What causes most OAuth errors when you add an MCP connector?
Four things: the address, the account, an expired request, or a missing permission. OAuth errors when adding an MCP connector look alike in every client, because the client only reports that sign-in failed. Elaichi's side says which step failed, and almost every fix is on the screen in front of you.
OAuth is the standard that lets Claude, ChatGPT or Cursor act for you without holding your password. The client registers itself, opens Elaichi's sign-in in your browser, and asks for a grant: a record of what it may do, for whom. OAuth 2.0 defines the flow, and its error names, such as invalid_grant, are the ones Elaichi returns.
What if sign-in never opens?
Check the address before anything else. Elaichi's endpoint is https://api.elaichi.ai/mcp, exactly. An unsigned request to it returns 401 with a pointer to Elaichi's sign-in details, and that 401 is what starts sign-in. Two near misses return no pointer:
https://api.elaichi.ai/mcp/, with a trailing slash, returns 404.https://app.elaichi.ai/mcp, on the app host, returns 405.
Anthropic's docs say Claude needs that 401 to start sign-in (how Claude authenticates connectors). Its troubleshooting page names the two errors you see when it is missing or sign-in stalls: "Couldn't reach the MCP server" and "Authorization with the MCP server failed" (troubleshooting a connector). ChatGPT and Cursor word it differently, but the fix is the same address.
What does "Your organization requires signing in with SSO" mean?
Your company makes everyone sign in through its identity provider. When your email's domain belongs to an Elaichi organization that enforces SSO (single sign-on), Google, Microsoft, GitHub and email-code sign-in are refused with that message. The login screen then starts the SSO sign-in for you, and you land back on the same connection request.
Nothing is broken, and nothing needs an admin. Sign in the way your company asks, and continue.
Why does the consent screen say the request is no longer valid?
Because it expired or was already used. A connection request lasts 30 minutes and works once. Leaving the tab open over lunch, or double-clicking Allow, ends it. The screen says the request is no longer valid and offers a way back to Elaichi.
Start the connection again from the client: Claude's Connect, ChatGPT's app, or Cursor's server entry. That opens a fresh request. The 30 minutes are long enough to build a toolbox in another tab and come back, if the step that picks toolboxes sends you off to make one.
What if you are signed in to the wrong account or organization?
Use Not you? for the account, and connect again for the organization. The consent screen shows the signed-in email at the top. Not you? signs you out and returns you to the same request after you sign in as someone else.
The organization is chosen once per connection. With one membership it is chosen for you. With several, nothing is preselected, and the client will see only the organization you pick. Picking the wrong one means disconnecting and connecting again, and a second organization means a second connection.
If your account belongs to no organization yet, Continue and Allow stay disabled. The screen asks you to join or create one, then start the connection again.
Why are Continue and Allow greyed out?
Usually because nothing can be granted yet. Four cases disable them:
- No organization. The account has nothing to give access to.
- No organization picked. With several memberships, Continue waits until you choose one.
- No active plan. The screen says the organization requires an active Gold or Black subscription. An Owner or a Billing Admin fixes that.
- Nothing ticked. Untick every checkbox and the screen asks you to allow at least one thing or deny the request.
What does a "Not authorized" tool error mean after connecting?
The connection is missing a permission. The consent screen offers up to four: Read your organization's data, Create and change data, Run your connected tools, and Delete data and remove access. Everything the client requested starts ticked except delete, which never does. A client that asks for nothing gets read only.
When a tool needs a box that was not ticked, Elaichi answers the call with an error naming the checkbox and telling you to reconnect. It does not reject your login, because nothing is wrong with it. That answer arrives as a normal response, and Anthropic's docs say Claude ignores a sign-in challenge on such a response, so Claude will not ask on its own. Disconnect, reconnect, and tick the box. This works only if the client requested that permission in the first place.
Why did a working connection stop with invalid_token or invalid_grant?
Because the grant behind it was revoked, or its refresh token lapsed. An access token lasts one hour, and the client refreshes it quietly. A refresh token lasts 30 days and is replaced on every use. A client unused for more than 30 days therefore has to reconnect, and the grant itself never expires while it is used.
Other things end a grant too. You disconnect the app under Settings, then Connected apps, the client revokes it, an admin removes or suspends you, or an old refresh token is used twice. In Elaichi, removing or suspending a member revokes every live grant in the same transaction as the membership change, and the next request returns invalid_token. Elaichi deliberately makes unknown, expired and revoked tokens look the same, so the fix is the same: reconnect.
What does a 429 mean?
Too many requests in a minute. Elaichi accepts 30 OAuth requests a minute, counted per client for most of the flow and per network address for registration, and 120 MCP requests a minute per token. Over either limit you get 429 with a Retry-After of 60 seconds. Wait a minute and try again.
Which errors can you fix yourself, and which need an admin?
| What you see | Who fixes it | How |
|---|---|---|
| Sign-in never opens | You | Paste exactly https://api.elaichi.ai/mcp |
| SSO required | You | Sign in through your company's SSO |
| Request no longer valid | You | Start again from the client |
| Wrong account or organization | You | Not you?, or connect again |
| "Not authorized" naming a checkbox | You | Reconnect and tick it |
invalid_token or invalid_grant |
You | Reconnect |
| 429 | You | Wait 60 seconds |
| No organization, or no longer a member | An admin | An invite or a membership |
| No active Gold or Black plan | An Owner or Billing Admin | Billing |
| Empty tool list, or one app missing | It depends | Not an OAuth error; see the checklist below |
An empty tool list after a clean sign-in is not an OAuth error at all. MCP tools not showing up? Start here walks those checks in order.
What should a custom MCP client send?
The standard flow, with PKCE (Proof Key for Code Exchange) on every request. Register at the endpoint the discovery document names, under RFC 7591. Then send a code_challenge with code_challenge_method=S256, as RFC 7636 defines. Elaichi does not assume S256 when the method is missing, and it refuses plain.
Three more rules catch hand-built clients:
- The redirect URI must match. It must be exactly one you registered. The only allowance is a loopback address changing its port.
- The resource must be Elaichi's. If you send one, it must be on
https://api.elaichi.ai, or the request fails withinvalid_target. - Scopes come from a fixed list. Ask only for
mcp:read,mcp:write,mcp:destructive,mcp:tools,openidandemail. Anything else, such asoffline_access, returnsinvalid_scope.
The MCP authorization specification describes the discovery steps a compliant client follows.
What does sign-in not decide?
Which tools the person can call. A clean sign-in proves who they are and what the connection may attempt. Their role, what is shared with them and restrictions decide the rest. Restrictions decide which connectors and which individual tools a target may reach, and a role or restriction change takes about two minutes to apply.
To set the connector up from the start, follow the Claude setup, the ChatGPT setup or the Cursor setup. Elaichi's Gold plan is $15 per user per month in USD, with your region's price on the pricing page.