Three fixes, one of which was stopping AI assistants from connecting at all on affected sites.
Tokens were dead the instant they were issued
On a site where another plugin changes the site's timezone and doesn't put it back — LearnDash does this in two places, and so do some custom plugins — every sign-in code and access token was stored with the wrong time on it, off by that site's distance from UTC.
In India that is five and a half hours. A sign-in code meant to last ten minutes was recorded as having expired five hours before it was created. The assistant got invalid_grant the moment it tried to finish signing in, and no connector could be added at all. Nothing in the logs explained it, because nothing had gone wrong as far as either side could tell.
Where it came from
Every line of this plugin's own time handling was correct — UTC on the way out, UTC on the way back. The damage happened in between, in the database layer everything is written through:
$timestamp = strtotime( $value ); // reads the string in PHP's default timezone
$value = gmdate( 'Y-m-d H:i:s', $timestamp ); // writes it back out as UTCThe value handed in was already UTC, so it was converted a second time. WordPress normally sets that timezone to UTC, which makes the double conversion harmless — until another plugin moves it.
Measured on a 600-second sign-in code:
| Site timezone | Stored before | Stored after |
|---|---|---|
| UTC | 03:10:56 valid | unchanged |
| Asia/Kolkata | 21:40:56 expired | 03:10:56 valid |
| America/New_York | 07:10:56 (4h late) | 03:10:56 valid |
The half nobody would have reported
West of UTC the same fault runs backwards and extends access instead of ending it. Tokens on those sites stayed usable for hours past the point they should have stopped working, with nothing to show for it. An outage in one hemisphere and a silent security defect in the other, from one line.
Times are now recorded in UTC whatever any other plugin has done to the clock. Nothing to configure.
Existing tokens are left alone. Nothing distinguishes a shifted row from a correct one, so a repair pass would be guessing, and guessing wrong revokes working connections. They expire and are cleaned up on their own. If you want certainty on a site west of UTC, revoke the connections on the AI Connectors tab and reconnect.
Site Health reports a changed timezone
Under Tools → Site Health, a new check reports whether PHP's timezone is still the UTC WordPress sets at startup. This plugin no longer depends on it — but other plugins on your site may, and until now nothing told you it had been changed.
ChatGPT can be given credentials, like every other assistant
The ChatGPT tab was the only one with no Generate credentials button. It said manual credentials were impossible, which was a misreading of how ChatGPT works.
ChatGPT picks its sign-in return address based on the site it is connecting to. A site whose identity it cannot verify gets a one-off address invented per connection, which nothing can register in advance. A site it can verify gets a fixed one. This plugin has always been in the second group — it publishes the proof ChatGPT looks for and includes it in every sign-in response — so the fixed address applies and credentials work.
The existing route is unchanged: leave ChatGPT's OAuth fields blank and it still registers itself, which is still the simpler path. The instructions alongside the generated credentials were also rewritten — they still walked you to a dialog OpenAI retired when Connectors became Plugins in mid-2026.
A heads-up in Firefox
Firefox's Enhanced Tracking Protection can stop an assistant part-way through connecting: the connector is added, sign-in opens, and then nothing finishes — with no error anywhere to explain it.
Opening the AI Connectors screen in Firefox now shows how to get past it: click the shield icon left of the address bar and switch Enhanced Tracking Protection off for that site, then connect again. The setting is per-site, affects nothing else you browse, and can go back on once the connection works. Firefox only — nobody on Chrome, Safari or Edge sees it — and dismissible.
Upgrading
No database changes: no table is altered and no upgrade routine runs. On a site with a normal timezone the first fix is a no-op, byte for byte. Requires AcrossAI MCP Manager 0.3.4+ and AcrossAI Abilities Manager 0.0.34+, unchanged from 0.9.14.