“Connection expired”

The connector's access token expired and claude.ai did not get a new one, so it asks the user to sign in again. The three common causes: (1) The authorization server issues no refresh token, so there is nothing to refresh with. To tell: The doctor warns that the refresh_token grant is not advertised. (2) claude.ai does not refresh on its own, even with a valid refresh token, so the connection lapses daily. To tell: Your identity provider issues refresh tokens and a manual refresh succeeds; see #65036 and #228, both open. (3) The token was revoked (or the registration deleted) and the error is reported as an expiry. To tell: Your identity provider's log shows a revoked token or an invalid_grant on refresh. One command shows which step breaks: npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client claude-ai.

Check your server now

npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client claude-ai

Discovery only: no credential, no client registration. It prints the first broken step, whose it is, and the fix with the spec section.

Who prints it

claude.ai web and Claude Desktop. 9 issues in anthropics/claude-ai-mcp, counted 8 October 2026.

The three causes, and how to tell them apart

  1. Cause 1. The authorization server issues no refresh token, so there is nothing to refresh with.
    The check fails at step refresh-grant. The doctor warns that the refresh_token grant is not advertised.
  2. Cause 2. claude.ai does not refresh on its own, even with a valid refresh token, so the connection lapses daily.
    The check cannot see this one from outside: it happens after consent, or inside the client. Your identity provider issues refresh tokens and a manual refresh succeeds; see #65036 and #228, both open.
  3. Cause 3. The token was revoked (or the registration deleted) and the error is reported as an expiry.
    The check cannot see this one from outside: it happens after consent, or inside the client. Your identity provider's log shows a revoked token or an invalid_grant on refresh.

Public reports

Keep checking

Re-check it every hour and email me when a step breaks: agentcheck's free watch, no account — it follows the sign-in a new client follows, with these same rules.

Nightly, with history: mcpcheck Server Pro re-runs these sign-in checks against the server every night, with 90 days of history, and emails when one fails ($49 a server a month; the first run is free).

Other messages

Written 8 October 2026 from the public issues above. The sign-in check · MCP Liveness · Terms · Privacy