debug-access-token
Installation
SKILL.md
Debug Access Token
Help a developer figure out why a Meta access token is failing — without ever handling the raw token yourself.
Security first — never handle a live token
An access token is a bearer credential: whoever holds it can act as its owner. Anything pasted into this chat enters the agent's context and is transmitted to the AI provider (logs, history, retention). Treat a token like a password.
- Do NOT ask the developer to paste an access token (or an app secret) into this chat. Inspect tokens using the developer-run options below, and ask only for the resulting metadata.
- If a token was already pasted, tell the developer to revoke/rotate it (Graph API Explorer, or the app dashboard → regenerate), then continue with the metadata flow below using a fresh token.
Workflow
-
Confirm the symptom. Ask what failed:
- The error
codeandsubcode(e.g.190/463) - Which endpoint/request failed
- Which app the call was made with, and what the token is expected to do (which permissions/scopes)
- The error
-
Have the developer inspect the token themselves. Offer either option — both run in the developer's own environment and return only metadata, never routing the token through this agent: