No MCP tools discovered#
Inspect the connection test/startup discovery result. Check the exact command/runtime or HTTP URL, timeout and authentication mode. One failing server may be skipped. OAuth-protected tools/list can fail before personal credentials exist; completing OAuth does not prove automatic rediscovery.
MCP disconnected or timed out#
STDIO read timeout kills/resets the process; a later call can restart/initialize it. HTTP has no verified universal retry/reconnect loop. Check the remote server logs and configuration before repeating a consequential operation.
Permission denied#
Inspect the exact permission, user roles, active module state and request scopes. Explicit deny takes precedence. Login alone is not a grant. A tool visible to the AI can still be denied at execution.
Approval required or expired#
Review the current pending card and preview. A changed request requires new approval; an expired/consumed card cannot authorize another execution. File HTTP actions requiring approval return 409 instead of creating one-time approvals. Pending state is not restored after restart.
Module installation failed#
Check ZIP/yamod format, manifest identity/entrypoints, primary version, declared permission-code matches, python/ directory and package size/path constraints. Validation imports code; use trusted packages. New installations/removals need restart. Inspect module health/detail after configuration.
Authentication and AD availability#
Invalid credentials and inactive accounts are distinct from directory unavailability. AD authentication can return 503 when its provider is unavailable; invalid credentials return 401. Use the authorized local recovery path rather than changing database credentials or disabling security controls.
HTTP status codes#
| Code | Verified context | Diagnostic direction |
|---|---|---|
| 401 | Missing session/invalid login; provider auth failures | Check the relevant application's session or configured provider credential |
| 403 | Admin/RBAC/CSRF denial; external provider restrictions | Inspect role, permission/scope and session-matched CSRF token |
| 409 | Conflicts/approval-required file actions/changed approval groups | Review current state and the exact handler's error |
| 429 | Login throttle or outbound Action1 vendor rate limit | Distinguish login limits from vendor pacing; respect retry guidance |
| 503 | AD authentication provider unavailable | Check configured directory/worker availability |
Action1 execution failures#
Inline PowerShell on a currently disconnected endpoint fails with action1_endpoint_disconnected and automation_submitted=false. Do not generalize that preflight shortcut to every library/deployment operation. Client errors distinguish HTTP, transport, response and polling timeout failures. Ambiguous mutations are not blindly replayed.
1C service support#
The integration is read-only HTTP, not direct SQL. Missing schema/query service support raises a universal-API unavailable/configuration error. Legacy stock/movements/search paths remain separate. Confirm what the published 1C service implements before querying.