Skip to content

Troubleshooting ​

This page is by what you see. Find the words your AI client or the management page showed you, and read what they mean and who can fix it.

How to read a refusal ​

When the server does not allow something, it says so in a sentence, and the AI client passes that sentence on to you. Most refusals:

  • start with Refused:;
  • say what was asked and why it is not allowed;
  • end with who can change it. For a limit or a switch that is the address of the page of the management site where an administrator changes it, followed by "A tool call cannot change it." That last sentence is true: asking the AI client again, or in other words, does not help.

An error that starts with Meta Graph API error:, LinkedIn API error: or Google Ads API error is the platform's own answer. The first line is the platform's words; the lines after it are the server's advice.

Three places show you more:

  • My activity keeps every change that failed, with the reason. See The activity log.
  • Notifications keeps what the server found while you were away: a queued post that failed, a connection about to end.
  • Test connection on each connection page asks the platform what your login can reach, and lists a permission your connection lacks.

The AI client cannot use the server ​

"Not authenticated" ​

The client sent no token, or one the server does not know. Create a token on MCP tokens and put it in the client's configuration: see Connect an AI client. A token is shown once. If you lost it, revoke it and create another.

Codex and OpenCode read the token from the environment variable NAMA_MARKETING_TOKEN. If it is not set, or the client was started before you set it, they send no token. Set it, open a new terminal and start the client again: see Keep the token in an environment variable.

"The account ... is disabled" ​

An administrator disabled your user. Your tokens stop working until they enable it again on Users. Nothing of yours was deleted.

The client cannot connect at all ​

  • Check that the server is running: open the management page in a browser.
  • Check the address. It ends in /mcp, and it is the one MCP tokens shows.
  • An address that begins http://127.0.0.1 works only on the machine the server runs on. A client on another machine needs the server's public address: see Server settings.
  • Claude on the web and the Claude desktop app connect from Anthropic's servers, not from your machine. They need the public address even when they run on the server's own machine: see Claude on the web and the Claude desktop app.
  • The server speaks HTTP only. A client that wants to start the server as a program of its own cannot use it.

The AI client says it has no tool for that ​

Some tools are not offered at all in two cases, so the client cannot call them:

  • the whole server is in read-only mode (Read-only server on Safety limits);
  • Reporting only is on for Meta Ads or LinkedIn Ads, which leaves out the tools that change ads on that platform.

Both take effect when the server starts. An administrator changes the setting and restarts the server. See Limits and switches.

You are not allowed to make changes ​

"this server is running in read-only mode" ​

Every change is refused for everyone. Reading still works. An administrator switches it off and restarts the server: see Server settings.

"writing is not enabled for ..." ​

Your user may read and may not change. An administrator ticks May write for you on Users: see Users and access.

LinkedIn: "LinkedIn refused this change" ​

LinkedIn names two possible causes and the server cannot tell which:

  • your role on the ad account is Viewer, which can only read. A role is given in LinkedIn's Campaign Manager, not here;
  • LinkedIn still has the app in the Development tier of its Advertising API, which may change at most 5 ad accounts. LinkedIn decides when it grants more.

Reconnecting LinkedIn helps with neither.

A platform is not connected ​

"has not connected a Google account yet" (or Meta, or LinkedIn) ​

Each person connects their own accounts. Open the connection page of that platform and press Connect Google, Connect Meta or Connect LinkedIn. See Google, Meta, LinkedIn.

"This installation has no ... credentials yet" ​

The administrator has not finished setting up that platform's app. Nobody can connect until the app's id and secret (and, for Google Ads, the developer token) are saved on Google Ads API, Meta app or LinkedIn app. The first part of each connection guide is for the administrator.

"The Google connection ... was not granted Google Ads" ​

Your Google connection was made for website analytics only, or the Google Ads box was unticked when Google asked. Open Google connection, press Reconnect Google, and accept Google Ads.

The platform refuses the sign-in itself ​

  • Google or Meta complain about the redirect address. The address the app was given at the platform must be exactly the one the app's page in the management site shows. It has to be HTTPS, or this machine itself (localhost). If the server's Public URL changed, the address changed with it.
  • Meta lets only some people sign in. While the Meta app is in Development mode, it works only for people who have a role on the app. For everyone else Meta wants each permission approved through App Review.
  • LinkedIn refuses everyone. LinkedIn refuses the whole sign-in when the app asks for a permission LinkedIn has not approved. An administrator turned on a switch on LinkedIn app before LinkedIn approved its product: turn it off again until the approval arrives.

A connection ended ​

"Your Meta connection is no longer valid" ​

Meta gives no way to renew a connection. It ends after about 60 days, or sooner when the Facebook password changes or the access is removed at Meta. Open Meta connection and connect again. The page and a notification warn you before the date.

"Your LinkedIn connection is no longer valid" ​

The server renews a LinkedIn connection by itself where LinkedIn allows it, but the sign-in ends for good a year after it was made, or when it is revoked at LinkedIn. Open LinkedIn connection and connect again.

"Google OAuth refresh failed" or "Google refused the sign-in" ​

Google no longer accepts your connection: the access was removed in your Google account, the password changed, or the consent screen of the Cloud project is still in Testing, where Google ends a sign-in after a few days. Open Google connection and connect again.

What a lost connection takes with it ​

A connection that ended by itself deletes nothing: reconnect and things carry on. Posts in the Queue, alert rules, lead feeds and watched accounts that need that platform fail or stop until then, and the server tells you once. Pressing Disconnect is different: it deletes what the server kept from that platform for you.

A permission is missing ​

"needs the ... permission ..., which your connection was not granted" ​

The installation asks for this permission, but your connection does not hold it: you connected before it was asked for, or you unticked it. Reconnect on that platform's connection page and accept it when the platform asks.

If the platform never asks, the app does not have the permission yet. For Meta an administrator adds it to the app, and for people without a role on the app it needs Advanced Access through App Review. For LinkedIn the app has not been approved for that product. The platform decides.

"which this installation does not ask for" ​

The permission sits behind a switch that is off, so reconnecting cannot grant it. An administrator turns the switch on first; the refusal names it and gives the address of its page. After that, everyone who needs the permission reconnects. See Limits and switches.

Meta: "The Meta app is missing a permission for this, or you do not have the right role" ​

Meta refused and does not say which of the two it is. Press Test connection on Meta connection: it lists any permission your connection lacks. If nothing is missing, the cause is your role on that Page or ad account, which is given at Meta.

LinkedIn: "You have no role on that ad account" or "the right role on that Page" ​

Test connection on LinkedIn connection shows your roles. A role on an ad account is given in Campaign Manager, and a role on a Page on LinkedIn itself. Page statistics need the administrator role on the Page.

Google: "The connected Google account cannot access ..." ​

The Google login you connected does not reach that Google Ads account. Check the account id. Check the manager account id on Google connection: clear it to see everything the login can reach. Or connect the Google login that has access.

A switch is off ​

"is switched off on this installation" ​

The capability is optional and an administrator has not allowed it. Most of these are off on a new installation: comments, Instagram delete, messages, hashtag search, Meta Ads, the Advertising API for LinkedIn, reading leads, sending conversions, customer lists, pushing leads, History, website analytics.

The refusal says what the capability would send and where, and ends with the page that holds the switch. Only an administrator can turn it on. Some switches add a permission to the sign-in, so everyone reconnects afterwards; Limits and switches says which.

A limit refused the change ​

Limits are set by the administrator on Safety limits. A request cannot raise one.

"exceeds the configured cap" ​

A Google Ads budget, bid, target or bid adjustment is above the installation's ceiling. Ask for a lower value, or ask an administrator to raise the limit. Lowering a value is never refused by these limits, even when the lower value is still above the ceiling.

"is a ...% change, above the configured limit" ​

One request may raise a budget only so far. Raise it in smaller steps. The Meta Ads refusal tells you the most this one request could set.

"a currency with no limit is not unlimited" ​

On Meta Ads and LinkedIn Ads, money limits are set for each currency. A currency with no entry is not unlimited: budgets and bids in it are refused until an administrator enters a limit for that currency on Safety limits. See Limits and switches.

"is not in Meta's table of ad account currencies" ​

The server does not know how Meta counts amounts in that currency and will not send one. Reading that ad account still works; changing budgets on it does not.

"above this installation's highest total" ​

Switching this on, or raising it, would take the daily budgets running on the ad account above the installation's total. Pause something else, lower a budget, or ask an administrator.

"would let the ad set run for ... more days" ​

The end date is further away than the installation's longest run. Give an earlier end.

"have already been published for you ... in the last 24 hours" ​

You reached the daily cap for posts, comment replies or messages. Each has its own cap, counted over the last 24 hours. Wait, or ask an administrator to raise it under Posting limits.

A similar refusal comes when you schedule a post into 24 hours that are already full: choose another time, or cancel one of the posts waiting there.

"the text is ... characters, above the configured limit" ​

Shorten the post, the reply or the message.

"you have not previewed in the last 24 hours" ​

On Meta Ads and LinkedIn Ads, an ad is switched on only after you have seen what it looks like. Ask the AI client to preview the ad, look at it, and then ask again to switch it on. An administrator can switch this requirement off (Require a preview before an ad is switched on).

Posting and media ​

"This server has no public https address" ​

Instagram does not take an uploaded picture. It fetches the picture from an address on the internet, and your server has none to give. This is not a limit and not a switch. Either:

  • an administrator gives the server a public HTTPS address on Server (see Server settings); or
  • you give the picture as a public https:// link of its own; or
  • you post it to Facebook, which does take uploads.

A video from your library works either way. See Media.

"must be an https:// URL" or "points at the private address" ​

A media link must be public HTTPS, because Meta downloads the file itself. A link to your own network or your own machine is refused. Upload the file on Media instead.

"this server has no media folders" or "is outside the server's media folders" ​

A file can be taken by its path only from a folder the administrator named under Media folders on Meta app. Otherwise upload the file on Media and ask the AI client to use it from there.

"Instagram accepts only JPEG images" ​

Instagram takes JPEG only. Ask for the picture to be converted, and the server posts a JPEG copy; your original stays in the library. See Media.

The time of a scheduled post is refused ​

Facebook does not take a scheduled post that is only minutes away or too far ahead, and the queue for Instagram and LinkedIn has its own furthest date. The refusal names the limit. Give a time with its time zone, such as 2026-10-01T09:30:00+02:00.

A queued post is Failed or Missed ​

The server never tries a queued post twice by itself. Open Queue: the row says why. Fix the cause (a connection that ended, the daily cap, a file that is gone) and press Publish now, or move it. See Scheduling.

"Meta did not answer within ... seconds" ​

The request may have gone through. Look at the Page or the account before you ask again, or you may post twice.

Messages ​

"the 24-hour window closed at ..." ​

Meta lets a Page reply to a person for 24 hours after that person's last message. After that, only the person writing again opens the window. The server does not use Meta's longer seven-day window. See Inbox.

Throttles and quotas ​

In every case here the cure is to wait. Asking again at once makes it worse, because each attempt is counted.

"Meta is rate-limiting this app" ​

Where Meta says how long, the refusal gives the minutes. Ask for one report with a breakdown rather than a report for each campaign.

"That report is more than Meta will work out in one request" is different: ask for a shorter period or fewer breakdowns.

"LinkedIn is rate-limiting this app" ​

LinkedIn counts calls for an app and for a person over a day, and starts again at midnight UTC. While LinkedIn has the app in its Development tier the allowance is small. LinkedIn also limits how many comments one person may post in a minute.

"is out of quota" (Google Analytics, Search Console) ​

The refusal says when the quota refills: within the hour, or tomorrow. See Website analytics reports.

The hashtag search is refused before it is tried ​

Instagram lets one account look up 30 different hashtags in 7 days. The server counts them and refuses the thirty-first, with the time the oldest stops counting. Looking up a hashtag you already used this week costs nothing. See Listening.

Google's and LinkedIn's APIs ​

"is not enabled on the Google Cloud project" ​

An API has to be switched on in the Google Cloud project behind the installation's OAuth client. An administrator opens the Cloud console, APIs & Services, Library, finds the API the refusal names and enables it. It works a few minutes later.

  • Website analytics needs three: the Google Analytics Data API, the Google Analytics Admin API and the Search Console API. See Website analytics.
  • Uploading conversions and Customer Match lists to Google needs the Data Manager API.

"Your developer token still has Test access" ​

The developer token works only with Google Ads test accounts until Google approves a higher access level. The administrator applies in the API Center of the manager account that owns the token. Google decides. See Google.

The lines under it are Google's own, one for each thing it refused, with the field where it names one. In a preview this is Google checking the change before anything is made: nothing was changed. Correct what Google names and preview again.

"LinkedIn no longer accepts API version ..." ​

LinkedIn retires each version of its API after a year. An administrator raises API version on LinkedIn app to a current one. See LinkedIn.

Webhooks, mail and lead delivery ​

"must be an https:// address" or "is this machine or its own network" ​

The server sends by itself only to a public HTTPS address. If the receiver really is on the server's own network, the administrator ticks Allow a private address. Plain http:// is accepted only for the server's own machine.

A notification or a report did not arrive ​

The notification itself is always on your Notifications page; the webhook and the mail are a courtesy, tried once. An administrator presses Send a test on Notification delivery to see what the webhook or the mail server answers. See Notifications.

Leads stopped reaching your system ​

A lead feed that fails tells its owner once and keeps trying, waiting longer each time. Nothing is lost meanwhile: the server keeps no leads, and reads them from the platform again when the receiver is back. Send a test lead on Lead delivery shows what the receiver answers. See Lead delivery.

Files of contact data ​

"this server has no data folders" or "is outside the server's data folders" ​

A file of customer records is read only from a folder the administrator named under Data folders on Server. Put the file there, or give the rows in the request itself.

"the data folder ... and the media folder ... are the same folder" ​

A data folder holds people's details and a media folder holds what may be posted, so the two may not be the same folder or one inside the other. The administrator names separate folders. See Contact data.

"This file, byte for byte, was already sent" ​

A file of conversions that was already sent to the same destination is refused, because the platforms count a conversion sent twice as two. If you do mean to send it again, say so. See Conversions and customer lists.

If you are still stuck ​

Give your administrator:

  • the refusal or the error, word for word;
  • the time, and what you asked for;
  • the row from My activity, if there is one;
  • for a platform's error, the id at its end (Meta's trace id, Google's request id). The platform's own support asks for it.

The Questions and answers page covers what is not an error.