Exception paths
When a call does not proceed. Categories are stable enough to plan for. Exact messages may vary by deployment.
Synthetic HTTP and JSON examples live in the integrator Errors appendix.
What stops a call
| Condition | Typical signal | What to do |
|---|---|---|
| Missing or invalid credential | 401 Unauthenticated | Re-mint via Connect. Do not reuse expired JWTs |
| Pack or write consent insufficient | 403 Forbidden | Operator adjusts packs/consent. Agent must not escalate in-host |
| Process up but not ready | 503 / failed /ready | Wait. Gate traffic on /ready |
| Rate limited | 429 | Backoff and retry |
| Invalid tool arguments | 400 / tool error | Fix args from the tool schema |
| Shared-record peer unavailable | 502 / 503 | Retry later. Escalate to operator if persistent |
| Unexpected failure | 500 | Backoff. Contact operator if persistent |
Buyer meaning
These failures are authority and readiness signals, not product judgment scores. A 403 means the credential boundary held. A not-ready response means the peer path is not safe for traffic yet. Neither is a substitute for human review of a prepare payload.
Integrator detail
Technical champions should use Errors and Production Checklist when wiring clients. Never log Authorization headers.