Workspace tools · Install and connect troubleshooting

Install and connect troubleshooting

Every failure the local app or the hosted app can show you has a word, and each word has one fix. This page lists them in the order a new install meets them: the app itself, the binding to a team, then each connected source.

The local app does not start, or the browser cannot reach it

  • The page at localhost:4000 does not answer. The desktop app runs its own server on port 4000. Another program on that port stops it; close the other program or set a different port in the app's settings, then open the address the app shows.
  • The daemon status says stopped. Open the daemon page. The app collects with its window closed only while the daemon runs; a stopped daemon means no new evidence, not lost evidence.
  • The update check says the feed is unreachable. The checker follows the feed's redirect. If your network blocks the download host, the app keeps running the version it has and says so on the update page.

A local page is still loading after startup

Startup prepares a small set of repository and source-status reads when memory permits. The Today queue can reuse its repository's prepared result. Other filters or reads may still need to run, and a slow preparation request times out and defers the remaining optional preparation to page use. This does not mean every page is fully prepared.

Reads carrying a session or approver credential run again instead of reusing a shared response, so the current viewer is checked. A warm queue is not an approval or an evidence-delivery receipt.

The machine is not bound to a team

A binding is one device token issued when you connect the desktop app to a team. Without one, every team read on the local app answers a stated zero state: not bound, never an error. Connect from the team's connect page.

  • 401 on a device read. The token is unknown to the service. Reconnect the device.
  • 403 on a device read. The token expired or was revoked. A revoked token keeps working through a short grace window so a rotation does not drop evidence; reconnect before it ends.
  • Repository outside your scope. A member reads only the repositories their team scope allows. An owner widens the scope on the team page; the app never widens it for you.

A source shows a health word

Each connected source carries one health code, the same code on both apps, chosen from what the provider answered rather than from its error text. The word is the fix.

unauthorized
The provider rejected the credential (a 401). Re-enter or rotate it on the connectors page.
denied
The provider denied the read (a 403) for a permission or a repository setting. The credential is fine; the setting on the provider's side is not.
scope
The credential lacks a scope the read needs, and the provider named it. Reissue the credential with that scope.
revoked
The app already knows the credential needs re-authorization and did not attempt the read. Reconnect the source.
rate_limited
The provider asked to slow down. The local app waits one, two, four, eight, then sixteen minutes between attempts; nothing to do but wait.
malformed
The provider answered with a page the reader could not parse. The page is kept as a dead letter so the failure is a row you can inspect, not only a word.
fetch_failed
The read did not complete: a network fault or a provider outage. It retries with the same backoff.
no_credential, vault_not_configured, decrypt_failed
Nothing to read with. Store a credential, configure the vault, or re-enter a credential the vault can no longer decrypt.
no_repo_mapping
The connector is not mapped to a repository, so its receipts have nowhere to land. Map it on the connectors page.
redaction_failed
Redaction failed and nothing was stored. The page is not kept; the read is retried.

After five consecutive failures the local app parks the source: it stops retrying and says parked with the last code, until you fix the cause and pull again. A parked source is not a silent one.

What a quiet source means

A source with no health word and no receipts is observing nothing, which is a different fact from observing zero incidents. Today shows a class with no observing source as no source, never as zero. The distinction and where each home draws it are on No data is not no incidents.

Which sources each app can read, and which reads are blocked and why, is the supported adapters and capture page.

Local pages after a restart

A page can show its last successful read while fresh data loads. Check its freshness label before treating a cached result as current. Response caches have entry and byte limits; oversized responses are served without being retained in that cache. These limits are not a cap on total app RAM. Refresh after reconnecting if a page still reports stale or unavailable data.

An incident changed before your update was saved

Another writer may have updated the incident while your action was running. Refresh the case and review its latest state before retrying a rejected edit. RepoOps refuses a stale replacement so it cannot erase the other update.

If a playbook reports that its actions ran but its timeline could not be saved, inspect the action results before running it again. A failed timeline write does not undo those actions. Hosted decision sync retains failed local saves for retry.

Last updated