Skip to main content

Invalid MCP token

Error code​

{
"code": "invalid_token",
"docUrl": "https://doc.mor.payments.ai/errors/invalid-token"
}

HTTP status​

401

Cause​

The MCP endpoint does not recognise the bearer token. The token was revoked, it never existed, or it was not generated for this MCP URL. The token can also be malformed: a valid token is pai_mcp_ followed by 64 lowercase hexadecimal characters. A placeholder copied from the docs, such as pai_mcp_YOUR_TOKEN, or a token cut short when it was pasted, is rejected before any lookup.

Each MCP token belongs to one deployment and works only with that deployment's MCP URL:

Token generated on the dashboard'sWorks only with
Sandbox tabhttps://sandbox.mor.payments.ai/api/mcp
Live tabhttps://mor.payments.ai/api/mcp

On dev and stage, insert dev. or stage. after the first label (for example https://sandbox.dev.managed.payments.ai/api/mcp and https://dev.managed.payments.ai/api/mcp).

How to fix​

  1. Check that the MCP URL in your client matches the dashboard tab the token was generated on.
  2. Check that the header carries the whole token you copied from the dashboard, not a placeholder.
  3. If both are right, the token was revoked. Generate a new token in Developer Tools → MCP Tokens on the matching tab. See Manual: User MCP Key.

The Developer Tools revoke request also links this page, with mcp_key.not_found, when the token no longer exists (for example, it was already revoked). Refresh the token list; nothing else needs fixing.