Everything about a connected agent is managed from Family → Agents. This article covers revoking access and the handful of things that go wrong when connecting.

Revoking an agent

  1. Open Family → Agents.
  2. Under Active authorizations, find the client by name and choose Revoke, then Confirm revoke.

Every token issued to that client is revoked at once. Its next call fails with an authentication error, and it has to go through the approval page again to reconnect. Work it already drafted stays in the queue and in the timeline.

Revoke when you stop using a client, when you replace a machine, or if you see calls in Family → Activity you do not recognise.

Tokens expire

Authorizations have an expiry, shown on the Agents page. Well-behaved clients refresh their token on their own. If yours stops working after a while and refreshing does not help, revoke it and connect again.

Common problems

The approval window never opens. Make sure a default browser is set, then trigger any tool call again. Some clients only try once per session; restarting the client helps.

The client says the server does not support dynamic registration. The client build is too old for HTTP transport with dynamic client registration. Use the mcp-remote bridge described in "Connecting an agent to Tutosaic".

Authentication error (401) on every call. The token is expired or revoked. Trigger a call so the client refreshes. If it still fails, the authorization was revoked: connect again from scratch.

The tool list is empty. The token was issued without the mcp:use scope. Check the scopes shown under Active authorizations, revoke, and approve again without changing the scope on the approval page.

The agent is throttled. It made more than the allowed number of writes in a minute for one tool. It receives a retry-after and the event shows under Family → Trust as a throttle event. Ask the agent to slow down or batch its work; nothing is lost.

Drafts never reach the queue. Either they fail the quality gate, visible in Family → Activity as gate-failed, or auto-approval is on for the family and they are already live. Check Family → Family.

The agent cannot find a student or subject. Agents address students and subjects by name within your family. Check the exact names under Subjects and on the student pages, or let the agent create the subject.

Before contacting support

Note the client you use, the time of the failing call and, if the client shows it, the error code. Family → Activity has the server-side view of the same call.