# Fix OAuth errors when adding an MCP connector

> Most OAuth errors when adding an MCP connector come from the URL, the account or a missing checkbox. What each Elaichi error means, and who fixes it.

**TL;DR** Most OAuth errors when adding Elaichi to Claude, ChatGPT or Cursor have one of four causes: the wrong address, the wrong account or organization, an expired consent request, or a permission left unticked. Paste exactly https://api.elaichi.ai/mcp, sign in as the right person, and reconnect when a tool says a checkbox is missing. A role, a restriction or an inactive plan is for an admin to fix.

## What causes most OAuth errors when you add an MCP connector?

Four things: the address, the account, an expired request, or a missing permission. OAuth errors when adding an MCP connector look alike in every client, because the client only reports that sign-in failed. Elaichi's side says which step failed, and almost every fix is on the screen in front of you.

OAuth is the standard that lets Claude, ChatGPT or Cursor act for you without holding your password. The client registers itself, opens Elaichi's sign-in in your browser, and asks for a grant: a record of what it may do, for whom. [OAuth 2.0](https://www.rfc-editor.org/rfc/rfc6749) defines the flow, and its error names, such as `invalid_grant`, are the ones Elaichi returns.

## What if sign-in never opens?

Check the address before anything else. Elaichi's endpoint is `https://api.elaichi.ai/mcp`, exactly. An unsigned request to it returns 401 with a pointer to Elaichi's sign-in details, and that 401 is what starts sign-in. Two near misses return no pointer:

- `https://api.elaichi.ai/mcp/`, with a trailing slash, returns 404.
- `https://app.elaichi.ai/mcp`, on the app host, returns 405.

Anthropic's docs say Claude needs that 401 to start sign-in ([how Claude authenticates connectors](https://claude.com/docs/connectors/building/authentication)). Its troubleshooting page names the two errors you see when it is missing or sign-in stalls: "Couldn't reach the MCP server" and "Authorization with the MCP server failed" ([troubleshooting a connector](https://claude.com/docs/connectors/building/troubleshooting)). ChatGPT and Cursor word it differently, but the fix is the same address.

## What does "Your organization requires signing in with SSO" mean?

Your company makes everyone sign in through its identity provider. When your email's domain belongs to an Elaichi organization that enforces SSO (single sign-on), Google, Microsoft, GitHub and email-code sign-in are refused with that message. The login screen then starts the SSO sign-in for you, and you land back on the same connection request.

Nothing is broken, and nothing needs an admin. Sign in the way your company asks, and continue.

## Why does the consent screen say the request is no longer valid?

Because it expired or was already used. A connection request lasts 30 minutes and works once. Leaving the tab open over lunch, or double-clicking Allow, ends it. The screen says the request is no longer valid and offers a way back to Elaichi.

Start the connection again from the client: Claude's Connect, ChatGPT's app, or Cursor's server entry. That opens a fresh request. The 30 minutes are long enough to build a toolbox in another tab and come back, if the step that picks toolboxes sends you off to make one.

## What if you are signed in to the wrong account or organization?

Use **Not you?** for the account, and connect again for the organization. The consent screen shows the signed-in email at the top. **Not you?** signs you out and returns you to the same request after you sign in as someone else.

The organization is chosen once per connection. With one membership it is chosen for you. With several, nothing is preselected, and the client will see only the organization you pick. Picking the wrong one means disconnecting and connecting again, and a second organization means a second connection.

If your account belongs to no organization yet, Continue and Allow stay disabled. The screen asks you to join or create one, then start the connection again.

## Why are Continue and Allow greyed out?

Usually because nothing can be granted yet. Four cases disable them:

- **No organization.** The account has nothing to give access to.
- **No organization picked.** With several memberships, Continue waits until you choose one.
- **No active plan.** The screen says the organization requires an active Gold or Black subscription. An Owner or a Billing Admin fixes that.
- **Nothing ticked.** Untick every checkbox and the screen asks you to allow at least one thing or deny the request.

## What does a "Not authorized" tool error mean after connecting?

The connection is missing a permission. The consent screen offers up to four: **Read your organization's data**, **Create and change data**, **Run your connected tools**, and **Delete data and remove access**. Everything the client requested starts ticked except delete, which never does. A client that asks for nothing gets read only.

When a tool needs a box that was not ticked, Elaichi answers the call with an error naming the checkbox and telling you to reconnect. It does not reject your login, because nothing is wrong with it. That answer arrives as a normal response, and Anthropic's docs say Claude ignores a sign-in challenge on such a response, so Claude will not ask on its own. Disconnect, reconnect, and tick the box. This works only if the client requested that permission in the first place.

## Why did a working connection stop with invalid_token or invalid_grant?

Because the grant behind it was revoked, or its refresh token lapsed. An access token lasts one hour, and the client refreshes it quietly. A refresh token lasts 30 days and is replaced on every use. A client unused for more than 30 days therefore has to reconnect, and the grant itself never expires while it is used.

Other things end a grant too. You disconnect the app under **Settings**, then **Connected apps**, the client revokes it, an admin removes or suspends you, or an old refresh token is used twice. In Elaichi, removing or suspending a member revokes every live grant in the same transaction as the membership change, and the next request returns `invalid_token`. Elaichi deliberately makes unknown, expired and revoked tokens look the same, so the fix is the same: reconnect.

## What does a 429 mean?

Too many requests in a minute. Elaichi accepts 30 OAuth requests a minute, counted per client for most of the flow and per network address for registration, and 120 MCP requests a minute per token. Over either limit you get 429 with a `Retry-After` of 60 seconds. Wait a minute and try again.

## Which errors can you fix yourself, and which need an admin?

| What you see | Who fixes it | How |
|---|---|---|
| Sign-in never opens | You | Paste exactly `https://api.elaichi.ai/mcp` |
| SSO required | You | Sign in through your company's SSO |
| Request no longer valid | You | Start again from the client |
| Wrong account or organization | You | **Not you?**, or connect again |
| "Not authorized" naming a checkbox | You | Reconnect and tick it |
| `invalid_token` or `invalid_grant` | You | Reconnect |
| 429 | You | Wait 60 seconds |
| No organization, or no longer a member | An admin | An invite or a membership |
| No active Gold or Black plan | An Owner or Billing Admin | Billing |
| Empty tool list, or one app missing | It depends | Not an OAuth error; see the checklist below |

An empty tool list after a clean sign-in is not an OAuth error at all. [MCP tools not showing up? Start here](/blog/mcp-tools-not-showing/) walks those checks in order.

## What should a custom MCP client send?

The standard flow, with PKCE (Proof Key for Code Exchange) on every request. Register at the endpoint the discovery document names, under [RFC 7591](https://www.rfc-editor.org/rfc/rfc7591). Then send a `code_challenge` with `code_challenge_method=S256`, as [RFC 7636](https://www.rfc-editor.org/rfc/rfc7636) defines. Elaichi does not assume S256 when the method is missing, and it refuses `plain`.

Three more rules catch hand-built clients:

- **The redirect URI must match.** It must be exactly one you registered. The only allowance is a loopback address changing its port.
- **The resource must be Elaichi's.** If you send one, it must be on `https://api.elaichi.ai`, or the request fails with `invalid_target`.
- **Scopes come from a fixed list.** Ask only for `mcp:read`, `mcp:write`, `mcp:destructive`, `mcp:tools`, `openid` and `email`. Anything else, such as `offline_access`, returns `invalid_scope`.

The [MCP authorization specification](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization) describes the discovery steps a compliant client follows.

## What does sign-in not decide?

Which tools the person can call. A clean sign-in proves who they are and what the connection may attempt. Their role, what is shared with them and restrictions decide the rest. Restrictions decide which connectors and which individual tools a target may reach, and a role or restriction change takes about two minutes to apply.

To set the connector up from the start, follow [the Claude setup](/blog/connect-elaichi-to-claude/), [the ChatGPT setup](/blog/connect-elaichi-to-chatgpt/) or [the Cursor setup](/blog/cursor-mcp-one-endpoint-vs-per-developer/). Elaichi's Gold plan is $15 per user per month in USD, with your region's price on the [pricing page](/pricing/).

## FAQ

### Why does sign-in never open when I add the Elaichi connector?

The address is usually wrong. https://api.elaichi.ai/mcp answers an unsigned request with the 401 challenge that starts sign-in. With a trailing slash it returns 404, and on the app host it returns 405, and neither carries the challenge.

### How long does an Elaichi sign-in last?

An access token lasts one hour, and the client refreshes it. A refresh token lasts 30 days and is replaced on every use, and the grant itself never expires. A client left unused for more than 30 days has to reconnect.

### Why does a tool say I am not authorized after I connected?

The connection is missing a permission, such as running connected tools or deleting. The message names the checkbox. Reconnect in the client and tick it on Elaichi's consent screen. Your login is fine.

### Which Elaichi sign-in problems need an admin?

Having no organization, no longer being a member, a role without the tool:execute permission, a restriction, or an organization without an active Gold or Black plan. The person connecting cannot fix those.

## Read next

- [Connect company apps to Claude and ChatGPT](/blog/connect-company-apps-to-claude-and-chatgpt/) — To connect company apps to Claude and ChatGPT, connect each account once in Elaichi, share it, and add one URL to both. No MCP server to run.
- [Connect Elaichi to Claude Code](/blog/connect-elaichi-to-claude-code/) — To connect Elaichi to Claude Code, run one claude mcp add command and sign in with OAuth. The entry holds no secret, so a project .mcp.json is safe to commit.
- [Connect Elaichi to Codex](/blog/connect-elaichi-to-codex/) — To connect Elaichi to Codex, add one URL as a streamable HTTP server and run codex mcp login. No token, no header, and each engineer signs in as themselves.
