Earliest supported layer
Rules distinguish availability, discovery, parsing, configuration, dependency, connection, authentication, registration, exposure, activation, authorization, execution, and persistence.
Codex capability diagnosis
Paste only the redacted OAuth stage, HTTP status, provider, and callback outcome. Never paste access or refresh tokens.
Local redaction. Save only by choice.
Diagnosis workspace
Not checkedYour result appears here after you review and submit the sanitized evidence.
The connector reaches the OAuth callback, but the authorization-code exchange returns invalid_grant. No access or refresh token is included here.
The earliest supported failure is authentication: connection reached an identity boundary, but the current session did not establish a valid authenticated principal.
The supplied evidence names an unauthenticated response, token/grant failure, sign-in requirement, or OAuth callback/exchange failure.
Separate Codex sign-in from a connected provider's authentication before choosing a login or changing credentials.
Method and limits
Deterministic rules over your redacted evidence. What the tool cannot support, it declines to claim.
Rules distinguish availability, discovery, parsing, configuration, dependency, connection, authentication, registration, exposure, activation, authorization, execution, and persistence.
A rule must meet a deterministic threshold. Conflicting or incomplete evidence becomes partial or unknown; it is not converted into a confident root cause.
The site does not install capabilities, execute packages, contact private endpoints, edit configuration, or ask for credentials.
A diagnosis is stateless by default. Saved reports use random URLs, expire after seven days, can be deleted immediately, and are excluded from indexing.