TROUBLESHOOTING

Fix “endpoint not authorized” errors

QueryWarden rejects a direct endpoint when the private identifier is invalid or the request source does not match its access policy. Relay credentials have a separate enrollment and rotation lifecycle.

Available now Account owners and device administrators
BEFORE YOU START

Prepare the safe path

  • Use a trusted signed-in dashboard session.
  • Do not paste the rejected endpoint into public diagnostic tools.
  1. 1

    Confirm the endpoint was copied completely

    Compare the client configuration with the selected device setup value without sending either value elsewhere. Missing path characters, an older rotated value, or the wrong device endpoint will be rejected.

  2. 2

    Review Source access

    Open the device Source access control. If restricted, confirm the current public IPv4 or IPv6 source is represented by an approved entry.

  3. 3

    Decide whether to update access or rotate

    Update the approved source when a legitimate network changed. Rotate the endpoint when its private value may have been exposed or an unknown client used it.

  4. 4

    Replace the client configuration

    After rotation, the old endpoint stops working. Install the new value on the intended client and remove old copies from password managers, configuration systems, or tickets where appropriate.

  5. 5

    Check fresh endpoint activity

    Select Start traffic check and generate a new request. Confirm the selected device reports recent activity before closing the trusted session.

WHAT SUCCESS LOOKS LIKE

Confirm the result

The intended device uses a current private endpoint from an authorized source, while obsolete or disallowed requests remain rejected.

SECURITY NOTES

Protect the account while you work

  • Rotation is the correct response to suspected endpoint disclosure; adding Any IP does not invalidate a leaked identifier.
  • Never ask QueryWarden support to test the complete private endpoint on your behalf.
TROUBLESHOOTING

When the expected result does not appear

The public IP changes repeatedly.

Use Any IP with strict endpoint secrecy, a deliberate supported network range, or an architecture better suited to roaming. Avoid constant broad allowlist edits.

The old endpoint still appears in a client.

Clear the DNS client configuration, restart it if required, and confirm the complete new URL is active.

Relay reports a credential error.

Use Relay enrollment or credential rotation in the Relay workspace; direct-device source-IP steps do not replace Relay credentials.

PRODUCT STATE

Capabilities used in this guide

Private device endpoints · Available nowSource IP restrictions · Available now