Troubleshooting
Diagnose authentication, origin, rate-limit, timeout, and client catalog issues.
401 Unauthorized
The request had no Bearer credential, the API key was invalid or revoked, the user is no longer a member of the bound organization, or the OAuth client could not refresh its token.
- For API keys, confirm the client sends
Authorization: Bearer fvk_live_…and that the key is still active under Settings → API Keys. - Confirm the process actually receives the environment variable used by its config; apps launched from the Dock may not inherit shell variables.
- For OAuth, disconnect Forvibe in the client, add it again, and complete a fresh consent.
- If your organization role or membership changed, sign in to Forvibe and confirm the intended organization is active.
403 Forbidden origin
A browser client sent an Origin header outside the server's current allowlist. Recognized production origins are claude.ai, chatgpt.com, cursor.sh, gemini.google.com, and forvibe.app; localhost and 127.0.0.1 are allowed for development. CLI and server-side clients that send no Origin are accepted.
A self-hosted web client or proxy with its own Origin needs an allowlist update. Contact support@forvibe.dev with the exact HTTPS origin.
429 Rate limit exceeded
Personal API keys allow 120 MCP requests in a rolling 60-second window. The response includes X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, and, on rejection, Retry-After. Wait for the indicated reset instead of retrying immediately. This per-key limiter does not currently apply to OAuth tokens.
Insufficient credits
AI-powered tools can return an insufficient-credit tool error even though the MCP transport itself is healthy. Review the error's required and available balance, then buy credits from Buy Credits or choose a non-AI operation.
Request timed out
Forvibe allows a maximum 120-second request. Configure the client tool timeout to at least 120 seconds for AI localization and metadata simulation. A shorter client timeout can report failure while the server is still finishing the operation; check the corresponding status or history tool before retrying.
OAuth callback, resource, or consent loop
- Use the canonical server URL
https://forvibe.app/mcpwith no extra path. - Do not manually enter a Client ID or Client Secret in clients that support Dynamic Client Registration.
- Allow pop-ups for the client and Forvibe, sign in to Forvibe in the same browser, and repeat the consent.
- Remove the partially connected server before retrying so the client does not reuse stale registration or refresh-token state.
- If the platform guide marks OAuth as unverified, use its documented personal API-key configuration instead.
Tool missing or server disabled
- Start or enable
forvibein the client's MCP settings, then reload the editor or begin a new chat. - Switch the client to its tool-capable Agent mode and enable Forvibe in the conversation's tools picker.
- Compare the name with the Tools Reference. Console-only tools are intentionally absent from external clients.
- Account for client plan policy: ChatGPT Pro, for example, exposes read/fetch behavior rather than Forvibe's full write catalog.
Check the endpoint directly
A successful MCP initialize request confirms the URL, credential, and transport independently of the client UI:
curl -X POST https://forvibe.app/mcp \
-H "Authorization: Bearer fvk_live_..." \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"curl-check","version":"1.0"}}}'A 200 response with Forvibe server information means the endpoint and auth work. A 401 points to credentials; 403 points to Origin; 429 points to the API-key quota.
Still stuck?
Email support@forvibe.dev with the client name and version, authentication method (never the secret), exact error, timestamp with timezone, and whether the direct initialize check succeeded.