---
title: "Ashby integration not sending screens or writing results"
description: "Fix the common Ashby problems, from a rejected webhook signature or missing key permissions to candidates without an email and failed writes."
updated: 2026-10-06
canonical: https://kendor.io/docs/ashby/troubleshooting
---

# Ashby integration not sending screens or writing results
Most Ashby problems show up in two places in Kendor: the **Setup** checklist and **Recent invites from Ashby**, both on the Ashby page under **Integrations**. When something needs fixing, the Ashby card names the first problem and offers **Finish setup**, and the Ashby page reads **Needs attention**. Start there, fix it in Ashby, and choose **Check again**.

## What the card is telling you

| Message | What it means | Fix |
|---|---|---|
| **The key is missing permissions** | The API key lacks one or more required permissions. | Edit the key in Ashby under **Admin → API keys**, add the permissions listed under **Key permissions**, then choose **Check again**. |
| **Webhook not registered** | Kendor couldn't add the webhook, usually because the key can't write API keys. | Add it by hand: see [Add the webhook by hand](/docs/ashby/connect-ashby). |
| **Kendor fields missing in Ashby** | One or more of the five fields doesn't exist on Application. | Create them with the exact names, or give the key **Write hiring process metadata** and choose **Check again**. |
| **A result couldn't be written to Ashby** | A recent write to an application failed. | See **Failed writes** below. |

## The candidate entered the stage but got no invite

Work through these in order.

1. **Is there a matching rule?** Check **Stages that send a screen**. A one-job rule must name that exact job and stage. An **any job** rule matches the stage name on any job.
2. **Is the webhook in place?** The **Webhook** row in **Setup** should have a tick. If you added it by hand, check that the type is **Candidate stage change** and the URL and secret match what Kendor shows.
3. **Did Kendor leave a note in Ashby?** Look at the candidate's notes. A note that starts `Kendor: no invite sent` gives the reason.
4. **Was the application already invited from this stage?** Each application gets one invite per stage. Moving it out and back in doesn't send another. Use **Send reminder** on the candidate in Kendor instead.

### Notes Kendor leaves instead of an invite

| Note | Fix |
|---|---|
| `Kendor: no invite sent, because this candidate has no email address in Ashby.` | Add an email to the candidate in Ashby, then move the application into the stage again. |
| `Kendor: no invite sent. Email must belong to the … domain` | The screen has an **Email domain allowlist** and the candidate's email is outside it. Change the **Allowed email domain** in the screen's settings, or correct the email in Ashby, then move the application into the stage again. |
| `Kendor: no invite sent. This candidate has already completed the screen; …` | Turn on **Allow re-invite after completion** on the screen, then move the application into the stage again. |
| `Kendor: no invite sent. Candidates can only be invited to a live screen. …` | Set the screen live, then move the application into the stage again. |

When no invite was sent, nothing is recorded for that stage, so moving the application into it again tries again.

## Webhook signature failures

Ashby signs each stage change with your webhook secret, and Kendor checks the signature before doing anything. A request with a missing or wrong signature is rejected with `401 Unauthorized`, and no invite is sent.

This usually means the secret in Ashby doesn't match Kendor's. On the Ashby page in Kendor, choose **Show secret** in the **Webhook** row, copy the **Secret token**, and paste it into the webhook in Ashby.

A request to a webhook URL Kendor doesn't recognise is rejected with `404`. That happens after you disconnect: the old URL stops working, and connecting again issues a new URL and secret. Update or remove any webhook you added by hand.

## Duplicate deliveries

If Ashby delivers the same stage change more than once, Kendor sends one invite and ignores the repeats, even when they arrive at the same moment. You don't need to do anything.

## Failed writes

When Kendor can't write to an application, for example because Ashby rejected the key or couldn't be reached, the invite shows **Not written yet; retrying** in **Recent invites from Ashby**. Hover it to see Ashby's reason.

- Kendor retries every 10 minutes for a day from the first failure.
- After a day it stops retrying that invite. The next change to the attempt, such as a submission or a decision, writes everything again.

If the reason is about the key, replace it with **Replace key** using a key with the same permissions, or fix its permissions and choose **Check again**.

## Ashby rejects the key when connecting

If **Connect** or **Replace key** shows **Ashby rejected the API key**, the key is wrong, revoked or disabled in Ashby. Create a new key and paste it again. **Could not reach Ashby** means the request didn't get through; try again in a moment.

## After disconnecting

**Disconnect** removes the key, every stage rule and the webhook Kendor registered. New stage changes send nothing. Invites already sent stay valid, but their progress is no longer written to Ashby.

> **Note.** Only **Owners** can see and change the Ashby connection. Editors and Viewers see **Only owners can manage Ashby.**
