Errors

exact_user_client_organization_revoke_fails_closed

Exact user, client, and organization revoke is not safe against live WorkOS.

exact_user_client_organization_revoke_fails_closed means Everyn stored a per-organization MCP grant projection, but live WorkOS cannot uniquely identify that one grant. Deleting the WorkOS application or user authorization would revoke every organization grant for the same client.

Recovery guidance

Do not retry revoke. Continue from the host workspace (https://app.everyn.ai/w). /mcp/connect is only a failure landing page and cannot restart the connection. The local projection stays projected until a later product-review change makes exact revoke safe. The settings UI localizes the workspace handoff from action: open_workspace.