{"title":"Troubleshoot an agent connection","slug":"troubleshoot-an-agent-connection","url":"https://support.storeconnect.com/articles/troubleshoot-an-agent-connection","url_markdown":"https://support.storeconnect.com/articles/troubleshoot-an-agent-connection.md","subtitle":null,"summary":"Fix an AI agent that cannot connect to your store over MCP, or that connects and then cannot do what you asked. Organized by the message you were shown, so you can go straight to the cause: a refused token, a user with no editing access, a client StoreConnect has not allowed yet, an address that names no store, an expired session, and a permission change that has not taken effect.","type":"AI","video_url":"","keywords":"mcp troubleshooting, agent will not connect, cannot connect ai agent, token not valid, token inactive, no editing access to this store, redirect address is not on this store\u0026#39;s allow list, allow list, no store is configured, several stores share, different endpoint, sign in refused, oauth error, session expired, agent stopped working, agent cannot find, permissions boundary, connection failed, mcp error","last_modified":"2026-09-18T03:49:59+0000","body_markdown":"Use this article when an AI agent cannot connect to your store, or connects and then cannot do what you asked. Start from the message you were shown rather than retrying, because each cause has its own fix and retrying changes none of them. To set a connection up in the first place, see [Connect an AI agent to your store](connect-an-ai-agent-to-your-store).\n\nMost failures are one of three things: the token, the access behind it, or the address. The message tells you which.\n\n## The sign-in screen refuses the connection\n\nThe sign-in screen names what failed, above the store it was about to grant access to.\n\n### That token isn't valid or is inactive\n\nThe token is wrong, has been turned off, or has passed its expiry. Reveal the current value again from **Your agent access** in the StoreConnect Console and check the state shown beside it. Disabling or resetting access replaces the token, so a copy saved earlier stops working once an administrator has done either. Paste the current value, not one from a password manager entry you have not updated since.\n\n### This user has no editing access to this store\n\nThe token is fine. Your user has no **Store Role** of type `Content Changes` covering the store at that address. Ask an administrator for one, at `Editor` level to stage changes or `Approver` level to publish them. See [Store roles](store-roles).\n\nThis message is about the store at the address you signed in at, not about every store. On a shared domain, a role that covers your store does not help if you signed in at another store's path.\n\n### This client's redirect address is not on this store's allow list\n\nNeither your token nor your access is the problem. The product you are connecting from is not one StoreConnect accepts a browser sign-in for yet, and the list is StoreConnect's own configuration, so a store administrator cannot add to it. Email [support@storeconnect.com](mailto:support@storeconnect.com) with the product name and the address shown under the message.\n\nMeanwhile, the product can still connect by sending the bearer credential as a header. Copy it from **Your stores** in the Console rather than assembling it by hand.\n\n### This client asked to connect to a different endpoint than this store's\n\nThe client is pointed at one store and signing in at another. The message names the address the store expects. Correct the address in the client and start the sign-in again.\n\n## The address names no store\n\nAn address that names no store fails before your token is ever checked. Every message here means the address, not your access. For how addresses are built when several stores share one domain, see the shared-domain section of [Connect an AI agent to your store](connect-an-ai-agent-to-your-store).\n\n### No store is configured at this address\n\nThe path is wrong, or the store at it is not live. Your store's path is the **Path** field on its **Store** record (`s_c__Store__c.s_c__Path__c`), and it goes between the domain and `/mcp`. A store with nothing in that field is the one served at the root of the domain.\n\n:::warning\nThe **Store URL** shown in the Console leaves the path out, so on a shared domain it shows the root store's address for every store in the list. Add your store's path yourself before you connect.\n:::\n\n### Several stores share this domain and none is marked as the default\n\nYou used the domain with no path on it, and more than one store answers to that domain. Connect using your store's own path, or ask your administrator to mark one store as the default.\n\n### Your store's \"page not found\" page\n\nOpening `https://\u003cyour-store-domain\u003e/.well-known/mcp.json` and getting your store's own \"page not found\" page means the store is on a version earlier than v22 and has no endpoint to connect to. Nothing is broken, and retrying will not change the outcome. Email [support@storeconnect.com](mailto:support@storeconnect.com) or ask your implementation partner about upgrading. The version check is in [Connect an AI agent to your store](connect-an-ai-agent-to-your-store).\n\nThe skills toolkit still works while you wait, because knowledge does not need a connection. See [Install the StoreConnect AI skills](install-ai-skills).\n\n## The agent is connected but something does not work\n\n### The agent cannot perform an action\n\nIf an agent cannot perform an action, it is usually a permissions boundary rather than a fault. The agent works as you, so it can only do what your **Store Role** allows, on the stores that role covers. Ask your administrator to review the access for that store instead of looking for a workaround.\n\n### The agent stopped working partway through\n\nSign-in sessions expire after about eight hours. When a session expires, sign in again from your agent using your existing token. You do not need a new token.\n\n### A change to your access has not taken effect\n\nA session carries the permissions you had when you signed in. If your **Store Role**, its scopes, or the stores it covers have changed, sign in again from your agent so the change applies. Until you do, the agent keeps working with the old permissions.\n\nWhen the cause is fixed, the sign-in screen names your store and its address, you are prompted for your token, and your agent shows the connection as active."}