“Couldn't reach the MCP server”

claude.ai's servers could not complete a request to the MCP server or to one of its discovery documents; the request comes from Anthropic's network, not from your browser. The three common causes: (1) The host does not resolve publicly over IPv4: private or split-horizon DNS, or IPv6 only. claude.ai connects over IPv4 and refuses private addresses. To tell: Look up the host's A record from outside your network; the doctor run from inside it can still pass. (2) A firewall or bot protection blocks Anthropic's egress range (160.79.104.0/21) or answers it with a challenge page. To tell: The doctor reports a bot challenge on a metadata document, or your WAF log shows blocks from that range. (3) Discovery answers 404, or the WWW-Authenticate header was in a form claude.ai did not parse (a case-sensitive match over HTTP/2, reported fixed around 24 April 2026). To tell: The doctor fails at the challenge or at protected-resource metadata. One command shows which step breaks: npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client claude-ai.

Check your server now

npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client claude-ai

Discovery only: no credential, no client registration. It prints the first broken step, whose it is, and the fix with the spec section.

Who prints it

claude.ai and Claude Desktop. 17 issues in anthropics/claude-ai-mcp, counted 8 October 2026.

The three causes, and how to tell them apart

  1. Cause 1. The host does not resolve publicly over IPv4: private or split-horizon DNS, or IPv6 only. claude.ai connects over IPv4 and refuses private addresses.
    The check fails at step reachable. Look up the host's A record from outside your network; the doctor run from inside it can still pass.
  2. Cause 2. A firewall or bot protection blocks Anthropic's egress range (160.79.104.0/21) or answers it with a challenge page.
    The check fails at step prm. The doctor reports a bot challenge on a metadata document, or your WAF log shows blocks from that range.
  3. Cause 3. Discovery answers 404, or the WWW-Authenticate header was in a form claude.ai did not parse (a case-sensitive match over HTTP/2, reported fixed around 24 April 2026).
    The check fails at step www-authenticate. The doctor fails at the challenge or at protected-resource metadata.

Public reports

Keep checking

Re-check it every hour and email me when a step breaks: agentcheck's free watch, no account — it follows the sign-in a new client follows, with these same rules.

Nightly, with history: mcpcheck Server Pro re-runs these sign-in checks against the server every night, with 90 days of history, and emails when one fails ($49 a server a month; the first run is free).

Other messages

Written 8 October 2026 from the public issues above. The sign-in check · MCP Liveness · Terms · Privacy