Troubleshooting

Diagnose authentication, origin, rate-limit, timeout, and client catalog issues.

Updated 2026-09-23
6 min read

401 Unauthorized

The request had no Bearer credential, the API key was invalid or revoked, the user is no longer a member of the bound organization, or the OAuth client could not refresh its token.

  • For API keys, confirm the client sends Authorization: Bearer fvk_live_… and that the key is still active under Settings → API Keys.
  • Confirm the process actually receives the environment variable used by its config; apps launched from the Dock may not inherit shell variables.
  • For OAuth, disconnect Forvibe in the client, add it again, and complete a fresh consent.
  • If your organization role or membership changed, sign in to Forvibe and confirm the intended organization is active.

403 Forbidden origin

A browser client sent an Origin header outside the server's current allowlist. Recognized production origins are claude.ai, chatgpt.com, cursor.sh, gemini.google.com, and forvibe.app; localhost and 127.0.0.1 are allowed for development. CLI and server-side clients that send no Origin are accepted.

A self-hosted web client or proxy with its own Origin needs an allowlist update. Contact support@forvibe.dev with the exact HTTPS origin.

429 Rate limit exceeded

Personal API keys allow 120 MCP requests in a rolling 60-second window. The response includes X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, and, on rejection, Retry-After. Wait for the indicated reset instead of retrying immediately. This per-key limiter does not currently apply to OAuth tokens.

Insufficient credits

AI-powered tools can return an insufficient-credit tool error even though the MCP transport itself is healthy. Review the error's required and available balance, then buy credits from Buy Credits or choose a non-AI operation.

Request timed out

Forvibe allows a maximum 120-second request. Configure the client tool timeout to at least 120 seconds for AI localization and metadata simulation. A shorter client timeout can report failure while the server is still finishing the operation; check the corresponding status or history tool before retrying.

  • Use the canonical server URL https://forvibe.app/mcp with no extra path.
  • Do not manually enter a Client ID or Client Secret in clients that support Dynamic Client Registration.
  • Allow pop-ups for the client and Forvibe, sign in to Forvibe in the same browser, and repeat the consent.
  • Remove the partially connected server before retrying so the client does not reuse stale registration or refresh-token state.
  • If the platform guide marks OAuth as unverified, use its documented personal API-key configuration instead.

Tool missing or server disabled

  • Start or enable forvibe in the client's MCP settings, then reload the editor or begin a new chat.
  • Switch the client to its tool-capable Agent mode and enable Forvibe in the conversation's tools picker.
  • Compare the name with the Tools Reference. Console-only tools are intentionally absent from external clients.
  • Account for client plan policy: ChatGPT Pro, for example, exposes read/fetch behavior rather than Forvibe's full write catalog.

Check the endpoint directly

A successful MCP initialize request confirms the URL, credential, and transport independently of the client UI:

bash
curl -X POST https://forvibe.app/mcp \
  -H "Authorization: Bearer fvk_live_..." \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"curl-check","version":"1.0"}}}'

A 200 response with Forvibe server information means the endpoint and auth work. A 401 points to credentials; 403 points to Origin; 429 points to the API-key quota.

Still stuck?

Email support@forvibe.dev with the client name and version, authentication method (never the secret), exact error, timestamp with timezone, and whether the direct initialize check succeeded.