Most MCP problems are key or permission issues. Here are the common errors and what to do about them.
Authentication failed (invalid or unknown key)
The key is mistyped or truncated. Copy it again — but note that keys are only shown once at generation, so if you no longer have it, regenerate the key under Settings → MCP API Access and update your client.
"This API key has been revoked" / "was rotated and replaced"
The key was revoked (by you or an administrator) or replaced by a regeneration. Generate a new key, or update the client to the key shown at regeneration.
Permission denied
The key was never given the permission the tool needs (for example, label creation). Regenerate the key with the needed permissions — adding permissions always requires a new key.
Insufficient permission ("permissions have changed")
The permission is on the key, but your ShipCelero permissions changed since — for example your role was reduced or billing was hidden for your account. The affected permission shows as Inactive on the settings page. Restore the underlying permission, or regenerate the key with fewer permissions.
Account suspended
The customer account behind the key is suspended. Contact support@shipcelero.com.
Too many failed authentication attempts
Repeated failures temporarily block authentication for about a minute. Fix the key in your client configuration, wait, and try again.
Confirmation expired right after review
The draft or your quota changed between the review and the confirmation (for example, another label was booked in the meantime). Ask the assistant to run the review again and confirm the updated summary.
Label download link returns 404
Signed label links expire after about 15 minutes. Ask the assistant for the label again to get a fresh link.