Skip to main content
Every error body is { "error": "<message>", "code": "<CODE>" }. A few answers carry no code; the message then says what is wrong. Every code, with the operations that return it, is in the error reference.

The one rule

Know whether the action may have run before you retry. Parmana’s answers fall into three groups: The SDKs never retry a POST on their own; they retry only GET requests, and only when you configure a retry policy.

How the SDKs raise them

Every error from a response carries its status: statusCode in TypeScript, status_code in Python. Decide on a 5xx by its code, never by the status alone.

By status

400: the request is malformed

401: no valid key

{"error":"authentication required"}, with a WWW-Authenticate header. The key is missing, wrong, rotated, or not sent as Authorization: Bearer <key>. Nothing about the request was read.

403: not allowed

POLICY_DENIED covers every refusal by the decision, each with its own message:

404: not found

409: conflict

429: too many requests

RATE_LIMITED. Wait for the Retry-After header, then retry the same request.

500, 502: the action may have run

For an external connector, a request naming a parameter the registration does not allow, or an endpoint whose host now resolves to a non public address, is also reported as 502 EXECUTION_OUTCOME_UNKNOWN although nothing was sent. Check the endpoint’s own record before resolving.

503: unavailable, nothing ran

Retry later with a new transaction. If it persists, tell the operator; each is an alert in Chapter 8.

Common situations

More, by symptom: Troubleshooting.