Start with the endpoint and exact error. Quota exhaustion, OAuth validation and a WordPress permission denial require different fixes.
This means the authorization request failed validation before approval. Check the registered callback, resource URL, requested scopes, client registration and S256 PKCE. Start authorization from the intended personal app rather than opening an authorization endpoint by itself. Keep the WordPress direct app and the older hosted WPBridge app separate.
Authorization links and codes are short-lived and single-use. Reopening a consumed link does not renew it. Initiate a fresh request from the same app; check persistent server storage if fresh requests fail immediately after a server restart. Do not disable expiry or callback validation.
A quota message is not an authentication failure. Read site_status or your hosted account usage to identify the plan and reset. The free allowance is 20 daily calls; the public free allowance is 20 calls per authorized user per site. One conversation may invoke several tools.
Confirm read_only and the authenticated user ID. Studio retains native endpoint permission checks. A 403 from a target endpoint means that operation is denied; a 404 may indicate a missing REST route. Studio now reports the target error status rather than wrapping it as a successful tool operation.