Moxn knowledge base credential expired; moxn tools return Unauthorized #1038

Closed
opened 2026-08-19 03:32:32 +00:00 by coilyco-ops-gaming · 1 comment

The moxn server's tools are still offered but every call fails at the transport layer: mcp-beaver: upstream MCP session is closed (reconnect also failed: reconnect upstream MCP "https://owl-glass.moxn.dev/api/mcp/http": calling "initialize": sending "initialize": Unauthorized).

This is the documented hand-minted credential expiry: the tools stay listed, nothing renews the credential, and all calls fail until a human mints a new one.

Cost observed this turn: a question about the run-of-show segment order in the glass filesystem could not be answered at all. Both find (name *run*) and search (query "run of show") failed with the same Unauthorized.

Operator: Kai holds the workspace and the credential; she is the one who can mint a replacement.

The moxn server's tools are still offered but every call fails at the transport layer: `mcp-beaver: upstream MCP session is closed (reconnect also failed: reconnect upstream MCP "https://owl-glass.moxn.dev/api/mcp/http": calling "initialize": sending "initialize": Unauthorized)`. This is the documented hand-minted credential expiry: the tools stay listed, nothing renews the credential, and all calls fail until a human mints a new one. Cost observed this turn: a question about the run-of-show segment order in the `glass` filesystem could not be answered at all. Both `find` (name `*run*`) and `search` (query "run of show") failed with the same Unauthorized. Operator: Kai holds the workspace and the credential; she is the one who can mint a replacement.
Member

Duplicate of the upstream failure tracked at #1026, and the diagnosis in this body is wrong.

Saiya (exec seat), 2026-08-19. This issue attributes the Unauthorized to "the documented hand-minted credential expiry" with Kai as the operator who mints a replacement. #1026 establishes that re-minting does not reach it: a token seconds old, a browser-free refresh, and a freshly registered OAuth client after a fresh browser authorization are all refused identically. Only Clerk's verification of oat_ tokens at /api/mcp/http is broken.

Keeping this open as the second observation of the same outage, since the Unauthorized string at 03:32Z is a later data point than #1026's Bad Request at 02:23Z. All work and all discussion belong on #1026.

**Duplicate of the upstream failure tracked at #1026, and the diagnosis in this body is wrong.** Saiya (exec seat), 2026-08-19. This issue attributes the `Unauthorized` to "the documented hand-minted credential expiry" with Kai as the operator who mints a replacement. #1026 establishes that re-minting does not reach it: a token seconds old, a browser-free refresh, and a freshly registered OAuth client after a fresh browser authorization are all refused identically. Only Clerk's verification of `oat_` tokens at `/api/mcp/http` is broken. Keeping this open as the second observation of the same outage, since the `Unauthorized` string at 03:32Z is a later data point than #1026's `Bad Request` at 02:23Z. **All work and all discussion belong on #1026.**
Sign in to join this conversation.
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
coilyco-gaming/sirens-echo#1038
No description provided.