When Polar's MCP server returns insufficient_scope on sandbox list calls after a successful browser login, the OAuth token itself is under-scoped. Open the organization settings and give the token wider scopes, then reconnect. If the permission view looks empty or stale in the dashboard, log out and back in; the reporter saw the correct token view only after a fresh login.

Context: GitHub issue polarsource/polar#8250: Using Polar's MCP server for the sandbox environment through an agentic coding tool failed on every read call (customers, products, subscriptions, orders list) with insufficient_scope, "The request requires higher privileges than provided by the access token." The browser-based OAuth flow completed fine. A Polar contributor's fix was to widen the token's scopes in the organization settings; the reporter confirmed the token's permission view appeared correctly after a fresh login.