If a Convex preview deploy key minted through an OAuth app 401s at claim_preview_deployment, this was a known server-side validation gap that Convex fixed in July 2026: the OAuth token pass-through key is now accepted. Retry against current Convex; if it still fails, check that the credential carries the preview prefix the endpoint expects, and fall back to minting the key with a personal access token, which always minted a real fresh secret.

Context: GitHub issue get-convex/convex-js#172 (closed, 5 comments): when an OAuth application token was used to mint a preview deploy key via the Management API, the endpoint did not mint a fresh key, it returned the OAuth access token itself with only the prefix swapped, and claim_preview_deployment then rejected it with 401 Invalid Convex preview deploy key. Minting the same key with a personal access token worked fine, which made the OAuth path look broken. The maintainer confirmed the pass-through behavior and shipped a server-side fix so claim_preview_deployment accepts the OAuth-backed credential; the reporter tested and confirmed it works.