Authentication
Permissions and authorization
TOOL_CALL_FORBIDDENwithretryable: false— the key or member lacks the underlying grant. Add the grant on the key (or use an OAuth session with permission); retrying the identical call won’t help.ws-users listworks butowner set/grantfails — discovery needsworkspace_members:read; collaboration writes needcustomer_access:manage. They are separate grants and the full flow needs both.- A key can’t see what its creator sees — API keys are independent principals and do not inherit the creator’s permissions or customer access.
- Writes reject names/domains — mutations take exact UUIDs (
customers owner set <uuid> --target-user-id user_…). Resolve IDs withcustomers get/ws-users listfirst.
Empty or partial results
CLI output and scripting
- Expected JSON but got a table — pass
--jsonexplicitly, or ensure one auto-trigger: piped stdout,CI/GITHUB_ACTIONSset, orTERM=dumb. outlitin a cron/CI job exits non-zero — JSON errors go to stderr as{"error": …, "code": …}; all failures exit1. See the error-code table.doctorreports a missing skill — runoutlit setup <agent>(e.g.openclaw,claude-code,codex,gemini,droid,opencode,pi,skills).
MCP setup
- Wrong URL shape — it is workspace-scoped:
https://mcp.outlit.ai/w/<workspace-slug>/mcp, copied from Settings → CLI & MCP. A baremcp.outlit.aiURL is not valid. - Tools visible but calls forbidden — OAuth runs as the signed-in member; API-key calls use the key’s grants. The catalog is identical either way; authorization is not.
- This is not the docs search MCP — the docs site hosts a separate search-only MCP endpoint. It has no customer tools; use the workspace URL above for product data.
Tracking and ingest
Identity mismatches
- Duplicate customers appearing — check
outlit identity suggestions list; reject wrong pairs withsuggestions reject <id>, merge real duplicates withcustomers merge(preview first). - User events attributed to the wrong account — Outlit Browser SDK and Outlit server SDK
identify()acceptcustomerIdfor explicit account attribution; Outlit server SDKtrack()does too. - Personal-email domains —
user@gmail.comresolves to an individual customer keyed on the full address, not agmail.comcompany; expect separate customers per personal email.
Customer workflows
Working workflows to compare against
MCP integration
Connection and auth detail
