ComponentsMCP serversEnd User Usage

Credential Recovery

Reconnect a broken app credential in one click, wherever Airia notices the problem.

Credential Recovery is how Airia notices when a connection you already set up stops working, and gets you back to a working connection in one click. An OAuth sign-in can expire, an API key can get rotated on the provider's side, or a setup step can go unfinished. Instead of leaving you to figure out which app broke and why, Airia flags it for you with a direct fix.

What triggers it

SituationWhat happened
Never connectedYour organization has this app available, but you haven't signed in or provided your own credentials yet.
Needs your sign-inAn admin already configured this app for your organization, but you still need to connect your own account to use it.
No longer validYou were connected, but your sign-in expired, was revoked, or the app's credentials were rotated on the provider's side.

Airia refreshes OAuth sign-ins on your behalf well before they expire, so most of the time you won't notice anything happening at all. Recovery only comes into play when that automatic refresh isn't possible, usually because access was revoked or changed outside of Airia.

Where you'll see it

Where the connection is being used determines how you're notified:

  • In Airia Chat, a banner appears above the chat box naming the app that needs attention, with a button to fix it right there.
  • In an external AI tool (like Cursor or Claude Code) connected through an MCP Gateway, the assistant's response includes a link explaining that a specific tool needs reconnecting, along with a URL you can use to fix it.
  • In MCP Self-Service, the affected app's status shows that it needs setup or reconnection, so you can spot and fix it any time, even if you never saw a banner.

A broken connection only affects that one app. Everything else you've connected keeps working normally, and the rest of your chat session or tool call isn't interrupted.

Diagram showing the MCP Gateway returning a synthetic tool with a reconnect link to the MCP client, instead of a dead end or a 401 error, so the end user can reconnect Salesforce in two clicks and pick up where they left off

Watch the full 5-step walkthrough ↗

Fix it

Click Connect on the banner, or the link you were given.

Sign in again, or provide a new API key if that's how the app authenticates.

Once it succeeds, the banner clears and the app is ready to use again immediately. You don't need to retry your original request from scratch.

If a recovery link sends you to MCP Self-Service, the affected app opens automatically, so you do not have to hunt for it. Open Apps if you want to browse the rest of your catalog instead.

Before you finish reconnecting, Airia shows you the exact permissions the app is requesting, the same as any other sign-in, so you can confirm nothing has changed.

Personal connections only

Credential Recovery applies to your own personal sign-in or key for an app, not to shared, Tenant-level configurations an admin set up. See Tenant vs. Personal App Credentials for how the two relate. If a Tenant-level connection itself stops working, that's on your admin to fix.

If several of your connected apps share one underlying sign-in (for example, multiple Google tools), reconnecting once clears recovery for all of them.

Manage your connections

Everything described here happens through MCP Self-Service, at https://airia.ai/gateway/mcp-self-service. You can always check the status of your connections there, whether or not you have been prompted by a recovery banner.

Was this page helpful?

On this page