Skip to content

Troubleshooting

Operate

Troubleshooting starts from symptoms, scope, reason codes, and metadata-only evidence. The goal is to prove or restore the governed MCP path without bypassing policy, reading production databases, or exposing private payloads.

  • Operators diagnosing failed runtime checks.
  • Security operators reviewing denials or no-secret scan failures.
  • Support engineers turning request IDs into safe remediation.
  • Docs reviewers checking public troubleshooting material.

This page is the public symptom matrix for V1. It routes identity, policy, credential, connector, API import, SIEM/export, session drain, and secret-scan failures to concrete checks and fail-closed action.

Use it after the Operator Workflow baseline when one surface still fails. If the question is “why did the gateway hide or deny this tool?”, include Audit and Deny Diagnostics in the path.

  1. Capture branch, exact command, exit status, request ID when available, and first failing check.
  2. Map the symptom to the contract or runbook surface that owns the reason code.
  3. Use Admin API, CLI, harness, or audit search instead of direct database inspection.
  4. Preserve deny, disabled, revoked, or blocked state until the source-backed fix is known.
  5. Record safe resource IDs, redaction status, whether upstream was attempted, and the V1 boundary.
SymptomCheckFail-closed action
Docs missing or staledocs harnessLink the missing source and keep the page draft until source exists.
Identity missingidentity/policy/revocation eval or /v1/identity/me source flowDeny discovery and calls until IdP or local identity refs validate.
Policy deny unclearpolicy simulation plus deny diagnosticsPreserve deny and review Cedar version/context.
Credential unavailablecredential-binding statusBlock new calls and rotate, reapprove, or revoke the binding.
Connector disabledconnector status and impactKeep route unavailable until lifecycle and health are source-backed.
API import rejectedOpenAPI import diagnosticsFix selection, approval, host allowlist, schema, timeout, size, or credential mapping before publish.
SIEM/export deniedaudit export or telemetry/SIEM checkPreserve local audit metadata and fix customer export refs.
Session drain issuereconnect/drain/terminate evalReject new stateful sessions and finish drain or rollback.
Secret scan failurefull harness or no-secret gateRemove retained material and keep only metadata.
  • The same failing command is rerun without changing inputs or reading the first failing check.
  • A denial is “fixed” by weakening policy, broadening host allowlists, disabling schema checks, or bypassing credential binding state.
  • Support packets include tokens, prompts, request bodies, response bodies, tool payloads, customer data, screenshots with secrets, or copied private payloads.
  • A public page cites internal workpads or raw evidence instead of curated source docs.
  • Troubleshooting introduces a non-V1 dependency to recover a path that should fail closed.

Type set in Geist, Source Serif 4, and Departure Mono.