upstash/context7 · warning

not_found

not_found

Error message

Endpoint not found.

What it means

The /.well-known/openai-apps-challenge endpoint returns 404 (error code "not_found") when the OPENAI_APPS_CHALLENGE_TOKEN environment variable is not set. The route exists but has nothing to serve, so it reports the endpoint as not found instead of returning an empty challenge.

Solutions

  1. Set the OPENAI_APPS_CHALLENGE_TOKEN env var to the token value provided by OpenAI's domain verification and restart the server.
  2. Confirm the env var reaches the process (docker compose env_file, --env-file, systemd Environment=).
  3. Re-run the domain verification challenge after the server is up.

Example fix

// before
// (no env var set) -> 404 not_found
// after
# .env / shell
OPENAI_APPS_CHALLENGE_TOKEN=abc123-challenge-token
npm start
Defensive patterns

Strategy: validation

Validate before calling

if (!process.env.OPENAI_APPS_CHALLENGE_TOKEN) {
  console.warn('OPENAI_APPS_CHALLENGE_TOKEN not set; challenge endpoint will 404');
}

Try / catch

const res = await fetch(`${serverUrl}/.well-known/openai-apps-challenge`);
if (res.status === 404) {
  console.error('Challenge token missing on server: set OPENAI_APPS_CHALLENGE_TOKEN');
}

Prevention

When it happens

Trigger: GET /.well-known/openai-apps-challenge on an MCP server started without OPENAI_APPS_CHALLENGE_TOKEN in its environment (undefined or empty).

Common situations: OpenAI Apps SDK domain verification fails because the operator forgot to set the challenge token env var, or the server was restarted without the env loaded (e.g. missing in Docker/compose/systemd config).

Understand the failure class

Background: "environment variable is not set" and "Missing keys in environment" errors: what missing required env var messages mean and how to fix them — this error's family across 28 libraries.

Related errors


AI-assisted analysis of upstash/context7@4416fb855b (2026-09-16). Data as JSON: /api/errors/89f4292dc3086ad6. Report an issue: GitHub.

Appendix: source

Thrown at packages/mcp/src/index.ts:597

            });
          }
          res.json(upstream.metadata);
        } catch (error) {
          console.error("[OAuth] Error fetching OAuth metadata:", error);
          res.status(502).json({
            error: "proxy_error",
            message: "Failed to proxy authorization server metadata",
          });
        }
      }
    );

    // OpenAI Apps SDK domain verification challenge
    app.get(
      "/.well-known/openai-apps-challenge",
      (_req: express.Request, res: express.Response) => {
        if (!OPENAI_APPS_CHALLENGE_TOKEN) {
          return res.status(404).json({
            error: "not_found",
            message: "Endpoint not found.",
          });
        }
        res.type("text/plain").send(OPENAI_APPS_CHALLENGE_TOKEN);
      }
    );

    // Catch-all 404 handler - must be after all other routes
    app.use((_req: express.Request, res: express.Response) => {
      res.status(404).json({
        error: "not_found",
        message: "Endpoint not found. Use /mcp for MCP protocol communication.",
      });
    });

    let activeHttpServer: ReturnType<typeof app.listen> | undefined;
    installProcessShutdown(

View on GitHub (pinned to 4416fb855b)