WORKING MACHINES TROUBLESHOOTING

Codex MCP authentication failed

Codex knows about the Working Machines MCP server but cannot finish login, repeatedly opens consent, or returns an authentication error when it tries to discover tools.

Likely causes

  • The configured server name does not match the name used by the login command.
  • A previous authorization attempt left stale local credentials.
  • The browser callback was closed before consent completed.
  • The configured URL, OAuth resource, and issued token do not identify the same MCP endpoint.

Check first

  • Inspect the Codex MCP server list and confirm the exact configured name.
  • Confirm the URL uses HTTPS and ends with /mcp.
  • Confirm the authorization popup shows Working Machines and the intended Codex client.
  • Check that the system clock and browser session are valid before retrying.

Resolution

  1. 01Remove the stale Working Machines authorization from Codex.
  2. 02Add or confirm the remote server configuration.
  3. 03Run Codex MCP login for the exact configured server name.
  4. 04Complete sign-in and approve only the scopes shown on the consent screen.

Verify the fix

  • Codex reports Working Machines as authenticated.
  • A read-only discovery request succeeds.
  • The first provider action uses the intended named connection.

What to include in a support report

Record the client name and version, the MCP endpoint hostname, the time of the failed attempt, and the exact error text. Include the affected provider and action when relevant, but remove authorization headers, cookies, OAuth codes, API keys, and provider data. This evidence distinguishes configuration, authorization, connection, and provider-permission failures without exposing credentials.

Related resources

ONE CONNECTION. REAL WORK.

Give your agent software it can use.

Connect through MCP or explore the Agent App catalog and choose only the capabilities your workflow needs.

EXPLORE AGENT APPS