"When the tool starts the sign-in, or when it exchanges the sign-in for a tokenThe tool is using a registration StackJack does not know, or one that was switched off: a registration from another workspace, a sign-in registration an admin revoked, a deleted credential, or an endpoint in the wrong region (registrations belong to one region). Remove the StackJack server from the tool and add it again with the address from MCP Setup, so it registers fresh.
"Invalid client credentials"When the tool exchanges a Client ID + Secret for a tokenThe secret is wrong or was rotated, the ID and secret are in each other's fields, or the credential is one that cannot be used for a browser sign-in (a personal or automation credential). Re-enter the current values from MCP Setup, or connect with the sign-in method instead — see authentication options.
"Client authentication required"When a tool configured with a pre-created Client ID sends no secretEnter the Client Secret in the tool, or remove the Client ID and use the sign-in method.
"The client_id metadata document could not be retrieved or failed validation."When a tool that identifies itself by a web address (ChatGPT, for example) starts the sign-inOne message covers two causes. Either StackJack could not fetch or validate the client document the tool publishes at that address — usually brief on the tool's side, so try again in a few minutes. Or that tool has been switched off for StackJack as a whole, which affects every one of your users at once (see An AI app fails for every user at once). If it persists, contact support.

unauthorized_client is never a StackJack sign-in answer. StackJack's own sign-in and token endpoints do not return it. When you see it, a connector vendor sent it back on a tool call: the vendor refused the access StackJack's connection asked for — for example, Google Workspace domain-wide delegation that is missing a scope group, or a Microsoft app registration that is not permitted the sign-in it is configured for. Reconnecting your AI tool does not fix it. An admin fixes it in the vendor's console, following that connector's setup guide; see also Tool errors and troubleshooting.

"403 Forbidden" on tool calls

A 403 with "No active connector subscriptions found" or "No connector credentials configured for your active subscriptions" means authentication worked but the workspace has no usable connector yet:

  • The owner, a co-owner, or an Administrator needs to set up at least one connector on the Connectors page (which also activates its subscription).
  • Even in this state, StackJack's built-in tools still work through the AI tool — you can check service status and open a support ticket before any connector is configured.

Connected, but tools are missing

  • Pending approval — you self-registered and only see StackJack status tools. An admin approves you via Edit Roles or Edit Tools on the Team page (details).

  • Tool roles and assignments — the tools you see are the union of the tool roles assigned to you plus any extras picked for you individually, then narrowed by the credential in use (which has its own roles and extras). A role that was removed from you, or from the credential, removes its tools on your next request. Ask an admin to check your roles and extras on the Team page and the credential's on MCP Setup.

  • Plan tier — each connector's plan tier determines which of its tools exist for your workspace at all.

  • Your AI tool's own limit — several AI products cap how many tools they accept from one server. Some silently drop the rest; at least one returns an error instead. The caps differ per product, vendors change them, and StackJack tracks them in one place: Client tool limits. Check that table rather than a number quoted in a setup guide.

    The first-line fix is catalog modes: switch StackJack to compact or minimal mode so it serves a small tool list while keeping every tool reachable on demand. This matters because at least one client re-sorts your whole catalog alphabetically before truncating it, so no ordering on StackJack's side can protect a particular tool.

    Check whether StackJack has already done this for you. If your organization has never made an explicit catalog-mode choice, a connection from an AI tool StackJack recognizes is automatically served a reduced catalog once your catalog is large enough — that is the tool's own cap where it has one, and StackJack's general auto-reduce threshold where it does not. StackJack recognizes Claude, Claude Desktop, Cursor and Windsurf by the way the tool identifies itself, and Microsoft 365 Copilot connections by how the connection signs in. Three products carry the Copilot name and only that one is recognized: GitHub Copilot in VS Code and Microsoft Copilot Studio have caps but present nothing StackJack can recognize them by, so they are not reduced automatically. Auto-detection applies per connection, so the same workspace can be compact from one tool and full from an uncapped one on the same day.

    For every other client, an admin must enable catalog modes for your organization on the Settings page; until then the standard endpoint serves the full tool list. The compact hostname is the exception, and needs nothing enabled: every connection to it is served the smaller catalog whatever your organization has chosen, which makes it the one fix that works while the setting is still off. Trimming the credential's or member's tool selection also helps. See Choosing tools for each client and managing harness tool limits and Catalog modes.

After an admin changes your assignments, the fix is picked up on your next request — refresh the tool list in your AI tool; no reconnect is needed.

"I revoked/rotated, but it still works"

  • Rotation of a Client ID + Secret or API key kills the old secret and the OAuth access and refresh tokens minted from it. Both fail on the connection's next request; there is no one-hour grace period.
  • Everything else — revoking a credential, removing a member, revoking an app authorization — also takes effect on the connection's next request.
  • If something still works minutes later, the likely cause is not a delay. Check that you revoked the right row, that the tool is not connected under a different credential or a sign-in session as well as the one you revoked, and that you are looking at the same workspace. See the timing reference.
  • Reactivating a member does not restore everything. Shared-app authorizations and credentials that the suspension itself switched off come back; per-install sign-in registrations and anything revoked for cause do not. See Managing members.

An AI app fails for every user at once

If a specific AI product suddenly gets 401s for all of your users (sign-ins fail too), StackJack may have blocked that app for all customers to protect accounts. This is a deliberate protective action, not an outage. Contact support@stackjack.io.

Copilot Studio: the tool will not create, connect, or reconnect

Copilot Studio's MCP tools ride Power Platform plumbing, and the three failures below are all Power Platform-side. None of them is a StackJack credential problem, and re-entering the connection does not fix them.

  • An orphaned custom connector from an earlier attempt. Adding an MCP tool creates a custom connector in the Power Platform environment behind the scenes, and deleting or re-adding the tool can leave the old one behind — after which creating or connecting the tool errors. Clean it up at make.powerapps.com: pick the SAME environment the agent lives in (the environment picker, top right), open Custom connectors, delete the stale StackJack connector, then add the MCP tool again in Copilot Studio.
  • The Default environment and DLP policies. Agents built in the org's Default environment are covered by data-loss-prevention policies that commonly block custom connectors — the tool then fails to create or the connection is refused, often without naming DLP as the reason. Build the agent in a dedicated environment, or have your Power Platform admin allow the connector in the DLP policy that covers the environment.
  • Missing environment rights. Creating the MCP tool needs maker rights in the environment (Environment Maker); cleaning up another maker's orphaned connector can need the environment's System Administrator. If the options above are missing from your view, that is why.

Rate limits and quotas

  • There is no per-minute rate limit — bursts of requests are not throttled.
  • The enforcement point is the monthly plan cap per connector subscription. If a connector's monthly allowance is exhausted, its tool calls fail until the billing cycle resets or the plan is upgraded. Check usage on the Dashboard or Billing pages.

When you contact support

Include:

  • Your workspace (company) name and the signed-in email.
  • Any support code shown (they start with SJ-, e.g. SJ-ACCESS-AWAITING-APPROVAL).
  • The AI tool/product, the exact error text, and the time it occurred (StackJack timestamps are Eastern Time).

Email support@stackjack.io or use the Support button in the portal header.