Skip to content

Troubleshooting

Practical fixes for the most common problems, organized by what you’re seeing. Every action mentioned here is recorded in your organization’s audit log, so if something you didn’t expect happened, that’s the first place to check who did it and when.

SymptomLikely causeWhat to check
”Invalid credentials” on email/password sign-inWrong password, or the account uses SSO/social sign-in onlyUse Forgot password? to reset it, or try signing in with Google/Microsoft if that’s how the account was created
Redirected back to sign-in after choosing your organization’s SSO optionYour organization’s SSO isn’t fully configured yet, or you picked an identity provider your organization hasn’t actually set upAsk an organization Owner or Admin to confirm SSO is enabled and which provider it’s configured for - see SSO
Asked for a 2FA code that no longer works, or you’re locked out after several failed attemptsThe code expired (codes are time-limited, usually 30 seconds), or you’ve hit a temporary lockout after repeated wrong attemptsWait for a fresh code from your authenticator app; a repeated-failure lockout clears itself after a short wait rather than staying locked permanently
Lost your authenticator app entirelyTwo-factor authentication can’t be disabled without a valid code from that deviceContact support - there’s no self-service recovery for this
”Account is not fully set up” or similar after signing inYour profile is missing required fields (name/surname)Complete the profile form you’re redirected to - it only appears once

See FAQ and Account security.

SymptomLikely causeWhat to check
Invitation link says it’s invalid or expiredThe invitation was revoked, already accepted, or expiredAsk the Owner/Admin who sent it to check its status and resend if needed
Signed in but not seeing the organizationThe invitation was accepted with a different email address than the one it was sent to, or wasn’t accepted at allConfirm which email received the invitation, and that you actually completed the accept step rather than just following the link
Accepted the invite but access seems limitedA pending invitation grants no access - only an accepted one does, and your role only takes effect once it’s acceptedCheck your role in the organization’s member list

See Organizations & teams.

SymptomLikely causeWhat to check
Validation reports “Invalid”Wrong key/secret value, a revoked or rotated token, or insufficient permissions on the credentialCompare against Credential permissions, regenerate the credential at the provider if you’re unsure it’s still valid
Credential stuck on “awaiting validation”Saving a credential doesn’t automatically validate itClick Validate on the credential’s row
Credential was valid, now everything using it failsThe provider-side key was rotated or revoked outside SencaiAdd a fresh credential with the new value and remove the old one - an existing credential’s secret can’t be edited in place

See Connect a cloud provider.

SymptomLikely causeWhat to check
Scan completes but the inventory is emptyThe credential is read-scoped too narrowly for the resource types you expected, or genuinely has no resources in the region(s) it can seeReview what permissions the credential actually has against Credential permissions
Scan never seems to runAutomatic scanning wasn’t turned on for that credential, and no manual scan has been triggered yetTrigger a manual scan, or enable automatic scanning on the credential
Some resources show up, others don’tDifferent resource types can need different permissions on some providersCheck the credential covers the specific resource type that’s missing

See Import existing infrastructure.

SymptomLikely causeWhat to check
Instance stuck in ProvisioningThe provider is taking longer than usual, or a step is genuinely failing silently upstreamGive it a few minutes; if it doesn’t resolve, check the instance’s activity log for the specific failing step
Instance moved to ErrorThe provider rejected the request (quota exceeded, invalid region/size combination, credential permissions)Read the error detail on the instance - it’s the provider’s own message, not a generic failure
Provisioning never starts at allNo cloud account is connected or selected, or the selected credential isn’t validatedConfirm a validated credential is connected - see Connect a cloud provider

See Provision & manage instances.

SymptomLikely causeWhat to check
Enrollment command failsThe enrollment token was already used, expired, or belongs to a different organizationGenerate a fresh enrollment token from the fleet agent settings - tokens are single-use
Enrollment fails to reach Sencai at allOutbound network access from the server is blockedConfirm the server can make outbound HTTPS connections - the agent never needs an inbound port opened
Agent enrolled but shows OfflineThe agent process stopped, the host lost network connectivity, or its connection is blocked after enrollmentOn the server, check the agent service is running (for example systemctl status sencai-agent) and that outbound connectivity is still available
Agent is online but not reporting a capability you expect (inventory, patch status, and so on)That capability hasn’t been granted to the agentAn organization admin needs to enable the specific capability from the agent’s settings

See Install & enroll an agent.

SymptomLikely causeWhat to check
No terminal option on a host you manageThe host isn’t registered in your organization as a cloud instance - the terminal is an instance feature, not a fleet-agent featureRegister or import it as a cloud instance; see Provision & manage instances and the prerequisites in Browser terminal
Terminal control is present but disabled on an instanceThe instance isn’t in a state the terminal can reach (only a running or imported instance qualifies), or the instance record has no address to connect toWait for it to reach Running; for an imported instance, have an admin set the connection details on the instance record
Terminal opens but the session never connectsThe platform’s access hasn’t been set up on the target host yet, or its SSH port isn’t reachable from SencaiSee the caution in Browser terminal; contact support if it should work and doesn’t
Terminal connects, but you get a permission errorYour organization role doesn’t include terminal accessCheck your role - see Roles & permissions

See Browser terminal.

SymptomLikely causeWhat to check
401 UnauthorizedThe token is missing, malformed, expired, or was revokedConfirm you’re sending the token as a bearer credential, and that it hasn’t been revoked from your organization’s API tokens settings
403 Forbidden on a read callThe token’s scope or your organization’s tier doesn’t include that resourceCheck the token’s scope, and whether the feature you’re calling is available on your organization’s current tier
403 Forbidden specifically on a write/mutating callThe token is read-only, or it’s read/write but AI-agent write access hasn’t been turned on for the organizationConfirm both: the token itself has write scope, and an Owner has enabled write access - see API tokens

See API tokens and AI agents.

SymptomLikely causeWhat to check
No deliveries arriving for a real event (an instance provisioned, drift was detected, and so on)Automatic dispatch for these event types isn’t live yet - registering an endpoint and choosing events works, but the platform doesn’t yet call your endpoint when the event happensUse Test on the webhook’s row to confirm your endpoint works; see the note in Webhooks
A Test delivery failsThe endpoint isn’t reachable from Sencai, or returned a non-2xx statusConfirm the endpoint is publicly reachable over HTTPS, then check the HTTP status code for that delivery on the Webhook Delivery Log screen
Signature verification fails on your endUsing the wrong signing secret, or verifying against the raw body incorrectlyRe-check the signing secret shown on the webhook’s settings against what your endpoint is configured with

See Webhooks.

SymptomLikely causeWhat to check
A resource exists but shows no costCost data for that resource hasn’t been ingested yet, or the resource type/provider doesn’t report cost data the way Sencai expectsGive it a billing cycle to appear; confirm the credential has the permissions needed for cost data on that provider
Costs look wrong or incomplete for the periodYou’re looking at a partial billing period, or resources are missing cost-allocation tagsCheck the date range you’re viewing, and see Cost allocation for tagging
Nothing shows up for an entire connected accountThe credential itself may not be validated, or has no cost-read permissionSee Cloud credential validation fails above

See Costs.

SymptomLikely causeWhat to check
No email notifications at allYour email preferences have that category turned off, or the address bouncedCheck your notification preferences in your profile settings
No notifications in a channel like Slack/TeamsThe integration channel isn’t configured, or its endpoint has been failingCheck the channel’s status in your organization’s notification settings - a repeatedly failing channel can be paused automatically
Some events notify you, others don’tNotification categories are configured individuallyCheck which categories are enabled for the channel or your personal preferences

See Notifications.

  • FAQ - shorter, common questions
  • Glossary - unfamiliar terms
  • Support - if none of the above resolves it