Error codes

Every way this service can fail or refuse has a code of the form STS-<SUBSYSTEM>-<NNNN>. There are 4074 of them, in 41 subsystems.

Where a code appears

  • On the audit row for the event, as errorCode, and at the front of its summary. Filter for one at /admin/audit?code=STS-… or GET /admin-api/audit?code=STS-…; a prefix such as STS-OAUTH matches a whole subsystem.
  • On the admin console at /admin/error-codes (Monitoring), which lists this table with how many rows in the audit log carry each code right now, and at GET /admin-api/error-codes.
  • In the service log, at the front of the line [STS-…], for every audit row that carries one and for failures that have no row — chiefly the ones that stop the service starting, which happen before there is an audit log to hold them.

Where a code never appears

A code is never sent to a client — not in a response body, a header or a redirect. Each protocol this service speaks already defines how it reports an error (invalid_grant, KDC_ERR_PREAUTH_FAILED, an LDAP result code, a SOAP fault, a gRPC status, a SAML StatusCode), and a client under test must see exactly that. The Client sees column below says what the client is sent for each condition; it describes the response, and the code changes nothing about it.

A code is an operator’s name for a condition. It is never renumbered or reused, so it is safe to put in an alert rule or a saved search.

The three generic codes

STS-HTTP-0002 and STS-HTTP-0003 are what the HTTP call log records for a 4xx or 5xx response that no handler gave a more specific code. Seeing one means a failure site is missing its code — please report it with the request path from the audit row. STS-HTTP-0001 is an unrouted path, which is an ordinary outcome.

Contents

STS-HTTP

HTTP front door. Every HTTP request passes through here before it reaches a protocol: the security headers, the CORS allowlist, the body parsers, the validation guard, the rate limiter, and the call-log funnel that records the answer. The three generic codes below are what that funnel records for a failed response nothing more specific claimed.

Raised from: common/app.js, common/cors.js, common/validation.js, common/websecurity.ts.

Code What failed Client sees
STS-HTTP-0001 No route matched the request path, and Express answered with its own 404 (Cannot GET /path). HTTP 404
STS-HTTP-0002 A request was refused with a 4xx status that no handler classified. This is the call-log funnel’s fallback, and a row carrying it names a failure that is missing its own code. HTTP 4xx, as the handler sent it
STS-HTTP-0003 A request failed with a 5xx status that no handler classified — usually an exception Express caught. A row carrying it names a failure that is missing its own code. HTTP 5xx, as the handler sent it
STS-HTTP-0004 The request body exceeded the 5 MB limit the body parsers enforce. HTTP 413
STS-HTTP-0010 A query string carried a parameter named constructor, prototype or proto, which the validation guard refuses before any endpoint sees the request. HTTP 400 text/plain
STS-HTTP-0011 A query-string value contained a control character (a CR, LF, NUL or similar), which the validation guard refuses before any endpoint sees the request. HTTP 400 text/plain
STS-HTTP-0012 The request body was in a charset or content encoding the body parsers do not read, so it was refused before any endpoint saw it. HTTP 415
STS-HTTP-0013 The request body was cut off before it was complete, or did not match its Content-Length, so it was refused before any endpoint saw it. HTTP 400
STS-HTTP-0014 A middleware ahead of the router raised an error the body parsers do not classify (a body stream that could not be read, most often), so the request failed before any endpoint saw it. HTTP status as Express’s final handler sends it
STS-HTTP-0015 A state-changing form post from a signed-in session carried no CSRF token. the refusal the calling surface renders (a console, portal or sign-in page)
STS-HTTP-0016 A state-changing form post carried a CSRF token that belongs to a different session, or to one that has ended. the refusal the calling surface renders (a console, portal or sign-in page)
STS-HTTP-0017 Too many attempts at one operation for one identity inside the rate-limit window; further attempts are refused until the window passes. the refusal the calling surface renders, in its own protocol’s words
STS-HTTP-0018 Too many attempts at one operation from one address inside the rate-limit window; further attempts are refused until the window passes. the refusal the calling surface renders, in its own protocol’s words
STS-HTTP-0019 A CORS preflight came from an origin that is not this service’s own and that no application in the realm lists in appCorsOrigin, so it was answered with no CORS headers. HTTP 204 with no Access-Control-Allow-Origin; the browser does not send the request
STS-HTTP-0020 A cross-origin request named no client, and its origin is not this service’s own and is listed by no application in the realm, so its answer carried no Access-Control-Allow-Origin. none — the endpoint answers; the browser withholds the answer from the page
STS-HTTP-0021 A cross-origin request named a client this realm has no application for (a client_id, Basic user name, client assertion or access token client_id), so its answer carried no Access-Control-Allow-Origin. none — the endpoint answers; the browser withholds the answer from the page (a CORS error in place of the protocol’s own error)
STS-HTTP-0022 A cross-origin request named a client whose appCorsOrigin does not list the request’s origin, so its answer carried no Access-Control-Allow-Origin. none — the endpoint answers; the browser withholds the answer from the page
STS-HTTP-0023 A value of global.corsOrigins is not an origin, and was ignored rather than widened. —

STS-PROXY

PROXY protocol. The HAProxy PROXY protocol v2 header read at the front of every TCP connection when global.proxyProtocol is v2: who may send one (global.trustedProxies), the header itself, and the startup refusal when nobody is trusted.

Raised from: common/proxy_protocol.ts, server.js.

Code What failed Client sees
STS-PROXY-0001 A connection from an address outside global.trustedProxies (and not this host) was closed, because with global.proxyProtocol on every connection must come through a trusted proxy. One audit row per address per minute; the rest are counted. the TCP connection is closed before any protocol byte is read
STS-PROXY-0002 A connection from a trusted proxy did not begin with the PROXY protocol v2 signature — a balancer without proxy protocol enabled, or a plain client on the proxy’s address — and was closed. the TCP connection is closed
STS-PROXY-0003 A connection from a trusted proxy began with a PROXY protocol version 1 (text) header; only version 2 is accepted, and it was closed. the TCP connection is closed
STS-PROXY-0004 A PROXY protocol v2 header was malformed — a version other than 2, an unknown command, family or transport, an address block shorter than its family needs, or a TLV running past the declared length — and the connection was closed. the TCP connection is closed
STS-PROXY-0005 A PROXY protocol v2 header declared more address and TLV bytes than this service reads (4096), and the connection was closed before they were buffered. the TCP connection is closed
STS-PROXY-0006 A PROXY protocol v2 header carried a CRC32C TLV that does not match the header, and the connection was closed. the TCP connection is closed
STS-PROXY-0007 A connection from a trusted proxy did not complete its PROXY protocol header within global.proxyProtocolTimeoutMs, and was closed. the TCP connection is closed
STS-PROXY-0008 A connection from a trusted proxy closed part-way through its PROXY protocol header. —
STS-PROXY-0009 The service refused to start: global.proxyProtocol is v2 and global.trustedProxies holds no usable address or range, so no header could be believed. —

STS-CORE

Service core. Starting the service, the settings table, trust realms, and the helpers every protocol shares.

Raised from: server.js, common/protocol_stack.ts, common/config.js, common/config_file.js, common/realms.js, common/helpers.js, common/mode.js, common/version.js, sts_metadata.ts, home/, admin-ui/node_health_admin.ts, admin-ui/worker_pools_admin.ts (STS-CORE-0126), cluster/node_snapshots.ts.

Code What failed Client sees
STS-CORE-0001 The appconfig file CONFIG_FILE names could not be loaded, so the service refused to start. —
STS-CORE-0002 One or more settings have no value in the appconfig layer or the environment (env/defaults.js has not been regenerated), so the service refused to start. —
STS-CORE-0003 A runtime setting change could not be handed to persistence. The setting is in force and may not survive a restart. —
STS-CORE-0004 A setting was named that does not exist in the settings table. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0005 A restart-only setting was changed while the service is running; it must be set in the appconfig file or the environment instead. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0006 A setting’s value failed its type or bounds check — from a console form, /admin-api, or a per-application attribute that overrides it. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0007 A setting was reset where nothing had overridden it. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0008 A runtime setting saved in the persistence store was not applied, because it no longer passes validation (renamed, retyped or made restart-only since). —
STS-CORE-0009 A trust realm id was not lower-case letters, digits and hyphens of at most 31 characters. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0010 A trust realm was defined with the id of the built-in default realm. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0011 A trust realm id is the first segment of a path this service already serves, so the realm would shadow the endpoint. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0012 A trust realm was defined with an id that is already in use. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0013 A trust realm was named that is not defined. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0014 A realms.* setting was set on one trust realm; those settings decide how a realm is reached and may only be set service-wide. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0015 A per-process setting (such as workers.requestCount) was set on one trust realm, where it would change every realm at once. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0016 A setting was cleared on a trust realm that does not set it. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0017 The router could not be read to reserve realm ids, so a realm id may shadow an endpoint without being refused. —
STS-CORE-0018 A trust realm change watcher threw; the change stands but what watches it (persistence, most often) may not have recorded it. —
STS-CORE-0019 A store could not build itself for a newly created trust realm; the realm exists without that store’s state. —
STS-CORE-0020 A store could not purge a removed trust realm’s state, which is left behind for an id nobody can reach. —
STS-CORE-0021 The persistence observer offered to the realm stores was not a function, so nothing this process mints will be written down. —
STS-CORE-0022 Two persisted stores were declared under one handle; the second is not persisted. —
STS-CORE-0023 A persisted store could not report a write to persistence; the write stands in memory and may not be written down. —
STS-CORE-0024 A trust realm’s signing keys could not be certified under its Issuing CAs; they still sign, with a self-signed certificate. —
STS-CORE-0025 (retired) The BBS key pair handed down from the front process could not be read, so this process generated its own. —
STS-CORE-0026 A request declared a JSON body that does not parse; it is read as empty. whatever the endpoint answers for an empty body
STS-CORE-0027 The token recorder behind the statistics threw while a JWT was being signed; the token is unaffected and is missing from /admin/tokens. —
STS-CORE-0028 A trust realm’s post-quantum keys could not be generated ahead of time; the first JWKS fetch in that realm makes them instead. —
STS-CORE-0029 The Kerberos KDC’s TCP/UDP listeners could not start (often port 88 is privileged or taken); the rest of the service runs. —
STS-CORE-0030 The embedded LDAP directory’s listener could not start; the rest of the service runs. —
STS-CORE-0031 The SPIFFE gRPC listeners could not start; the rest of the service runs. —
STS-CORE-0032 (retired) The 8443/9443 TLS endpoints could not start. Retired 2026-09-16: both listeners were deleted and this module binds nothing, so there is no bind here to fail —
STS-CORE-0033 The last flush at shutdown failed, so the process exited non-zero and a change made just before it may not have been written down. —
STS-CORE-0034 (retired) The BBS key pair could not be shared with the request workers; each generates its own and a did:web document may name a key its siblings did not sign with. —
STS-CORE-0035 The service refused to start because its signing key material (or the key-encryption key that opens it) could not be read. —
STS-CORE-0036 The service refused to start because the configured persistence store could not be opened or read. —
STS-CORE-0037 The front page’s logo could not be read from disk at startup; the page is drawn without it. —
STS-CORE-0038 The logo was requested and none was read at startup. HTTP 404 text/plain
STS-CORE-0039 The VERSION file is not M.N and was ignored. —
STS-CORE-0040 No readable VERSION file was found, so the version is reported as 0.0. —
STS-CORE-0041 The build stamp version.json could not be written at image build time. —
STS-CORE-0042 A shared store’s reconciler threw while deciding whether a restored or replicated row (or its removal) may be applied, so it was not applied and what the process held is unchanged. —
STS-CORE-0043 The plain-HTTP revocation listener (pki.httpPort) could not bind, so every http:// CRL, OCSP and caIssuers address in this service’s certificates answers nothing. —
STS-CORE-0090 setSubjectResolver() was given an object without both subjectFor() and nameFor(), so no person in this process is issued a subject. none — logged
STS-CORE-0091 The subject resolver threw, and the person was given no subject (or a subject was treated as naming nobody). none — logged
STS-CORE-0092 A realm’s key set could not be generated off the event loop; the first read of it generates it on the loop instead. none — logged
STS-CORE-0093 The service or its in-process suite was started from a tree whose TypeScript sources are not compiled, which only an image build does (#50). none — the process exits before listening
STS-CORE-0094 A module registered a cache with the cache registry and left out a member every descriptor must have (#74). none — the module fails to load
STS-CORE-0095 A registered cache threw while listing its entries for /admin/caches, so the page shows it with no rows (#74). none — logged; the page says the cache could not be listed
STS-CORE-0096 A registered cache reports no bound: its maxEntries() answered no finite number. Every cache and replay store has one since 2026-09-18, so this is a regression in its owner; /admin/caches shows it as a problem on the row. none — logged; the page marks the row
STS-CORE-0097 A bounded store that decides a replay was full of LIVE entries and refused a new one rather than forget one (logged at most once a minute per store; each refusal is counted on /admin/caches). The request is refused under its own protocol’s code. none — logged; the refusal carries the protocol’s own code
STS-CORE-0098 A persisted store declared a retention policy other than “keep” or “age”. It is treated as “keep”, so its rows are never dropped by age. none — logged at require time
STS-CORE-0099 A trust realm’s domain was not a DNS name of at least two labels (letters, digits and hyphens, each at most 63 characters, a top-level label that is not all digits). the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0100 A trust realm was given a domain another realm — the default realm’s global.domain included — already has. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0101 An update tried to change a trust realm’s domain, which is fixed when the realm is created. the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0102 A cache or replay store could not eject its expired entries; the store still refuses an expired entry where it reads it. none — logged by the caches.eject-expired job
STS-CORE-0103 A write giving a development-only setting a value other than its default — a …SkipTlsVerification or spiffe.k8sSkipKubeletVerification (#171); oauth2.breakIdTokenNonce, ssf.breakSetSignature, ssf.legacySubClaim or spiffe.acceptAssertedSelectors on, or spiffe.attestWorkloads off (#104); oid4vp.requireStatusReference off (#165); risc.googleSubjectType or saml.allowSha1Signatures on, saml2.signAssertion, saml11.signAssertion, saml11.signResponse or spiffe.requireSecurityHeader off, krb5.clockOffset not 0, or a weak value of saml.signatureAlgorithm (rsa-sha1), saml2.keyTransportAlgorithm (rsa-1_5) or pki.signatureAlgorithm (sha1-rsa, sha1-ecdsa) (#181) — was refused because the realm it lands in is in product mode. console: the page’s error list; /admin-api: HTTP 400 { ok: false, errors }
STS-CORE-0104 An outbound request (a GNAP push, an SSF push, a federation back channel or an XACML nudge) was not made because the CA file its …CaFile setting names could not be read or holds no certificate. none — the family’s own failure record (a grant history, a dead letter, a relationship’s last error, a PEP row)
STS-CORE-0105 The service did not start: the appconfig file or the environment still names a setting removed on 2026-09-23 (#171) — gnap.pushAllowInsecure, ssf.pushAllowInsecure, federation.outboundAllowInsecure or xacml.pepNotifyAllowInsecure. none — the process exits
STS-CORE-0106 A development-only setting — one of those STS-CORE-0103 lists, or an application attribute overriding one (#181) — is stored in a realm that is in product mode, and is ignored: its default is in force. Logged once per process and setting or attribute (#104). none — a warning in the log
STS-CORE-0107 A trust realm id is an EST label (a certificate profile). /.well-known/est// and /.well-known/est/ the caller’s refusal (errors on a console or /admin-api reply)
STS-CORE-0108 The service did not start: a value in the environment, the appconfig file or env/defaults.js fails the check a console or API write of it would (a value outside an enum or a list’s csvValues, a number out of bounds, a malformed boolean) — #86. —
STS-CORE-0120 A trust realm was removed (#232) before everything it owed had been delivered within realms.removalDeliveryTimeoutS — session ends still waiting on their claim, back-channel Logout Tokens or SSF events (session-revoked, account-purged, stream-updated) not yet delivered, or a retirement hook that failed. The realm is removed anyway. none — logged; the removal succeeds
STS-CORE-0121 A sign-in or an issuance was refused because its trust realm is being removed (#262): realms.retire() marks the realm retiring before it ends its sessions and announces the removal, and from then on no session, token, authorization code, assertion, ticket, credential, certificate or SVID is started or issued in it, in either mode. Also logged once, as information, when the mark is set. the protocol’s own refusal — invalid_grant at the token endpoint, access_denied at the authorization endpoint, credential_request_denied at OpenID4VCI, a SAML Responder / RequestDenied status, a SOAP fault, a 503 problem at ACME, EST and SCEP, and a refused session at every sign-in door
STS-CORE-0122 A trust realm’s removal was refused because a removal of it is already in progress (#294): realms.retire() marked it less than realms.removalDeliveryTimeoutS plus a 30-second margin ago, or is running in this process. Starting a second one would end and announce everything twice. Once that time has passed the removal is taken to be interrupted, and removing the realm again finishes it. none — the console and /admin-api refuse the remove action
STS-CORE-0123 A trust realm is stuck half removed (#294): it carries the retiring mark (#262) from longer ago than a removal can take, so the process that was removing it stopped before it finished. Every new sign-in and issuance in it is refused (STS-CORE-0121) until an administrator removes it again, from another realm. Logged when such a realm is restored at start, and when the removal is finished. none — logged; /admin/realms and GET /admin-api/realms show it
STS-CORE-0124 The /admin/node-health page or GET /admin-api/node-health could not build its report of the node’s container and processes (#329). HTTP 500 page or JSON
STS-CORE-0125 ECS_CONTAINER_METADATA_URI_V4 is set, but the ECS task metadata endpoint did not answer Monitoring → Node Health within its bound, or answered with an error (#329). Logged when it starts failing, not on every page; the page says so in a sentence and draws the cgroup figures without the cross-check. none — the page and GET /admin-api/node-health still answer 200
STS-CORE-0126 Monitoring → Worker Pools or → Node Health, or their management API operations, were asked about a node (?node=) that is neither this node nor any node with a snapshot or a membership row (#332). HTTP 404, with the names there are
STS-CORE-0127 A cluster node’s snapshot of Monitoring → Worker Pools and → Node Health could not be written to the shared store, or the other nodes’ snapshots could not be read from it (#332). Logged when it starts failing, not on every run or page; the page draws this node alone and says why. none — the pages and their API still answer 200
STS-CORE-0128 The hourly cluster.node-snapshot-purge job could not delete the snapshots of nodes that are no longer live cluster members (#332). Logged when it starts failing, not on every run; the rows stay, and the pages go on drawing those nodes as gone. none — the scheduler records the failed run
STS-CORE-0140 A package this service requires at first use rather than at start (common/lazy_module.ts, #348) — the gRPC runtime, its proto loader, jsonld through the vendored bbs2023.js — failed to load when it was first needed, so the call that needed it fails. The image is missing or has a broken copy of the package. none — logged; the call fails as it would have at start
STS-CORE-0141 An uncaught exception reached a started process — the front process, a request worker or a computation worker — and was contained there rather than ending it (#355, common/fault_boundary.ts). The line carries the stack. Logged at the first three occurrences of each distinct fault and then at each power of ten, with the count. none — logged; the process carries on
STS-CORE-0142 A promise rejection nobody handled reached a started process and was contained there rather than ending it (#355). The line carries the stack, throttled as STS-CORE-0141 is. none — logged; the process carries on
STS-CORE-0143 An Express handler returned a promise that rejected (an async handler that failed, #355). The request is answered with a plain 500 through Express’s final handler, as a thrown error is, unless the handler had already answered or called next(); the line carries the stack, throttled as STS-CORE-0141 is. HTTP 500 Internal Server Error, with no detail
STS-CORE-0144 The Express guard (#355) could not be installed, because express/lib/router/layer is missing or not the shape it knows: a rejected async handler reaches the process handlers (STS-CORE-0142) instead of being answered with a 500. none — logged at start
STS-CORE-0145 A listener.* setting was given to the default realm, which has no listener of its own: it is served on the main port under global.publicBaseUrl (#99). the write is refused; nothing is changed
STS-CORE-0146 A realm’s listener.publicBaseUrl is not an https origin with no path, query or user, or listener.port was set without it. the write is refused; nothing is changed
STS-CORE-0147 A realm’s listener.port is already another realm’s or one of this process’s own listeners’ (every node binds every realm port, so each must be its own). the write is refused; nothing is changed
STS-CORE-0148 A realm listener (listener.port) was asked for while this service runs as several cells, which #99 does not support yet. the write is refused; nothing is changed
STS-CORE-0149 A module told of changed settings (config.onOverridesChanged()) or asked to judge a write between settings (config.addWriteRule()) threw. The change is in force; what that module does with it, or the rule it holds, did not run this time. logged; the write is not refused by the failed rule

STS-WORKER

Worker pools. The request workers the whole protocol stack can be dispatched to (and, until #363, the child processes post-quantum signing ran in).

Raised from: common/request_pool.js, common/request_worker.ts, common/service_state.ts, admin-ui/worker_pools_admin.ts.

Code What failed Client sees
STS-WORKER-0001 (retired) The IPC channel to a post-quantum worker process failed, so a job sent to it may not arrive or its answer may not come back. Retired by #363: the post-quantum worker pool was removed. —
STS-WORKER-0002 (retired) A post-quantum worker process exited or was killed with jobs in flight; every one of those jobs was failed and its caller told it can be retried. Retired by #363: the post-quantum worker pool was removed. —
STS-WORKER-0003 (retired) Post-quantum worker processes kept exiting immediately without finishing a job, so the pool stopped forking them and computes in the front process (blocking) — usually an unreadable CONFIG_FILE or a machine out of memory. Retired by #363: the post-quantum worker pool was removed. —
STS-WORKER-0004 (retired) A post-quantum worker stayed alive and did not answer a job within workers.jobTimeoutS, so the request waiting on it was failed rather than left to hang. Retired by #363: the post-quantum worker pool was removed. —
STS-WORKER-0005 (retired) During shutdown a post-quantum worker did not finish within the drain bound and was killed. Retired by #363: the post-quantum worker pool was removed. —
STS-WORKER-0006 (retired) A job (post-quantum sign, verify or generate, or a scrypt derivation) threw inside a worker process and was answered as a failure. Retired by #363: the post-quantum worker pool was removed. —
STS-WORKER-0007 A dispatched read waited the full 2000ms barrier bound for an earlier write to be reported committed and was served without it, so it may be stale. —
STS-WORKER-0008 Read-barrier tickets that had been answered for longer than the reap threshold without any worker reporting them committed were dropped — a lost commit announcement, or a flush running that long. —
STS-WORKER-0009 A TLS client certificate was too large to forward to a request worker in a header, so the worker saw the request as having presented no certificate. —
STS-WORKER-0010 The request-worker socket directory or socket file could not be narrowed to owner-only permissions and keeps the process umask. —
STS-WORKER-0011 A request worker asked the front process for a directory sign-out with a connection key the front process could not decode, so nothing was closed for it. —
STS-WORKER-0012 The front process could not close the LDAP connections a request worker asked it to end during a sign-out, so those connections may still be bound. —
STS-WORKER-0013 A realm’s signing keys or certificate authority could not be handed to a request worker over IPC, so that worker may hold different key material from the rest of the service. —
STS-WORKER-0014 A re-issued TLS listener certificate could not be handed to a request worker, so that worker keeps pinning the previous one and its OpenID Connect back channel fails until it is replaced. —
STS-WORKER-0015 After the certificate hierarchy was rebuilt, the front process could not re-issue its TLS listener certificate under it. —
STS-WORKER-0016 The front process could not send a newly forked request worker its start message. —
STS-WORKER-0017 A request worker reported that it could not start (its socket failed, its state could not be brought up, or it did not finish starting in time). —
STS-WORKER-0018 A request worker’s unix socket failed to bind or errored, so that worker cannot serve. —
STS-WORKER-0019 A request worker could not bring up its state (the store, the signing keys, the minted rows or coordination) and will not serve. —
STS-WORKER-0020 The IPC channel to a request worker failed. —
STS-WORKER-0021 A request worker died holding answered write requests whose flush it had not reported, so those writes may not have reached the store. —
STS-WORKER-0022 A request worker exited or was killed with requests in flight; each was answered 502. —
STS-WORKER-0023 Request workers kept exiting immediately without serving anything, so the pool stopped forking them and every request is handled in the front process. —
STS-WORKER-0024 The service refused to start: workers.dispatch names paths to hand to request workers but the process is not coordinating through a store, which would make workers answer from divergent private copies. —
STS-WORKER-0025 Not one request worker started, so every request is being handled in the front process. —
STS-WORKER-0026 Only some of the configured request workers started. —
STS-WORKER-0027 A request worker did not answer a read barrier in time, so the request was served from whatever that worker holds, possibly stale. —
STS-WORKER-0028 A request matched workers.dispatch while a pool is configured but no request worker was serving, so it was refused rather than answered from the front process. HTTP 503 (Retry-After: 5), plain text
STS-WORKER-0029 A request worker’s answer failed mid-stream, so the client’s connection was destroyed with a truncated response. connection reset (truncated response)
STS-WORKER-0030 A request worker could not answer a dispatched request (it went away or the proxy connection failed). HTTP 502, plain text (or a destroyed connection if headers were already sent)
STS-WORKER-0031 During shutdown a request worker did not finish within the drain bound and was killed. —
STS-WORKER-0032 A request worker could not announce to the front process that its flush committed, so a reader may be told it is current before that write is visible. —
STS-WORKER-0033 A client certificate forwarded by the front process could not be decoded in the request worker and was treated as absent. —
STS-WORKER-0034 A request worker could not send a message to the front process over IPC. —
STS-WORKER-0035 A request worker could not announce that a dispatched protocol operation finished, so a reader may wait the full barrier bound for it. —
STS-WORKER-0036 A request worker’s read barrier (catching up with the change log) threw unexpectedly; the front process was told it could not catch up. —
STS-WORKER-0037 A client certificate’s issuer chain was too large to forward to a request worker beside the leaf, so the worker saw the leaf alone and could not verify a foreign CRL about it. —
STS-WORKER-0038 The service refused to start: workers.surfaceCount gives the admin console and the user portal request workers of their own and workers.readYourWrite is off, so a sign-in crossing the two pools would intermittently read a session that had not yet arrived. —
STS-WORKER-0039 workers.surfaceCount is set and workers.dispatch names none of workers.surfaces, so the hosted-surface workers were not started. —
STS-WORKER-0040 A batch request (workers.batch) was refused because workers.batchQueueLimit batch requests were already waiting for the pool’s batch lane. HTTP 503 with Retry-After
STS-WORKER-0041 A batch request (workers.batch) waited workers.batchQueueTimeoutS for the pool’s batch lane and was refused. HTTP 503 with Retry-After
STS-WORKER-0042 The connection to a request worker failed before any byte of a dispatched request reached it, and the request was sent again on a new connection (#77). Nothing: the client gets the worker’s answer
STS-WORKER-0043 A request worker exited (or could not start) and a replacement was forked into its pool and slot. Nothing directly: requests in flight on the dead worker were answered 502 (STS-WORKER-0030)
STS-WORKER-0044 The /admin/worker-pools page or GET /admin-api/worker-pools could not build its report of the worker pools (#327). HTTP 500 page or JSON
STS-WORKER-0045 A request worker could not be forked at all (the fork call threw); the start gate moved on to the next (#342). —
STS-WORKER-0046 A request worker ran out of heap: its heap reached its limit (workers.heapLimitMb, #341) — ERR_WORKER_OUT_OF_MEMORY for a worker thread since #364, a SIGABRT of a worker process before. Nothing directly: requests in flight on it were answered 502
STS-WORKER-0047 (retired) A request worker was SIGKILLed while the container cgroup’s oom_kill count rose: the kernel’s OOM killer ended it because the container reached its memory limit (#341). Retired by #364: a worker is a thread, and the kernel’s OOM killer ends the whole process. —
STS-WORKER-0048 A heap limit was due for the front process and it could not restart itself with one (no process.execve, or the call failed), so it runs without a limit; its request workers still get one (#341). —

STS-STORE

Persistence and coordination. The memory, LDIF and PostgreSQL stores, the minted-row flush, and the change log several processes coordinate through.

Raised from: persistence/.

Code What failed Client sees
STS-STORE-0001 A scheduled persistence flush threw past its own handler. —
STS-STORE-0002 Writing the directory, the realm registry or the settings overrides to the persistence store failed; the change stays in memory, the write is retried with a backoff, and in postgres mode a request whose change was in it is answered 503 (STS-STORE-0066). —
STS-STORE-0003 persistence.mode names a mode the persistence module does not know, so nothing is persisted. —
STS-STORE-0004 The service refused to start: a persisting mode is configured and no directory module is installed to persist. —
STS-STORE-0005 The service refused to start: the database password comes from a secret store but persistence.databaseUrl is not a URL it can be injected into. —
STS-STORE-0006 The service refused to start: the configured persistence store could not be opened or read. —
STS-STORE-0007 A realm stored in the persistence store could not be recreated at startup and was skipped. —
STS-STORE-0008 The final flush or close of the persistence store at shutdown failed; changes since the last successful write are lost. —
STS-STORE-0009 The store holds directory entries for a realm that is not defined; they are not loaded and the next write removes them. —
STS-STORE-0010 Lines of an LDIF store file were not loaded (a URL-valued attribute or a line before the first dn:). —
STS-STORE-0011 The LDIF store’s keys.json could not be parsed. —
STS-STORE-0012 Product mode asked for minted state to persist on a store that cannot hold it (ldif); sessions, tokens and the audit log stay in memory. —
STS-STORE-0013 A batched read of minted rows during replication failed; the page falls back to one query per row. —
STS-STORE-0014 A replicated minted-row change carried a key that is not the shape this service writes, and was skipped. —
STS-STORE-0015 Another process’s minted row could not be opened because this process has no key-encryption key; this process is behind. —
STS-STORE-0016 Another process’s minted row would not open under this process’s key-encryption key, and was skipped. —
STS-STORE-0017 Another process’s minted row opened and is not JSON, and was skipped. —
STS-STORE-0018 Minted state could not be written because no key-encryption key is available to seal it. —
STS-STORE-0019 A handle that is not a declared store reported a minted write; its rows cannot be written. —
STS-STORE-0020 A minted store holds a value that will not serialise, so that row cannot be written. —
STS-STORE-0021 Writing minted state (sessions, tokens, codes, the audit log) to the store failed; the keys stay journalled, the write is retried with a backoff, and in postgres mode a request whose rows were in it is answered 503 (STS-STORE-0066). —
STS-STORE-0022 The service refused to start: minted state is persisted but no key-encryption key is available to open it. —
STS-STORE-0023 An earlier run’s unreadable minted rows could not be cleared from the store. —
STS-STORE-0024 A store refused a minted row restored at startup; the row was dropped. —
STS-STORE-0025 (retired) Minted rows older than persistence.mintedRetention could not be purged from the store at startup. Retired (#333): a start deletes nothing; the persistence.minted-expiry-purge job does, and its failure is STS-STORE-0065. —
STS-STORE-0026 The service refused to start: the minted state in the store could not be read. —
STS-STORE-0027 The service refused to start: persistence.mode is postgres and persistence.databaseUrl was set to empty. —
STS-STORE-0028 The service refused to start: persistence.mode is postgres and the pg package is not installed. —
STS-STORE-0029 The postgres store could not be opened because the schema is missing or the connecting role lacks permission on it (build it with postgres/schema.sql). —
STS-STORE-0030 An idle pooled postgres client errored (typically a database restart); the pool makes a new one. —
STS-STORE-0031 A checked-out postgres connection errored while in use; it is discarded. —
STS-STORE-0032 A postgres transaction’s ROLLBACK failed; the connection is discarded. —
STS-STORE-0033 A postgres metrics connection could not be RESET and is discarded rather than returned to the pool. —
STS-STORE-0034 The database metrics could not be collected (no connection). —
STS-STORE-0035 The postgres LISTEN connection for change notifications dropped; it reconnects and the poll covers the gap. —
STS-STORE-0036 The postgres LISTEN connection for change notifications could not connect; the poll still converges. —
STS-STORE-0037 The change log could not be read at startup, so this process runs uncoordinated and keeps retrying. —
STS-STORE-0038 A pull of other processes’ changes from the change log failed; this process is behind until a retry succeeds. —
STS-STORE-0039 A read barrier gave up before catching up with the change log; the request is answered from this process’s copy. —
STS-STORE-0040 A read barrier could not read the change log; the request is answered from this process’s copy. —
STS-STORE-0041 Preparing a page of replicated rows of one kind failed; they are applied one at a time. —
STS-STORE-0042 One replicated change could not be applied in this process; the rest of the page is unaffected. —
STS-STORE-0043 Clearing an applier’s per-page replication state failed. —
STS-STORE-0044 The open persistence driver has no used-assertion functions, so the used-assertion history is held in this process and forgotten at a restart. —
STS-STORE-0045 Writing the used-assertion history to a file store failed; a claim that could not be written is refused, a confirmation is lost. —
STS-STORE-0046 The database store could not be asked whether an assertion has been used; the assertion is refused. —
STS-STORE-0047 Sweeping expired used-assertion rows, or removing a removed realm’s, failed; the rows are ignored by every read and expire. —
STS-STORE-0048 Confirming or releasing a used-assertion claim when its response finished failed; the row stays reserved until the assertion expires. —
STS-STORE-0049 A change-log sequence number this process stepped past never became visible within the hole lifetime, and is no longer asked for; it was a transaction that rolled back. —
STS-STORE-0050 A conditional write of a signing-key or certificate-authority row found the row inserted and removed by other writers twice while it waited, and wrote nothing. —
STS-STORE-0051 A certificate authority another node wrote was adopted and the TLS listener could not be reconciled with it. —
STS-STORE-0052 A directory entry this process added was already in the store as a DIFFERENT entry another node created first; the stored entry was kept and this process’s copy replaced by it. none — logged
STS-STORE-0053 A change to a directory entry was not written because another node deleted the entry after this process last saw it; the entry was removed here too. none — logged
STS-STORE-0054 A minted row (a session, a code, a token) was not written back because another node had already ended it and the store holds its tombstone; this process’s copy was dropped. none — logged
STS-STORE-0055 Expired tombstones of ended minted rows could not be swept from the store. none — logged
STS-STORE-0056 A minted row another node had changed could not be merged with this process’s copy (it would not open or the merge threw), so this process’s copy was written as it was. none — logged
STS-STORE-0057 A process found its place among the change log’s readers removed since it last reported: it had been declared gone, so changes it had not applied may have been trimmed. It should be restarted. —
STS-STORE-0058 A process could not report its position in the change log; the log is not trimmed past where it last said it was, and the report is retried after the next pull. —
STS-STORE-0059 Trimming the change log below every reader’s position failed; it is retried on the next interval. —
STS-STORE-0060 A process did not take the stable persistence origin for its node name and slot — a live process still held it after the wait, or it has no stable name — and writes under a random origin, so its per-process rows (audit, counters) are read by others as a contribution. none — logged at startup
STS-STORE-0061 A process lost the claim on its persistence origin while running — another process took it — and exits rather than go on refusing every write. none — logged, then the process exits
STS-STORE-0062 The claim on this process’s persistence origin could not be renewed because the store did not answer. Not fatal: the claim outlives a short outage and every write checks it. none — logged
STS-STORE-0063 A minted store journalled a key holding a NUL character, which PostgreSQL text cannot hold; the row is left out of the write rather than failing every write after it. none — logged
STS-STORE-0064 A minted store’s expiresAt hook threw while its row was being written; the row is written as not expiring, so it is restored and kept until the store deletes it. Said once per store. none — logged
STS-STORE-0065 The persistence.minted-expiry-purge job could not delete the expired, orphaned or stale minted rows; a start skips them anyway, and the next run tries again. none — logged, and the job run is recorded as failed
STS-STORE-0066 A request changed the store and the commit of that change failed, so it was answered 503 with Retry-After instead of its success (#351); the change is still in memory and its write is retried. RFC 9110 section 15.6.4
STS-STORE-0067 An LDAP operation changed the store and the commit of that change failed, so it was answered unavailable (52) instead of its result (#351); the change is still in memory and its write is retried. RFC 4511 section 4.1.9
STS-STORE-0068 This process’s event loop was blocked past the warning threshold in the last report window; timers such as the origin renewal and the cluster heartbeat ran that late too. none — logged
STS-STORE-0069 The renewal of this process’s origin claim started or answered more than half the claim’s lifetime late; the line names the event loop’s delay, so a lost origin says why. none — logged
STS-STORE-0070 The liveness connection (origin renewal, heartbeat, leases) dropped or could not be opened; the next statement reconnects, and one that cannot goes through the pool. none — logged
STS-STORE-0071 A secret setting saved in the store (sts_appconfig or a realm’s overrides) is sealed and did not open; it is ignored and the setting has its configured value until it is set again (#222). —
STS-STORE-0072 A directory entry is sealed and did not open in this process (a data key it does not hold, or a blob that names another DN); it is left out of what the store answered (#391). —
STS-STORE-0073 The directory could not be walked to count or re-seal what its entries hold under a data key; nothing in it was counted or changed, so no key is destroyed on that count (#391). —
STS-STORE-0074 The PostgreSQL store was built before schema version 14: its directory lookup columns are generated from plaintext attributes, and this build seals every entry. The start is refused; recreate the database (#391). none — fatal at start

STS-CLUSTER

Cluster membership and agreement. Several containers against one store: membership and its heartbeat, leases and the fence every write checks, the gate in front of active-passive and active-active mode, atomic claims, the secrets every node shares, and the barrier that makes a request see what other nodes committed before it arrived.

Raised from: cluster/.

Code What failed Client sees
STS-CLUSTER-0001 A write transaction was refused by the fence: this node’s membership row had expired, or a lease the write needed was no longer held at the token it was acquired with. —
STS-CLUSTER-0002 This node was refused membership because a live node is running a different cluster mode or a different fingerprint of the settings every node must share; it does not start. —
STS-CLUSTER-0003 A heartbeat could not be written; the node keeps serving until its membership would expire. —
STS-CLUSTER-0004 This node could not renew its membership within its lifetime and exits, because the others may already treat it as dead. —
STS-CLUSTER-0005 This node’s membership row had already expired when it tried to renew it, so it exits rather than come back. —
STS-CLUSTER-0006 This node lost a lease that its role depends on (the service lease in active-passive mode) and exits. —
STS-CLUSTER-0007 A cluster mode other than off was configured without a postgres persistence store; the service does not start. —
STS-CLUSTER-0008 Active-active mode was configured without persisted keys under an operator key-encryption key, which every node must share; the service does not start. —
STS-CLUSTER-0009 Active-active mode was refused because capabilities it depends on are not provided by this build and were not accepted as missing; the service does not start. —
STS-CLUSTER-0010 Leaving the cluster on shutdown failed; this node’s row and leases expire on their own. —
STS-CLUSTER-0011 A write was fenced and this process exits, because a process that has lost its right to write would try again on the next change. —
STS-CLUSTER-0012 Asking the store for a lease failed; the role is not taken and is asked for again on the next heartbeat. —
STS-CLUSTER-0013 The claim store could not be asked; the single-use value is refused rather than accepted unrecorded. —
STS-CLUSTER-0014 Releasing a claim failed; it stays held until it expires. —
STS-CLUSTER-0015 Sweeping expired claims failed; they are ignored by every read and swept on the next attempt. —
STS-CLUSTER-0016 A secret every node must share could not be written to or read from the store; the service does not start. —
STS-CLUSTER-0017 A shared secret could not be sealed or opened with the key-encryption key; the service does not start. —
STS-CLUSTER-0018 A request could not catch up with the other nodes’ committed writes before it was served; it is answered from this process’s copy. —
STS-CLUSTER-0019 An outbound message held until this node’s writes committed could not commit them; it is sent anyway and the writes are retried. (A held RESPONSE whose commit fails is STS-STORE-0066 since #351.) —
STS-CLUSTER-0020 Active-active mode is running with capabilities an operator accepted as missing; each named one is a known way nodes disagree. —
STS-CLUSTER-0021 A request worker could not attach to its node’s cluster membership; the worker does not start. —
STS-CLUSTER-0022 A counter that may only go up (a WebAuthn signature counter, a one-time code step) could not be advanced because the store could not be asked; the credential is refused. —
STS-CLUSTER-0023 A rate-limit window every node counts in could not be counted, read or cleared because the store could not be asked; the limiter decided on this process’s own buckets for that attempt. —
STS-CLUSTER-0024 Sweeping the rate-limit windows whose time has passed failed; they are swept on a later count. —
STS-CLUSTER-0025 A node’s heartbeat ran late by a heartbeat or more because its event loop was busy; a stall past the membership lifetime costs the node its membership. —
STS-CLUSTER-0026 Active-active mode was refused because global.publicBaseUrl is empty, so each node would name itself by the address it was reached on. —
STS-CLUSTER-0040 A cluster mode was configured with persistence.minted off, so nodes would not share sessions, pending sign-ins, codes or tokens; the service does not start. —
STS-CLUSTER-0041 Standing down from a lease early failed in the store; the lease expires on its own within one node lifetime, and this node does not renew it. —
STS-CLUSTER-0162 The store every node shares could not be asked to spend against a budget (a GNAP right’s limits); the operation was refused (#432 phase 5). —
STS-CLUSTER-0163 A spend against a shared budget could not be refunded: the store could not be asked (#432 phase 5). —

STS-CELL

Cells and residency. One service deployed as several cells in several jurisdictions: the global and cell tiers of the store, the routing index that says where a person is homed, the inter-cell channel, relaying a request to the cell that owns it, the sealed locators, the transfer decisions and the revocations pushed between cells.

Raised from: common/cells.ts, common/cell_*.ts, persistence/tiers.js, persistence/persistence_tiered.js, admin-ui/cells_admin.ts.

Code What failed Client sees
STS-CELL-0001 The cell settings are inconsistent (an id without a jurisdiction, a malformed cells.peers, a peer with this cell’s id, or a cell id that is not [a-z0-9]{1,16}); the service does not start. —
STS-CELL-0002 cells.id is set and persistence.globalDatabaseUrl is empty, or the store is not postgres; a cell keeps its global rows in the global database, so the service does not start. —
STS-CELL-0003 A multi-cell deployment in product mode has no cell key-encryption key (keys.cellKekProvider is none), so one cell’s rows would open in every other; the service does not start. —
STS-CELL-0004 A service deployed as cells does not persist its signing keys or has no operator key-encryption key, so its cells would sign with different keys and could not open each other’s global rows; the service does not start. —
STS-CELL-0005 A service deployed as cells has no global.publicBaseUrl, so a cell would build addresses from the name a request reached it by; the service does not start. —
STS-CELL-0010 The global tier database password was read and is empty; the service does not start. —
STS-CELL-0011 The cell key-encryption key has no location of its own, or names the service key’s; it has no fallback, so the service does not start. —
STS-CELL-0012 The cell key-encryption key is the same key as the service key-encryption key; the service does not start. —
STS-CELL-0020 A person was written in this cell whose login name or entryUUID the routing index already places in another cell (a creation raced the index check); sign-in routing will not find the copy here. —
STS-CELL-0021 The routing index could not be updated at a directory flush; it is retried at the next write of the same person. —
STS-CELL-0022 Group membership rows in this cell belong to a group the global tier no longer has; they are not restored. —
STS-CELL-0030 A request could not be relayed to the cell that owns it, or that cell could not be dialled; the request is answered 503 here (fail-closed). —
STS-CELL-0031 This process’s inter-cell certificate could not be issued (the process branch or its inter-cell Issuing CA is missing or refused). —
STS-CELL-0032 A peer on the inter-cell channel was refused: its chain does not verify to the service Root, its leaf is not from the inter-cell Issuing CA, or it names a cell that is not one of this cell’s peers or not the one dialled. —
STS-CELL-0033 The inter-cell listener could not bind its port; requests relayed to this cell and questions from other cells fail at them. —
STS-CELL-0034 A relayed request did not carry its sending cell and exactly one hop, or a relayed request would have been relayed again; refused. —
STS-CELL-0035 An inter-cell operation call was refused: no such operation, not a POST, a body that is not JSON, or a body over the size limit. —
STS-CELL-0036 An inter-cell operation failed, at this cell for another’s call or at another cell for this one’s. —
STS-CELL-0040 The routing index could not be read while finding a person’s home cell; the request is served here as if the person were unknown. —
STS-CELL-0041 A pushed authorization request could not be handed to the home cell of a flow restarting there; the flow restarts without it. —
STS-CELL-0042 A request another cell selected this one for (?cell=) was refused: the release policy does not permit this cell’s people to be released to a reader in that cell’s jurisdiction. —
STS-CELL-0043 A person’s creation named a home cell this service does not have, or one in a jurisdiction the realm may not place people in (cells.jurisdictions); refused. —
STS-CELL-0044 A person’s creation was refused because the routing index already places that login name in another cell: a login name is unique in a realm across every cell. —
STS-CELL-0045 A re-homing was refused: the target is not a cell of this service, is this one, is in a jurisdiction the realm may not place people in, or the person is not homed here. —
STS-CELL-0046 A re-homing was refused: a value sealed on the person’s entry or device will not open in this cell, so it cannot be moved. —
STS-CELL-0047 A re-homing failed part way: the target did not take the person, the routing index could not be moved, or what was left here could not be removed. The log line says which, and what is left. —
STS-CELL-0048 A re-homed person could not be put back in one of their groups at the receiving cell. —
STS-CELL-0050 A change made in this cell to a projected person could not be sent to their home cell; it is held here only until the session ends. —
STS-CELL-0051 The cells holding a projection of a changed person could not be told; each finds out at its next check against home. —
STS-CELL-0052 A session could not be exported to the cell a relayed request came from; it stays at home and the browser stays pinned there. —
STS-CELL-0053 What this cell held for a person homed elsewhere could not be ended when their home said to. —
STS-CELL-0054 Another cell sent a change to an attribute of a person homed here that no other cell may write (a credential, the name, the entryUUID, memberOf); refused. —
STS-CELL-0055 A cell holding a person’s exported session could not be told to end it; it finds out at its next check against home. —
STS-CELL-0056 The home cell of a projected person could not be reached to confirm the account; refused fail-closed, or allowed within cells.failOpenGraceS when cells.homeUnreachable is fail-open. —
STS-CELL-0060 An inter-cell delivery was not sent: the outbound kill switch is on. —
STS-CELL-0061 An inter-cell delivery names no cell this service has; it is dead-lettered. —
STS-CELL-0062 An inter-cell delivery could not be prepared; it is dead-lettered. —
STS-CELL-0063 An inter-cell delivery could not reach the other cell (a timeout or a connection failure); it is tried again with a doubling backoff. —
STS-CELL-0064 The other cell refused an inter-cell delivery, or it was given up after its last attempt; it is dead-lettered and retried by hand from /admin/deliveries. —
STS-CELL-0065 An inter-cell delivery was deferred to a later attempt. —
STS-CELL-0066 An inter-cell delivery stayed pending past cells.deliveryRetentionS and was dead-lettered. —
STS-CELL-0067 The periodic summary of inter-cell deliveries in a realm: sent, retried and dead-lettered since the last line. —
STS-CELL-0068 The inter-cell delivery sweep failed; it runs again at its next slot. —
STS-CELL-0069 An inter-cell dead letter could not be retried. —
STS-CELL-0100 An ACME request naming its account only by key (a newAccount with no External Account Binding) or an RFC 9773 renewal-info request could not be asked of every other cell; it is refused 503 rather than answered by a cell that could not know. RFC 8555 section 7.3.1; RFC 9773 section 4
STS-CELL-0101 An EST enrollment on behalf of a person homed in another cell was refused: the certificate is written onto their entry only in that cell, and the administrator’s own credential is checked only in theirs. RFC 7030 section 4.2
STS-CELL-0120 Two cells’ short keyed tags collide, so a SAML artifact whose handle carries one is served where it arrives rather than relayed to either. —
STS-CELL-0121 A cell could not be asked whether it holds the session a SAML attribute or authentication query names; the query is answered without it. —
STS-CELL-0122 A federation partner’s sign-out could not reach every cell; sessions held in a cell not reached last until they end by themselves, and the partner is told where its protocol allows. —
STS-CELL-0123 A cell could not be asked whether a person homed there carries a federation partner’s link; the partner’s subject is decided without it. —
STS-CELL-0124 A person’s home cell did not release their attributes to the cell serving a token about them (the transfer policy refused, or no policy was available); the token is refused. —
STS-CELL-0125 A person’s home cell could not be reached for their attributes; a token about them is refused (fail-closed, D6). —
STS-CELL-0140 A SCIM create names a home cell (the iya-sts User extension’s homeCell, or the realm’s default) that this service does not have or that is outside the jurisdictions the realm may home people in; refused 400 invalidValue and nothing is created. RFC 7644 section 3.12
STS-CELL-0141 A SCIM create reached a cell that is not the home it resolves to and could not be relayed again (it arrived relayed, or inside a relayed BulkRequest); refused 400 invalidValue rather than made in the wrong region. RFC 7644 section 3.12
STS-CELL-0142 A SCIM create names a login name the routing index already places in another cell of this realm; refused 409 uniqueness. RFC 7644 section 3.12
STS-CELL-0143 A SCIM Group write names members homed in more than one cell; one request is performed in one cell, so it is refused 400 invalidValue whole and nothing is changed. RFC 7644 section 3.12
STS-CELL-0144 A SCIM BulkRequest’s operations belong to people homed in more than one cell; it is refused 400 invalidValue whole before any operation runs. RFC 7644 section 3.7
STS-CELL-0145 A SCIM write to an existing User names a homeCell other than the one the person is homed in; re-homing is an administrator’s act, so it is refused 400 mutability. RFC 7644 section 3.12
STS-CELL-0146 The routing index could not be asked to claim a SCIM create’s login name; the create is refused 500 and nothing is written. —
STS-CELL-0147 An LDAP simple bind names a person homed in another cell, and that cell could not be asked to verify the password; the bind is refused LDAP_UNAVAILABLE (52), fail-closed, and not counted as a failed bind. RFC 4511 section 4.1.9
STS-CELL-0160 A GNAP continuation for a grant that moved to another cell reached the cell it moved from by way of a third cell, and a relayed request is not relayed again; answered 503 too_fast so the client tries again once every cell knows where the grant went. RFC 9635 section 5
STS-CELL-0161 The cell that minted a GNAP grant did not hand it to the cell the resource owner’s browser is pinned to — it had issued tokens, was no longer waiting, or was not held there; the browser is told nothing is waiting. —
STS-CELL-0162 A GNAP grant waiting at an interaction handle could not be fetched from the cell that minted it; the browser pinned here is told nothing is waiting. —
STS-CELL-0163 Another cell could not be asked whether it holds a GNAP access token, user code or user reference; the request is served here as if no cell did. —
STS-CELL-0164 Another cell could not be told that a GNAP grant moved; a continuation it receives goes to the minting cell by the grant’s tag and is forwarded from there. —
STS-CELL-0165 A GNAP inter-cell operation was malformed: an unknown realm, an unknown kind, or a grant handed to no other cell; the calling cell is answered with a failure. —
STS-CELL-0180 Neither the issuance policy nor the built-in one it falls back to gave a verdict on a transfer question (hold-session or serve-request) — a defect; the strict default was read from the facts instead: a session is held only in the same jurisdiction or a listed transfer, a request refused only under a hard geofence (#98). none — a warning in the log
STS-CELL-0181 The built-in issuance policy could not be evaluated for a transfer question in a process with no issuance PEP — a defect; the strict default was read from the facts instead (#98). none — an error in the log
STS-CELL-0182 A transfer question named a realm this service does not have; the session is not held away from home, the request is not served and nothing is released (#98). —
STS-CELL-0183 A request about a person homed in another jurisdiction was refused under the realm’s hard geofence (cells.hardGeofence): the issuance policy answered serve-request with refuse, so it is neither served nor relayed (#98). —
STS-CELL-0184 Personal data of the people homed in this cell was withheld from a reader at a cell in another jurisdiction (a directory listing or a management-API call relayed with ?cell=): the issuance policy answered release-attributes with withhold (#98 D11). —
STS-CELL-0190 Server configuration -> Cells (/admin/cells) could not be drawn: the cell map or its peers could not be read; the page answers 500 and the reason is logged. —
STS-CELL-0191 GET /admin-api/cells could not read the cell map; the call answers 500 server_error. —
STS-CELL-0192 POST /admin-api/cells/rehome failed without a refusal of its own (the move threw, or a refusal carried no code); the call answers an error and the person stays where they were homed. —
STS-CELL-0193 A person’s creation from the console or /admin-api arrived relayed from another cell for a home that is not this cell (the two cells’ settings disagree); it is refused 400 rather than relayed again, and nothing is created. —
STS-CELL-0194 Another cell did not answer cluster-summary (#361): the Cluster page and GET /admin-api/cluster draw that cell as unreachable, with the reason, and every other cell as it answered. —
STS-CELL-0200 The one-time conversion of a single-cell store into a cell (persistence/cell_convert.js) was refused before it read anything: an unknown argument, no cells.id, a store that is not postgres, no global database, or keys not persisted under an operator key-encryption key. Nothing is changed and it exits non-zero. none — an operator tool
STS-CELL-0201 The conversion found the cell or the global database at a schema version other than this service’s; postgres/schema.sql has to be run against both first. Nothing is changed. none — an operator tool
STS-CELL-0202 The conversion found nothing to convert: the cell database holds no realm and no key and the global database is empty — the cell’s database URL does not name the single-cell deployment’s database. Nothing is changed. none — an operator tool
STS-CELL-0203 The conversion refused a second source: the global database already holds realms or keys that are not the cell database’s, or a routing index row naming another cell. Nothing is changed. none — an operator tool
STS-CELL-0204 The conversion’s copy into the global database (or an already-converted store’s missing routing index rows) could not be written; the transaction was rolled back and the cell database is unchanged. Running it again is safe. none — an operator tool
STS-CELL-0205 The conversion read the global database back after the copy and it did not hold what was copied (a row missing or different, or a person indexed in another cell); the cell database is unchanged. none — an operator tool
STS-CELL-0206 The conversion copied and verified the global rows and then could not take them out of the cell database; that transaction was rolled back. Running it again finds the copy and finishes. none — an operator tool
STS-CELL-0207 The conversion could not hold the service key-encryption key, or it did not open the stored key sets: the routing index’s digests are keyed under it and would route nobody. Nothing is changed. none — an operator tool
STS-CELL-0208 The conversion could not dial or read the cell or the global database the way the service does (a connection, a password provider or a statement failed). Nothing is changed. none — an operator tool
STS-CELL-0209 A conversion finished with something worth a look: the sts_risk_* counts moved while it ran (something else was writing the cell database), or an already-converted cell database holds a global-tier directory row or a person indexed in another cell. Nothing is changed for it. none — a warning in the log
STS-CELL-0210 A cell conversion found a sealed directory entry it could not open, so it could not decide the entry’s tier; nothing was converted (#391). cell_convert — refused

STS-SCHED

Scheduler. The one scheduler every periodic job in this service runs on: who leads it, the claim and fence that make a job run once per slot in the whole cluster, the runs it records, manual runs and the planned handover of its leadership.

Raised from: cluster/scheduler.ts, admin-ui/scheduler_admin.ts.

Code What failed Client sees
STS-SCHED-0001 A scheduled job’s run threw or rejected; the run is recorded as failed with the reason, and the job runs again at its next slot. —
STS-SCHED-0002 A job’s run took longer than its time limit; it is recorded as failed, its claim is given back, and anything it still does is fenced out. —
STS-SCHED-0003 A run’s outcome was fenced out: another attempt took the run over after this one’s claim lapsed, so this one’s result is not written. —
STS-SCHED-0004 A manual run was refused: no job by that id is registered. —
STS-SCHED-0005 A manual run was refused: the job runs on its schedule only. —
STS-SCHED-0006 A manual run was refused: the job is off (its setting, scheduler.enabled, or a development-mode predicate), and says why. —
STS-SCHED-0007 A manual run was refused to a realm administrator: the job is service-scoped, or names another realm. —
STS-SCHED-0008 The claim store could not be asked whether a run was already taken; the run is not started until it can be, so it never runs twice. —
STS-SCHED-0009 A job registration was refused whole: a member is missing or malformed, or the id is taken. —
STS-SCHED-0010 A step-down was refused: this service is not clustered, so there is no other node to hand the scheduler to. —
STS-SCHED-0011 A run was abandoned: the node running it stopped holding its claim before it finished, and another attempt took it over. —
STS-SCHED-0012 A manual run was refused: the realm it names does not exist. —
STS-SCHED-0013 The scheduler’s tick failed unexpectedly; it is tried again at the next tick. —
STS-SCHED-0014 The scheduler’s leader could not stand down; its lease expires on its own. —
STS-SCHED-0015 A per-process job’s run in this process threw or rejected; its row for this process says so, and it runs again at its next slot. —
STS-SCHED-0016 A run was asked for that does not exist (an unknown run id). —
STS-SCHED-0017 Purging the scheduler’s run history past its bound (scheduler.runHistoryCount, scheduler.runHistoryHours) failed; the rows stay until the next run of scheduler.history, and a start still skips the ones past their expiry. —
STS-SCHED-0018 A run of a realm job was not started, or its outcome not written, because its trust realm was removed; nothing is run for a removed realm, and nothing is written back into it. —

STS-KEYS

Cryptography, keys and secrets. Signing, verification, encryption and decryption; the signing keys that survive a restart; the key-encryption key and the database password read from a secret store.

Raised from: common/crypto.js, common/pq_jose.js, common/keystore.js, common/secrets.js.

Code What failed Client sees
STS-KEYS-0001 The artifact logger handed to an XML encryption threw and was ignored. —
STS-KEYS-0002 The key-encryption key is empty or shorter than 32 bytes and was refused rather than stretched. —
STS-KEYS-0003 This runtime cannot generate ML-DSA keys (it needs OpenSSL 3.5 / node 24); ML-DSA certificates are unavailable. —
STS-KEYS-0004 A stored password or secret hash is not decodable and was treated as no match. —
STS-KEYS-0005 A stored password or secret hash names scrypt parameters this process cannot compute and was treated as no match. —
STS-KEYS-0006 (retired) The worker pool could not run a scrypt derivation, so it was computed in the front process instead. Retired by #363: scrypt runs on libuv’s thread pool and there is no worker pool to fail. —
STS-KEYS-0007 An XML signature was not verified: the document is not well-formed XML. refusal by the calling protocol (e.g. SAML Responder status, SOAP fault)
STS-KEYS-0008 An XML signature was not verified: the named element is absent or carries no ds:Signature of its own. refusal by the calling protocol
STS-KEYS-0009 An XML signature was refused because its Reference names a different element than the one it is attached to (signature wrapping). refusal by the calling protocol
STS-KEYS-0010 An XML signature on a nested element uses inclusive canonicalization, which this service cannot reproduce, and was refused. refusal by the calling protocol
STS-KEYS-0011 The XML signature engine threw on a malformed signature element or an unknown algorithm. refusal by the calling protocol
STS-KEYS-0012 An XML signature value does not verify against the expected certificate or key. refusal by the calling protocol
STS-KEYS-0013 An XML signature is genuine but the digest does not match: the signed element was altered. refusal by the calling protocol
STS-KEYS-0014 An XML signature did not verify for a reason other than the signature value or the digest. refusal by the calling protocol
STS-KEYS-0015 An XML-encrypted element could not be decrypted: it is not well-formed XML. refusal by the calling protocol
STS-KEYS-0016 An XML-encrypted element could not be decrypted: it contains no xenc:EncryptedData. refusal by the calling protocol
STS-KEYS-0017 An XML-encrypted element uses a block cipher this service does not read. refusal by the calling protocol
STS-KEYS-0018 An XML-encrypted element carries no xenc:EncryptedKey in its KeyInfo (RetrievalMethod is not implemented). refusal by the calling protocol
STS-KEYS-0019 An XML-encrypted element wraps its key with a key transport this service does not unwrap. refusal by the calling protocol
STS-KEYS-0020 An XML-encrypted element is missing one of its two xenc:CipherValue elements. refusal by the calling protocol
STS-KEYS-0021 An XML-encrypted element’s wrapped key unwrapped to the wrong length: it was encrypted to a different certificate. refusal by the calling protocol
STS-KEYS-0022 An XML-encrypted element failed its AES-GCM authentication tag. (An AES-CBC failure is STS-KEYS-0078 since #202.) refusal by the calling protocol
STS-KEYS-0023 An XML-encrypted element decrypted with AES-GCM to something that is not well-formed XML — or, since #193, to octets that are not UTF-8 at all (binary data). (AES-CBC: every such failure is STS-KEYS-0078 since #202, one answer, closing the padding oracle.) refusal by the calling protocol
STS-KEYS-0024 An XML-encrypted element’s key could not be unwrapped with this service’s private key. refusal by the calling protocol
STS-KEYS-0025 An XML-encrypted element could not be read for a reason other than the key. refusal by the calling protocol
STS-KEYS-0026 The keystore was handed a store without both loadKeys and saveKeys, and refused it whole. —
STS-KEYS-0027 The service refused to start: signing keys are configured to persist and no persistence store is open. —
STS-KEYS-0028 The service refused to start: the stored signing key material could not be loaded from the store. —
STS-KEYS-0029 The service refused to start: stored signing key material could not be decrypted, almost certainly because the key-encryption key is not the one it was sealed with. —
STS-KEYS-0030 Signing keys adopted from another process could not be held, or this process’s cached set could not be dropped, so it keeps signing with its own and disagrees with the rest of the service. —
STS-KEYS-0031 A realm’s signing keys could not be serialised for sharing with other processes, so another process may hold different keys. —
STS-KEYS-0032 A realm’s stored key material is held encrypted and there is no key-encryption key to open it, so a new signing key is generated. —
STS-KEYS-0033 A realm’s key material decrypted at startup and no longer decrypts (corruption or a bug). —
STS-KEYS-0034 A realm’s generated signing keys cannot be written (no store open or no key-encryption key), so they will differ after the next restart. —
STS-KEYS-0035 Writing a realm’s signing keys to the store failed, so they will differ after the next restart. —
STS-KEYS-0036 Rotation could not remove a realm’s stored signing keys. —
STS-KEYS-0037 A realm was removed and its stored signing keys could not be removed with it. —
STS-KEYS-0038 An ephemeral key-encryption key was offered while the keystore persists, and was refused. —
STS-KEYS-0039 The ephemeral key-encryption key handed to this process was not usable. —
STS-KEYS-0040 A value could not be sealed under the key-encryption key. —
STS-KEYS-0041 A realm’s certificate authority cannot be written (no store open or no key-encryption key), so it will be gone after the next restart. —
STS-KEYS-0042 Writing a realm’s certificate authority to the store failed. —
STS-KEYS-0043 The key-encryption key could not be read from its configured secret provider. —
STS-KEYS-0044 The database password could not be read from its configured secret provider. —
STS-KEYS-0045 A secret provider’s SDK package is not installed (it is an optional peer dependency). —
STS-KEYS-0046 A secret provider is selected but its location (file path, secret id, resource name, vault URL or read path) is not configured. —
STS-KEYS-0047 The file holding a secret could not be read. —
STS-KEYS-0048 A secret store answered with no value, or without the named field. —
STS-KEYS-0049 The database password’s location is shared with the key-encryption key and holds something that is not a JSON object, so it was refused rather than handing the key to a database. —
STS-KEYS-0050 A secret’s provider setting names a provider that does not exist. —
STS-KEYS-0051 The secret store accepted the client certificate at the cert auth method and returned no token. —
STS-KEYS-0052 keys.vaultCertAuthMount is not a mount path this service will put into a request. —
STS-KEYS-0053 The database password read from its secret provider is empty and was refused. —
STS-KEYS-0054 The file holding a secret is readable by group or other. —
STS-KEYS-0055 keys.kidFormat asks for an RFC 9278 JWK Thumbprint URI and none could be computed for a signing key, so its tokens carry the internal kid. Logged once per key. none — the token is signed under its internal kid
STS-KEYS-0056 A queued write of a signing-key or certificate-authority row failed in a way its own handler did not report. —
STS-KEYS-0057 A certificate authority row was changed by another node at the same moment, and that node’s CA tier or certificate slot was kept over this one’s (first writer wins). —
STS-KEYS-0058 A signing-key or certificate-authority row another process wrote could not be decrypted or parsed, so it was not adopted. —
STS-KEYS-0059 A detached HTTP Redirect binding signature does not verify against the certificate it was checked with. the caller’s own refusal
STS-KEYS-0060 A detached HTTP Redirect binding signature could not be checked: no certificate, no Signature, an unreadable certificate, a Signature that is not base64, or an unreadable certificate. (An algorithm this service does not verify is STS-KEYS-0061 since 2026-09-17; SHA-1 refused by policy is STS-KEYS-0062.) the caller’s own refusal
STS-KEYS-0061 An XML signature (enveloped, or an HTTP binding’s detached one) names a SignatureMethod or DigestMethod this service does not verify — MD5, a MAC, Whirlpool, ESIGN, pre-hashed EdDSA, HSS/LMS or an unknown URI — or RSASSA-PSS parameters node cannot express. Refused as not checkable, on every XML signature path. refusal by the calling protocol
STS-KEYS-0062 An XML signature uses SHA-1 (its SignatureMethod or a DigestMethod) and saml.allowSha1Signatures is off (the default), so it was refused before any cryptography, on every XML signature path. refusal by the calling protocol
STS-KEYS-0063 A signing key rotation was refused: the realm’s key set could not be replaced (a newer generation was already held, or the store refused the write). the scheduler run fails with this code; /admin/keys and /admin-api report it
STS-KEYS-0064 After an emergency key rotation the realm’s sessions could not be ended; the keys were rotated and their certificates revoked. none — logged; the run still succeeds and its audit row counts the sessions ended
STS-KEYS-0065 A rotation was asked for a signing unit this realm does not have. HTTP 400 from POST /admin-api/keys/rotate; a refusal on /admin/keys
STS-KEYS-0066 An emergency rotation was asked for without its confirmation (confirm: “compromised”). HTTP 400 from POST /admin-api/keys/emergency; a refusal on /admin/keys
STS-KEYS-0067 A realm’s signing-key history could not be recorded; the rotation or retirement itself succeeded. none — logged. The next observation writes the rows, because the history is derived from the key set rather than from the event
STS-KEYS-0068 The signing-key history was asked for a unit this realm has no record of. HTTP 400 from GET /admin-api/keys/history; a refusal on /admin/keys/history
STS-KEYS-0069 A certificate authority row listed a certificate it still publishes as revoked; the revocation was dropped rather than written. none — logged. A row may not publish a certificate its own CRL calls revoked; the drop is evidence of a tier write that was lost
STS-KEYS-0070 An XML element encrypted to this realm wrapped its key with rsa-1_5 (RSAES-PKCS1-v1_5), and the realm is in product mode, where that key transport is never unwrapped — XML Encryption 1.1 section 6.1.2 (#181). the caller’s refusal: a LogoutRequest’s EncryptedID that cannot be read is answered as the SAML binding says
STS-KEYS-0071 An XML element’s block cipher, key management or OAEP digest is one the caller’s allow-list excludes; refused before any key operation (#168). the caller’s refusal — federation answers STS-FED-0139
STS-KEYS-0072 An rsa-oaep or rsa-oaep-mgf1p EncryptedKey named a digest and mask generation function this service cannot unwrap with: an unknown one, or two that differ (node derives MGF1 from the OAEP digest; rsa-oaep-mgf1p fixes MGF1 at SHA-1, so any other digest there, since #193). the caller’s refusal
STS-KEYS-0073 An XML element’s key is agreed by an AgreementMethod other than ECDH-ES. the caller’s refusal
STS-KEYS-0074 An XML element encrypted by ECDH-ES key agreement was handed to a recipient whose private key is not an EC key. the caller’s refusal
STS-KEYS-0075 A certificate authority another process in this service sent publishes a tier this process holds as superseded — a copy from before a rebuild — so it was refused, and the hierarchy held here was asserted again where it is itself consistent. none — logged. A supersession is permanent; adopting the copy put a replaced Intermediate back in every process
STS-KEYS-0076 A certificate authority merged with a copy another process had written publishes certificates its own Issuing CAs did not sign — keys certified from the branch a rebuild replaced — and each is certified again from the live Issuing CA. none — logged. The evidence of a certification that crossed a rebuild; the row would otherwise publish a certificate no published authority signed
STS-KEYS-0077 An XML signature was checked with an ECDSA key on a curve weaker than P-256 (secp160, secp192, secp224 and the like), and the realm is in product mode, where such a key verifies nothing (#202). the caller’s refusal: the signature does not verify, and each protocol answers that as it answers a wrong signature
STS-KEYS-0078 An AES-CBC XML-encrypted element did not decrypt to a well-formed element: its padding, its UTF-8 or its XML was wrong, and which is deliberately one answer — the padding oracle of XML Encryption 1.1 section 6.1.3, closed (#202). refusal by the calling protocol
STS-KEYS-0090 An XML element encrypted by ECDH-ES key agreement derives its key with something other than a SHA-256/384/512 ConcatKDF (PBKDF2, a SHA-1 digest, none), or names its originator key on a curve this service does not agree over; refused before any key operation (#193 — it was reported as a key encrypted to another certificate). the caller’s refusal
STS-KEYS-0091 A stored data encryption key could not be unwrapped under the key-encryption key — almost always the wrong key-encryption key. At startup the service does not start (#391). —
STS-KEYS-0092 A sealed value names a data encryption key this process does not hold, so it does not open; the stored data-key rows are read again in the background. Said once per key (#391). —
STS-KEYS-0093 A data-key row could not be written to the store; what was sealed under its new keys will not open after a restart until it is (#391). —
STS-KEYS-0094 A stored data-key row could not be read, so the data encryption keys in it are not held (#391). It is not overwritten. —
STS-KEYS-0095 A stored key row is not a version-2 envelope: the store was written before data encryption keys (#391) and this build does not read it. The service does not start; recreate the store. —
STS-KEYS-0096 Data encryption keys wrapped under the PREVIOUS key-encryption key (keys.previousKek*) were re-wrapped under the current one at start. Once every node runs with the current key, the previous one may be removed (#391). —
STS-KEYS-0097 A key-set or certificate-authority row under a superseded data encryption key could not be re-sealed; it stays under the old key, which is then not destroyed (#391). —
STS-KEYS-0098 keys.previousKekProvider names a provider and its location is empty, so the previous key-encryption key could not be read. The service does not start (#391). —
STS-KEYS-0099 A pass of the data-key re-encryption job failed: what is sealed under superseded data encryption keys could not be counted or re-sealed. Nothing is destroyed; the next pass tries again (#391). —
STS-KEYS-0100 A data-key rotation was asked for where data encryption keys are derived per run and not stored, or for a realm or class no stored key serves (#391). the console’s and the API’s refusal, 400
STS-KEYS-0101 A secret other than the key-encryption key names a key management service (vault-transit, aws-kms, gcp-kms, azure-keys) as its provider; a KMS wraps keys and holds nothing to read. The read is refused (#391). —
STS-KEYS-0102 The key management service’s key is not one data keys can be wrapped under: a Transit key that is not AEAD (associated data is required), an AWS KMS key that is not an enabled symmetric ENCRYPT_DECRYPT key, or a Transit mount that is not a plain path. The service does not start (#391). —
STS-KEYS-0103 A key management service did not wrap or unwrap a data encryption key: it refused, answered nothing, or the wrapped key is under another KMS key. A new data key is not written; one that does not unwrap at start stops the start (#391). —
STS-KEYS-0104 A rotation of the key-encryption key was asked for where it is not in a key management service (it is read into the process, or data keys are derived per run): its successor has to be configured with keys.previousKek* and the nodes restarted (#391). the console’s and the API’s refusal, 400
STS-KEYS-0105 The key management service refused to rotate the key-encryption key (commonly: the identity this service runs as may use the key but not rotate it). Nothing was re-wrapped (#391). —
STS-KEYS-0106 Counting the values sealed under each data encryption key failed; the counts shown are the previous ones (#391). —

STS-PKI

Certificate authority. The Root, Intermediate and Issuing CAs, certificate authoring, the CRL and OCSP responders, and the revocation check a presented certificate is held to.

Raised from: common/pki.js, common/pki_authoring.ts, common/pki_revocation.js, common/revocation_status.js, pki/, admin-ui/pki_admin.ts.

Code What failed Client sees
STS-PKI-0001 A certificate-authority use case prefers a key algorithm this service cannot use, so its Issuing CA was built with the branch’s algorithm instead. —
STS-PKI-0002 A build, issue, key generation or export named a key algorithm this service cannot generate. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0003 A build or issue named a signature algorithm this service cannot produce. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0004 The signing key cannot produce the signature algorithm asked for (the key and signature families disagree). Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0005 The Root CA could not be issued by the certificate encoder; nothing was stored. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0006 A scope’s Intermediate CA could not be issued by the certificate encoder; nothing was stored. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0007 One of a scope’s Issuing CAs could not be issued while building its branch; nothing was stored. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0008 The realm has no certificate authority (no hierarchy or branch), so nothing can be issued from, cleared or certified under it. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0009 The scope has no Issuing CA for the use case a certificate was asked for. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0010 A signing key pair was asked for without naming what it is issued to. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0011 A signing key pair was asked for with a purpose (profile) this service does not issue. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0012 A signing key pair was asked for with a subject kind (target) this service does not issue to. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0013 The certificate for an application or person signing key pair could not be issued by the encoder. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0014 A certificate path was checked in a realm that has no certificate authority, so there is no anchor. invalid_client or invalid_grant (HTTP 400/401), where an assertion x5c path is being checked
STS-PKI-0015 A presented certificate path could not be parsed. invalid_client or invalid_grant (HTTP 400/401), where an assertion x5c path is being checked
STS-PKI-0016 A link in a presented certificate path is not signed by the certificate above it. invalid_client or invalid_grant (HTTP 400/401), where an assertion x5c path is being checked
STS-PKI-0017 A certificate in a presented path names an issuer that is not the next certificate’s subject. invalid_client or invalid_grant (HTTP 400/401), where an assertion x5c path is being checked
STS-PKI-0018 A certificate in a presented path has expired. invalid_client or invalid_grant (HTTP 400/401), where an assertion x5c path is being checked
STS-PKI-0019 A certificate in a presented path is not valid yet. invalid_client or invalid_grant (HTTP 400/401), where an assertion x5c path is being checked
STS-PKI-0020 A presented certificate path is internally consistent and does not end at this service’s Root CA (a foreign anchor). invalid_client or invalid_grant (HTTP 400/401), where an assertion x5c path is being checked
STS-PKI-0021 A presented certificate path ends at this service’s Root and does not pass through this realm’s own Intermediate CA (issued in another realm). invalid_client or invalid_grant (HTTP 400/401), where an assertion x5c path is being checked
STS-PKI-0022 A certificate-authority operation named a use case that does not exist. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0023 A branch that no longer chains to the current Root could not be rebuilt before issuing, so nothing was certified. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0024 A leaf certificate under a use case’s Issuing CA could not be issued by the encoder. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0025 A certificate was to be forgotten from a slot that holds none. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0026 A certificate was to be issued under an Issuing CA with no subject public key given. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0027 The realm’s PKI object store is full (pki.maxStoredObjects), so a new object was refused rather than evicting one. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0028 An object-store removal or clear was asked for on a realm whose store is empty. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0029 An object named in the PKI object store does not exist. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0030 A realm’s signing key could not be read in order to certify it. —
STS-PKI-0031 Some of a realm’s signing keys could not be certified under its Intermediate; they still sign, self-signed. —
STS-PKI-0032 Some certificates under an Issuing CA could not be re-minted during a renewal or reissue. —
STS-PKI-0033 A replaced certificate could not be put on its issuer’s revocation list as superseded. —
STS-PKI-0034 A scope has no Intermediate CA (no branch), so an Issuing CA cannot be reissued or imported into it. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0035 A use case belongs to another scope kind (realm or process) than the one named. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0036 An Issuing CA could not be re-issued with a new key pair by the encoder. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0037 A CA import was missing the certificate or its private key. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0038 A certificate supplied for import or pinning could not be read. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0039 A private key supplied for import or pinning could not be read. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0040 A supplied private key does not belong to the supplied certificate. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0041 A certificate supplied as a CA is not a CA (basicConstraints cA:FALSE). Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0042 A key pair was pinned without naming the slot it is for. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0043 A key pair was pinned without a private key. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0044 A module registered key material for certification without a known use case, slot or publicKeyPem function; the registration was refused. —
STS-PKI-0045 A registered module’s public key could not be read to certify it at startup. —
STS-PKI-0046 A registered module’s key could not be certified at startup; it still works, self-signed. —
STS-PKI-0047 A registered key was certified and the module that owns it threw when told. —
STS-PKI-0048 At startup the service could not obtain a Root CA; every key is self-signed. —
STS-PKI-0049 At startup the process certificate-authority branch (TLS, SPIFFE) could not be built. —
STS-PKI-0050 At startup a realm’s certificate-authority branch could not be built. —
STS-PKI-0051 At startup the default realm’s signing keys could not be certified; they still sign, self-signed. —
STS-PKI-0052 At startup the certificate revocation lists could not be published into the directory; the LDAP distribution points do not answer. —
STS-PKI-0053 A realm created at runtime could not get a certificate-authority branch; its keys stay self-signed. —
STS-PKI-0054 Setting up the certificate authority for a realm created at runtime threw. —
STS-PKI-0055 A revocation, release or CRL named a certificate authority the scope does not hold. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0056 A revocation named no serial number. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0057 A revocation named a reason that is not an RFC 5280 section 5.3.1 reason. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0058 A hold was to be released on a serial that is not on the authority’s revocation list. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0059 A release was asked for on a certificate revoked for a permanent reason (only certificateHold can be released). Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0060 The directory hook for publishing CRLs was offered without both publishCrl() and baseDnFor(), and was refused whole. —
STS-PKI-0061 The directory could not say where a scope lives; the CRL DN falls back to one built from the realm’s domain. —
STS-PKI-0062 The Web Crypto engine pkijs needs could not be installed; CRLs and OCSP responses cannot be signed. —
STS-PKI-0063 A certificate revocation list could not be signed with its authority’s key. HTTP 500 text at /pki/crl; console refusal
STS-PKI-0064 A certificate revocation list could not be published into the directory (write-behind after a revocation, or at startup). —
STS-PKI-0065 An OCSP request was sent to an address with no certificate authority behind it. OCSP responseStatus unauthorized (6), HTTP 200
STS-PKI-0066 An OCSP request could not be parsed. OCSP responseStatus malformedRequest (1), HTTP 200
STS-PKI-0067 An OCSP response could not be signed with its authority’s key. OCSP responseStatus internalError (2), HTTP 200
STS-PKI-0068 A CRL was requested for a certificate authority this service does not hold. HTTP 404 text/plain
STS-PKI-0069 The CRL endpoint failed while building a CRL. HTTP 500 text/plain
STS-PKI-0070 An authority’s CA certificate (caIssuers) was requested for an authority this service does not hold. HTTP 404 text/plain
STS-PKI-0071 (retired) An OCSP GET request path segment was not a base64 DER request. Retired 2026-09-13: such a request does not conform to the OCSP syntax and is answered malformedRequest inside the protocol (STS-PKI-0066), as RFC 6960 section 2.3 asks. HTTP 400 text/plain
STS-PKI-0072 (retired) An OCSP request arrived with no body. Retired 2026-09-13, for STS-PKI-0071’s reason: it is answered malformedRequest (STS-PKI-0066). HTTP 400 text/plain
STS-PKI-0073 An OCSP POST body was larger than the 64KB this responder accepts. HTTP 413 text/plain
STS-PKI-0074 The OCSP endpoint threw while answering a request. HTTP 500 text/plain
STS-PKI-0075 A key pair could not be generated for the certificate authoring pane. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0076 A generated key pair could not be rendered as JWK and is shown as PEM instead. —
STS-PKI-0077 The certificate authoring pane named a certificate profile this service does not know. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0078 A subjectAltName or name-constraint general-name line on the authoring pane could not be read (no type, unknown type, or malformed othername). Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0079 An authority/subject information access line on the authoring pane has no method. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0080 A policy mapping line on the authoring pane is not =. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0081 A name constraint line on the authoring pane is not “permit " or "exclude ". Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0082 A custom extension line on the authoring pane is not ||. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0083 An extra subject attribute line on the authoring pane is not NAME=value or OID=value. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0084 A field on the authoring pane would not parse, for a reason no grammar code classifies. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0085 A certificate was to be issued from the authoring pane with no subject. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0086 “Reuse the key pair below” was ticked on the authoring pane and the two key boxes are not both filled in. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0087 The key pair pasted into the authoring pane could not be read as the chosen key algorithm. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0088 No issuing certificate authority was chosen or found for a certificate from the authoring pane. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0089 The issuer chosen on the authoring pane holds no private key in this service. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0090 A Not Before or Not After date on the authoring pane could not be read. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0091 Not After is not later than Not Before on the authoring pane. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0092 The certificate encoder could not issue the certificate the authoring pane described. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0093 A certificate was issued from the authoring pane and its certification request (CSR) could not be built. —
STS-PKI-0094 A certificate built on the authoring pane could not be stored, for a reason the store did not classify. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0095 The hybrid certificate’s alternative key pair is half filled in on the authoring pane. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0096 A stored object whose key pair was to be reused has no private key. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0097 The issuer chain above a stored PKI object loops back on itself; the walk stopped. —
STS-PKI-0098 A key pair export named a keystore format that does not exist. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0099 A key pair export found no key pair to export. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0100 The keystore export of a key pair failed (for example a password PKCS#12 needs, or a format the key cannot take). Console refusal page; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0101 A PKI console action or export was attempted by a session without Admin Write. HTTP 403 text/plain (export) or console refusal banner
STS-PKI-0102 A PKI console action threw an unexpected exception. Console refusal banner or page
STS-PKI-0103 The PKI console key-pair export threw an unexpected exception. Console refusal page
STS-PKI-0104 After the Root CA was replaced, a branch could not be rebuilt under it. —
STS-PKI-0105 A PKI console or API action was refused by the module behind it without a more specific code (a missing code at that module). Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0106 A person key-pair issue or removal named no person. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0107 A person key-pair action was asked of a process with no directory to hold it. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0108 (retired) An RFC 7522 (SAML) signing key pair was asked for a person; only applications may hold one. Retired 2026-09-13: a person may hold an RFC 7522 key pair, and the SAML bearer grant reads it. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0109 A person key-pair action named nobody in this realm. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0110 A person’s signing key pair was issued and could not be written onto their entry. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0111 A person key-pair removal found nothing to take off. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0112 A scoped PKI action named a realm’s branch that this realm’s console does not draw. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0113 An application key-pair issue or removal named no application. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0114 An application key-pair issue named an application that is not in this realm. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0115 An application’s signing key pair was issued and one of its attributes could not be written; the private key is lost. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0116 An application key-pair removal found nothing to take off for that profile. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0117 A PKI console or API action named an action that does not exist. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0118 A presented certificate chain was refused because a certificate in it is REVOKED — on this service’s own register, or on the verified CRL of a foreign issuer (common/revocation_status.js). Per door: no session at GET /tls/sign-in (HTTP 200 with signedIn false) and no recorded authentication for the sighting on the main port; invalid_client at the token endpoint (tls_client_auth, and an x5c assertion as invalid_client or invalid_grant); HTTP 403 access_denied at /xacml; the SCIM client-certificate scheme not accepted (401 if nothing else authenticates); gRPC UNAUTHENTICATED at the SPIRE Server API
STS-PKI-0119 A presented certificate chain was refused under pki.revocationCheck=hard-fail because its revocation status could not be established — a foreign CRL could not be fetched, did not verify, was stale, or no issuer certificate was available to verify one. The same refusals as STS-PKI-0118, per door
STS-PKI-0120 The CRL named by a presented certificate’s cRLDistributionPoints could not be fetched: a network failure, a timeout, a non-2xx status, a redirect or a body over pki.revocationMaxCrlBytes. —
STS-PKI-0121 A fetched CRL could not be used: it did not parse, named another issuer, failed its signature, carried an unsupported critical extension or was past its nextUpdate — or a presented chain could not be walked at all. —
STS-PKI-0122 The OCSP responder named by a presented certificate’s Authority Information Access could not be asked: a network failure, a timeout, a non-2xx status, a redirect, a body over pki.revocationMaxCrlBytes, or a responseStatus other than successful (common/revocation_status.js). —
STS-PKI-0123 An OCSP response could not be used: it did not parse, carried no answer for the certificate asked about, was signed by neither the issuer nor a delegated responder the issuer certified with id-kp-OCSPSigning, failed its signature, echoed a different nonce (or none, under pki.revocationOcspRequireNonce) or was not fresh. —
STS-PKI-0124 A delta CRL named by freshestCRL could not be applied: it did not parse or verify, carried no deltaCRLIndicator, named a different issuer or scope from its base, or its BaseCRLNumber and cRLNumber do not fit the base CRL it would be merged into. —
STS-PKI-0125 An indirect CRL could not be trusted: the cRLIssuer a certificate names has no certificate in the presented chain, among this service’s authorities or in pki.revocationCrlIssuersFile that may sign CRLs and chains to the presented path — or the list at that point was not signed by it or does not declare itself indirect. —
STS-PKI-0126 The certificate of a CRL’s signer could not be fetched from the caIssuers address in the CRL’s own Authority Information Access (RFC 5280 section 5.2.7), or none fetched there may sign that list: a fetch failure, a document that is not a certificate, or a certificate without cRLSign that does not chain to the presented path. —
STS-PKI-0127 A delegated OCSP responder’s answers were not used because its own certificate is REVOKED on the CRL it names, or because its status could not be established under pki.revocationCheck=hard-fail (RFC 6960 section 4.2.2.2.1). —
STS-PKI-0128 An ldap: or ldaps: revocation address was not dialled or not answered usably: plain ldap is not permitted by pki.revocationLdap, the URL names no host or a critical extension, a name relative to the CRL issuer has no pki.revocationLdapDirectory to be looked up in, or the directory answered with a referral, several entries or no such attribute. —
STS-PKI-0129 A certificate REGISTERED on an application entry (an RFC 7523 key’s x5c, an RFC 7522 certificate), on a federation relationship (fedSigningCertificate, or a key in its JWKS) or in oid4vp.trustedIssuerCertificates verified a signature and was then refused because it is revoked, or its status could not be established under pki.revocationCheck=hard-fail. Per door: invalid_client or invalid_grant at the token endpoint; the federated sign-in refused with the reason on the error page; invalid_request at the OID4VP response endpoint
STS-PKI-0130 The OCSP responder address of a certificate authority this service holds was fetched with a GET carrying no request — the URL exactly as it is written in a certificate’s Authority Information Access, which RFC 6960 appendix A.1.1 makes the base of both transports rather than a document. HTTP 400 text/plain naming the POST and GET transports
STS-PKI-0131 The OCSP responder address of a certificate authority this service does not hold was fetched with a GET carrying no request. HTTP 404 text/plain
STS-PKI-0132 An OCSP request carried a nonce of 0 octets or more than 32, which RFC 8954 section 2.1 requires a responder to reject. OCSPResponse malformedRequest(1), HTTP 200
STS-PKI-0133 An OCSP request named no certificate the responder’s authority issued — every CertID’s issuer name and key hashes belong to somebody else — so the responder is not authoritative for any of it (RFC 6960 section 2.3, RFC 5019 section 2.2.3). OCSPResponse unauthorized(6), HTTP 200
STS-PKI-0134 A request reached the plain-HTTP revocation listener for a path outside /pki/ and /enroll/scep. That socket serves the revocation endpoints, SCEP and /healthcheck, and nothing else. HTTP 404 text/plain
STS-PKI-0140 A certificate upload named no application, or the registration it produced could not be written. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0141 A certificate upload carried a PRIVATE KEY block. Nothing was stored; the application keeps its own key. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0142 A certificate upload carried no PEM certificate, or a PEM block that is not a certificate. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0143 A certificate in an upload, or the chain it forms, could not be parsed. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0144 The first certificate of an upload is a certificate authority rather than the signing leaf. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0145 An uploaded certificate is expired or not yet valid. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0146 An uploaded certificate carries a key the profile’s verifier cannot use, or a KeyUsage that forbids digitalSignature. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0147 An uploaded certificate’s chain is incomplete: it does not reach a self-signed root, or the certificate is itself self-signed. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0148 A certificate upload carried a certificate that is not on the path from the leaf to its root. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0149 An uploaded certificate chains to this service’s own Root and was refused by the realm path check (another realm’s branch, a failed link, or revocation). Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0150 An external chain uploaded with a certificate does not verify: a signature, an issuer name or a validity window failed. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0151 An issuer in an uploaded external chain is not a CA, may not sign certificates, or has its path length constraint exceeded. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0152 An uploaded certificate’s chain verifies and the certificate was refused on revocation. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0153 (retired) A certificate upload targeted a person. Only an application’s key pair is replaced by an uploaded certificate. Retired 2026-09-13: a person’s key pair may be replaced by an uploaded certificate too. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0154 An uploaded certificate verified and one of the attributes it replaces could not be written to the application entry. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0155 An uploaded certificate this realm issued would widen its holder: for a person, its subjectAltName names somebody else (another urn:sts:person: or an urn:sts:application:); for an application, it names a urn:sts:person:. Console refusal banner; /admin-api HTTP 400 with {ok:false, errors}
STS-PKI-0156 The certificate behind a key that verified an RFC 7523 or RFC 7522 assertion has an INCOMPLETE chain: it is not this realm’s, and nothing registered with it reaches a self-signed root (pki.verifySignerChain). invalid_grant at the grant, invalid_client at client authentication
STS-PKI-0157 The chain of the certificate behind a key that verified an RFC 7523 or RFC 7522 assertion does not verify: a signature, an issuer name or a validity window failed — the leaf expired, an intermediate expired, or a pinned self-signed certificate no longer holds. invalid_grant at the grant, invalid_client at client authentication
STS-PKI-0158 A certificate that signs another on a signer’s path is not permitted to: no basicConstraints cA=TRUE, a KeyUsage without keyCertSign, or a pathLenConstraint exceeded. Raised for a presented x5c (pki.verifyLeaf) and for a registered chain at use. invalid_grant at the grant, invalid_client at client authentication
STS-PKI-0159 The certificate whose key verified an assertion may not sign one: it is a certificate authority, or its KeyUsage does not permit digitalSignature. invalid_grant at the grant, invalid_client at client authentication
STS-PKI-0160 A registered JWK’s x5c certificate does not hold the key the JWK represents (RFC 7517 section 4.7), so its chain says nothing about the key that verified the assertion. invalid_grant at the grant, invalid_client at client authentication
STS-PKI-0161 A certificate behind a key that verified an assertion, or one in its registered chain, could not be read. invalid_grant at the grant, invalid_client at client authentication
STS-PKI-0162 The certificate chain an x5u header names was requested for a SHA-256 that is not a JOSE signing certificate in that scope — a mistyped address, or a certificate replaced since the token was signed. HTTP 404 text/plain
STS-PKI-0163 The certificate the register holds for a signing key’s slot is over a different key, so tokens signed with that key carry no x5c or x5u until it is certified again. Logged once per certificate. none — the token is issued without the header
STS-PKI-0164 The x5c or x5u header for a signed token could not be built; the token was signed without it. none — the token is issued without the header
STS-PKI-0165 A TLS listener certificate was asked for without naming what it is for (no slot). the caller’s refusal: console page or /admin-api HTTP 400 { ok: false, errors }
STS-PKI-0166 A TLS listener certificate was refused its subjectAltName: a name that is not a DNS name or IP address, or no name at all. the caller’s refusal: console page or /admin-api HTTP 400 { ok: false, errors }
STS-PKI-0167 A TLS listener certificate was asked for with a key algorithm a TLS stack does not serve (only RSA and NIST-curve ECDSA are issued). the caller’s refusal: console page or /admin-api HTTP 400 { ok: false, errors }
STS-PKI-0168 A TLS client certificate was asked for with no holder named. the caller’s refusal: /portal/signing-key HTTP 400 page
STS-PKI-0169 A TLS client certificate was asked for with a key algorithm a browser does not present (RSA 2048/3072, ECDSA P-256/P-384 only), or with a name that is not a short label. the caller’s refusal: /portal/signing-key HTTP 400 page
STS-PKI-0170 A person already holds pki.personTlsClientCertificateMax valid TLS client certificates, so another was not issued. the caller’s refusal: /portal/signing-key HTTP 400 page
STS-PKI-0171 A TLS client certificate revocation named a serial the signed-in person holds no certificate under. the caller’s refusal: /portal/signing-key HTTP 400 page
STS-PKI-0180 An application already holds pki.applicationTlsClientCertificateMax valid TLS client certificates, so another was not issued. the caller’s refusal (errors on a console or /admin-api reply)
STS-PKI-0181 A TLS client certificate revocation named a serial the application holds no certificate under. the caller’s refusal (errors on a console or /admin-api reply)
STS-PKI-0182 A certificate authority tier was built on this node and on another at the same moment; the other committed first and was kept. the caller’s refusal (errors on a console or /admin-api reply) for a deliberate build; none for a startup build, which adopts it
STS-PKI-0183 A certificate authority was not built because the store could not be asked whether another node is building it. the caller’s refusal (errors on a console or /admin-api reply)
STS-PKI-0184 Another node held the build of a certificate authority for longer than this node waits, and nothing appeared in the store. the caller’s refusal (errors on a console or /admin-api reply)
STS-PKI-0185 A CRL was not signed because its CRL number could not be advanced in the store shared by this service’s nodes. HTTP 500 from the CRL distribution point
STS-PKI-0186 A certificate was not recorded because the Issuing CA that signed it was replaced, repeatedly, while it was being signed. the caller’s refusal (errors on a console or /admin-api reply)
STS-PKI-0187 The public crypto metadata document (/crypto/metadata) could not be built. HTTP 500 server_error from /crypto/metadata
STS-PKI-0188 A presented certificate chain was refused under pki.revocationCheck=hard-fail because a certificate in it names revocation addresses this service is configured NOT TO DIAL and no other it could use — a plain ldap: CRL under pki.revocationLdap=ldaps, any ldap with it off, a name relative to the CRL issuer without pki.revocationLdapDirectory, a scheme that is never dialled, or an OCSP responder that is not http(s) — so its status could not be established. Distinct from STS-PKI-0119 so that a policy refusal is not read as an unreachable server; also logged, once per address per process, naming the setting that would dial it. The same refusals as STS-PKI-0118, per door
STS-PKI-0189 A presented certificate carries RFC 9608 noRevAvail beside something section 3 forbids with it — cA TRUE, cRLDistributionPoints, freshestCRL, or an OCSP responder in its Authority Information Access — and is refused as INVALID under every policy but off. The same refusals as STS-PKI-0118, per door
STS-PKI-0190 A presented certificate chain was refused under pki.revocationCheck=hard-fail because a certificate in it, issued by an authority this service does not hold, names no CRL distribution point and no OCSP responder, carries no RFC 9608 noRevAvail, and pki.revocationRequireDistributionPoint (auto, in product mode, or on) refuses a certificate nobody can revoke. The same refusals as STS-PKI-0118, per door
STS-PKI-0191 A certificate authority build, or a key pair issued under one, named a SHA-1 signature algorithm (sha1-rsa or sha1-ecdsa) in a realm that is in product mode, where SHA-1 is never used (#181). console: the page’s error list; /admin-api: HTTP 400 { ok: false, errors }
STS-PKI-0192 An encryption key pair was asked for in a key type this service does not issue one of (rsa-3072 and ec-p256, #168). the caller’s refusal
STS-PKI-0193 A certificate a merged certificate authority published from an Issuing CA it no longer holds could not be certified again from the live one. none — logged. The key still signs; its certificate chains to an authority nothing publishes until the slot is certified again
STS-PKI-0194 A certificate path a signer’s key or an upload depends on breaks a NAME CONSTRAINT: a name of a certificate below a CA is outside what that CA permits or inside what it excludes, is malformed where it is constrained, is in a form constrained in a way this service does not evaluate, or the names and constraints are too many to compare (RFC 5280 section 4.2.1.10; pki.pathRuleProblem, #201). invalid_grant at the grant, invalid_client at client authentication; the console’s error list for an upload
STS-PKI-0195 A certificate on a signer’s or an uploaded path carries a CRITICAL extension this service does not implement, which RFC 5280 section 4.2 says must be refused (pki.pathRuleProblem, #201). invalid_grant at the grant, invalid_client at client authentication; the console’s error list for an upload
STS-PKI-0196 A certificate on a signer’s or an uploaded path breaks a rule of RFC 5280 section 4 a relying party holds it to: an extension twice, an unreadable basicConstraints, keyUsage, extKeyUsage, subjectAltName or nameConstraints, an empty subject without a critical subjectAltName, a CA with an empty subject, keyCertSign or nameConstraints on a certificate that is not a CA, or an ML-DSA key with a keyUsage RFC 9881 does not permit (pki.pathRuleProblem, #201). invalid_grant at the grant, invalid_client at client authentication; the console’s error list for an upload
STS-PKI-0197 A certificate on a path below its anchor is signed with a broken hash — MD2 or MD5 on every path, SHA-1 on every path but this service’s own hierarchy in a development realm (#181) — and the path is refused (pki.pathRuleProblem, #201). invalid_grant at the grant, invalid_client at client authentication; the console’s error list for an upload
STS-PKI-0198 A certificate chain OpenSSL verified in a TLS handshake breaks the path rules every other path here is held to (pki.peerChainProblem, #201): on the main port the client certificate is treated as unverified (authorized false); on an outbound request the request fails as a TLS error. Also logged when the rules could not be asked. none on the wire: an unverified client certificate, or the family’s own failure for an outbound request
STS-PKI-0199 RFC 5280 section 6.1’s certificate policy processing refuses a path: a certificate on it requires an explicit policy (policyConstraints) and no acceptable policy remains in the valid_policy_tree, a policyMappings maps anyPolicy, or the policies and mappings make a tree too large to evaluate (pki.pathPolicyOutcome, #201). invalid_grant at the grant, invalid_client at client authentication; the console’s error list for an upload
STS-PKI-0200 A certificate authority build named an alternative key algorithm (pki.alternativeKeyAlgorithm, or altKeyAlg on the form) that is not a pure post-quantum signature algorithm this service generates, nor “none” (#68). console: the page’s error list; /admin-api: HTTP 400 { ok: false, errors }
STS-PKI-0201 A certificate carries an ITU-T X.509 clause 9.8 alternative signature that does not verify under its issuer’s alternative key (any path: this realm’s own, an uploaded chain, a registered root), or — on a path to this realm’s own hierarchy — cannot be checked (#68). the verifier’s refusal: whatever the certificate was presented for is refused as an untrusted certificate
STS-PKI-0202 A certificate on a path to this realm’s own hierarchy carries no alternative signature although its issuer holds an alternative (post-quantum) key — a hybrid path presented as classical, the downgrade #68 refuses. the verifier’s refusal: whatever the certificate was presented for is refused as an untrusted certificate
STS-PKI-0203 A Certificate & Key Configuration pane field that takes a closed set (pki_profile, pki_pq_mode, pki_key_alg, pki_alt_key_alg, pki_ks_format) held a value outside it (#86). HTTP 400 page or { ok: false, errors }
STS-PKI-0204 The OpenID4VP Verifier’s certificate was refused its name or its key: a DNS name a certificate cannot carry, a wildcard (the certificate names one host), or no signing key (#230). the Verifier’s refusal: STS-VC-0112, HTTP 500 at /oid4vp/start
STS-PKI-0205 A realm already holds the most OpenID4VP Verifier certificates it keeps (one per DNS name, sixteen), so none was issued for another name — set oid4vp.x509DnsName or pin global.publicBaseUrl (#230). the Verifier’s refusal: STS-VC-0112, HTTP 500 at /oid4vp/start
STS-PKI-0206 A key pair was not pinned in a slot that certifies a key the realm signs with: a pinned key does not sign, and the pin would have replaced that key’s published certificate (#245). console / /admin-api refusal (HTTP 400)
STS-PKI-0207 A key pair was not pinned as a signer: its key type does not match the slot’s algorithm (an RSA key under 2048 bits, a curve other than the slot’s, a post-quantum key of another parameter set) (#263). console / /admin-api refusal (HTTP 400)
STS-PKI-0208 A key pair was not pinned as a signer: the slot is not one a pinned key can sign from — a signer-group slot, a composite post-quantum algorithm, or an xml slot other than RS256 (#263). console / /admin-api refusal (HTTP 400)
STS-PKI-0209 A key pair was not pinned as a signer: the certificate chain supplied with it could not be read, or its first certificate did not issue the key’s certificate (#263). console / /admin-api refusal (HTTP 400)
STS-PKI-0210 A key pair was not pinned as a signer: the certificate supplied with it is expired or not yet valid, so relying parties would refuse everything it signed (#263). console / /admin-api refusal (HTTP 400)
STS-PKI-0211 An unpin named a slot that holds no pinned key pair (#263). console / /admin-api refusal (HTTP 400)
STS-PKI-0212 A pinned signing key’s certificate expires within pki.pinnedSignerExpiryWarningDays; its lifecycle is the operator’s (#263). log only (a warning, once a day)
STS-PKI-0213 A pinned signing key’s certificate has expired and the key still signs: relying parties that check the x5c or the metadata certificate refuse what it signs until it is unpinned (#263). log only (an error, once a day)
STS-PKI-0214 A pinned signing key could not be read when a signature needed it, so the realm’s generated key signed instead (#263). log only
STS-PKI-0215 A write or reset of pki.pinnedSigners was refused: it would turn the setting off in a realm holding a live or pending pinned signing key, which would change the signer with no signing-key-rotated. Unpin first (#263). console / /admin-api refusal (HTTP 400)
STS-PKI-0216 At start, a realm holds pinned signing keys but pki.pinnedSigners is off there (environment, appconfig or a stored override), so it signs with its generated keys (#263). log only (a warning, at start)
STS-PKI-0217 A key pair was not pinned into the xml slot: the certificate supplied with it has a keyUsage without keyEncipherment, and an xml pin is also the key partners encrypt to (#263). console / /admin-api refusal (HTTP 400)
STS-PKI-0218 A certificate authority branch finished building for a realm that had been removed while it was built, and was discarded rather than saved. none (logged; the realm is gone)

STS-ENROLL

Certificate enrollment core. Who may be issued a certificate for which directory entry, what a certificate issued over ACME, EST or SCEP contains, the PKCS#10 proof of possession, the enrolled certificates and credentials kept on a person or application entry, and their revocation.

Raised from: common/cert_enrollment.ts, common/enrollment_monitor.ts.

Code What failed Client sees
STS-ENROLL-0001 A certificate request named a profile that is not one of the nine issued over an enrollment protocol. the protocol’s refusal: ACME malformed / badCSR, EST HTTP 400, SCEP failInfo badRequest
STS-ENROLL-0002 A certificate request named a CA, OCSP Responder or Kerberos KDC profile, which is never issued over an enrollment protocol. the protocol’s refusal: ACME unauthorized, EST HTTP 403, SCEP failInfo badRequest
STS-ENROLL-0003 A certificate request named a profile that is not in the family’s allowedProfiles setting in this realm. the protocol’s refusal: ACME unauthorized, EST HTTP 403, SCEP failInfo badRequest
STS-ENROLL-0004 A certificate was asked of the enrollment core for a family that is not ACME, EST or SCEP. HTTP 500 (a defect in the caller)
STS-ENROLL-0010 A person or application was named by a malformed identifier. the protocol’s refusal (HTTP 400)
STS-ENROLL-0011 No directory is loaded in this process, so there is no entry a certificate could be issued for or kept on. HTTP 503
STS-ENROLL-0012 The person or application a certificate was asked for has no entry in this realm. the protocol’s refusal (HTTP 404 / ACME unauthorized / SCEP badRequest)
STS-ENROLL-0013 An enrollment authentication named no username or client_id. HTTP 401
STS-ENROLL-0014 An enrollment password was not accepted for a person who has an entry in this realm. HTTP 401
STS-ENROLL-0015 An enrollment password was offered for a name with no entry in this realm and no administrator standing. HTTP 401
STS-ENROLL-0016 Enrollment client credentials were not accepted: an unknown client_id, or (in product mode) a missing or wrong client secret. HTTP 401
STS-ENROLL-0017 Enrollment certificate authentication was attempted with no TLS client certificate on the connection. HTTP 401
STS-ENROLL-0018 An enrollment client certificate did not verify to this realm’s certificate authority (another realm, another authority, expired or revoked). HTTP 401
STS-ENROLL-0019 An enrollment client certificate verified but does not certify clientAuth, names no single entry, or is not an unrevoked certificate that entry holds. HTTP 401
STS-ENROLL-0020 An enrollment authorization was asked about with no authenticated principal or no target entry. HTTP 403
STS-ENROLL-0021 A certificate was asked for an entry other than the one that authenticated, by a principal that does not hold Admin Write. the protocol’s refusal: ACME unauthorized, EST HTTP 403, SCEP badRequest
STS-ENROLL-0022 A certificate request named more than one person or application in its subjectAltName. HTTP 400
STS-ENROLL-0023 An administrator with no entry of their own in this realm sent a request that named no entry. HTTP 400
STS-ENROLL-0030 A certificate request was empty or is not a readable PKCS#10 CertificationRequest. ACME badCSR, EST HTTP 400, SCEP badRequest
STS-ENROLL-0031 A certificate request carries a public key this certificate authority cannot certify. ACME badCSR / badPublicKey, EST HTTP 400
STS-ENROLL-0032 A certificate request carries a key-encapsulation key, which cannot prove possession by signing. ACME badCSR, EST HTTP 400
STS-ENROLL-0033 A certificate request’s signature does not verify with the key it carries (no proof of possession). ACME badCSR, EST HTTP 400, SCEP badMessageCheck
STS-ENROLL-0034 A certificate request’s subject or requested extensions could not be read. ACME badCSR, EST HTTP 400
STS-ENROLL-0035 A server-generated key pair was asked for an unknown key algorithm, or could not be generated. HTTP 400
STS-ENROLL-0040 A certificate was refused because the entry already holds pki.enrollmentMaxCertificatesPerEntry unexpired enrolled certificates. HTTP 409 / ACME rejectedIdentifier
STS-ENROLL-0041 An enrolled certificate, private key or credential could not be written onto its directory entry. HTTP 503
STS-ENROLL-0042 The family’s Issuing CA could not issue an enrolled certificate. HTTP 503 / ACME serverInternal
STS-ENROLL-0043 A server-generated private key or an EAB key could not be sealed for storage. HTTP 503
STS-ENROLL-0044 An entry already holds the most unused EAB keys or SCEP challenges it may. HTTP 409 on the console or /admin-api
STS-ENROLL-0050 A certificate request asked for a URI (or another name form) the entry does not own. ACME rejectedIdentifier, EST HTTP 403, SCEP badRequest
STS-ENROLL-0051 A certificate request asked for a DNS name or IP address not registered on the entry. ACME rejectedIdentifier, EST HTTP 403, SCEP badRequest
STS-ENROLL-0052 A certificate request asked for an email address that is not the entry’s mail attribute. ACME rejectedIdentifier, EST HTTP 403, SCEP badRequest
STS-ENROLL-0053 A certificate request asked for a user principal name that is neither the entry’s userPrincipalName nor its mail. ACME rejectedIdentifier, EST HTTP 403, SCEP badRequest
STS-ENROLL-0054 A TLS server certificate was asked for with no host name in the request. ACME malformed, EST HTTP 400, SCEP badRequest
STS-ENROLL-0055 An S/MIME certificate was asked for an entry with no mail attribute. HTTP 400
STS-ENROLL-0056 A smartcard logon certificate was asked for an entry with neither userPrincipalName nor mail. HTTP 400
STS-ENROLL-0057 An administrator tried to register something that is not a DNS name or an IP address as a certificate host name. HTTP 400 on the console or /admin-api
STS-ENROLL-0058 An administrator tried to remove a certificate host name the entry does not have. HTTP 404 on the console or /admin-api
STS-ENROLL-0060 An ACME or EST request arrived over plain HTTP in product mode. HTTP 403 (ACME: an RFC 7807 unauthorized problem)
STS-ENROLL-0061 A client was throttled after too many refused enrollment requests in one web-security window. HTTP 429 with Retry-After (ACME rateLimited)
STS-ENROLL-0070 A revocation named a serial no enrollment protocol issued in this realm. HTTP 404 (ACME malformed)
STS-ENROLL-0071 A revocation named a certificate that does not belong to the entry asking. HTTP 403 (ACME unauthorized)
STS-ENROLL-0072 The certificate authority refused an enrolled certificate’s revocation. HTTP 400
STS-ENROLL-0080 An External Account Binding key id is not known in this realm. ACME unauthorized / externalAccountRequired
STS-ENROLL-0081 An External Account Binding key that already bound one account was presented for another. ACME unauthorized
STS-ENROLL-0082 An External Account Binding key was presented after it expired. ACME unauthorized
STS-ENROLL-0083 A SCEP challenge password was not accepted (unknown id or wrong secret). SCEP CertRep FAILURE badRequest
STS-ENROLL-0084 A SCEP challenge password that had already been redeemed was presented again. SCEP CertRep FAILURE badRequest
STS-ENROLL-0085 A SCEP challenge password was presented after it expired. SCEP CertRep FAILURE badRequest
STS-ENROLL-0090 An enrollment monitor counter could not be recorded (the request it counted is unaffected). none (log only)
STS-ENROLL-0091 An ACME External Account Binding key or a SCEP challenge password could not be proved unspent because the cluster store could not be asked, so it was refused. ACME unauthorized / SCEP CertRep FAILURE badRequest
STS-ENROLL-0092 A renewal named a certificate that is not recorded as issued to the entry in this realm, so it could not be superseded and nothing was issued. EST 400 / SCEP CertRep FAILURE badRequest
STS-ENROLL-0093 A renewal was issued but the certificate it renews could not be revoked as superseded, so the renewal was revoked and the request refused. EST 503 / SCEP CertRep FAILURE badRequest
STS-ENROLL-0094 In product mode a certificate was refused to an application declared for some protocol families but not this enrollment protocol (ACME, EST or SCEP); the issuance policy’s protocol-not-declared rule decided it. each protocol’s own refusal (an RFC 8555 problem document, an RFC 7030 HTTP 403, an RFC 8894 failInfo)
STS-ENROLL-0095 The profile is not in the application’s own AllowedProfiles, which replaces the realm's list for it. each protocol’s own refusal (ACME invalidProfile, an RFC 7030 HTTP 403, an RFC 8894 failInfo)
STS-ENROLL-0096 EST refused an application an authentication method or /serverkeygen that its own estBasicAuthentication, estCertificateAuthentication or estServerKeyGeneration turns off. RFC 7030 HTTP 403

STS-ACME

ACME (RFC 8555). The ACME server: the directory, nonces, JWS request authentication, accounts bound by External Account Binding, orders, pre-validated authorizations, finalize, certificate download, revocation, key change, renewal information, and its console pages.

Raised from: acme/.

Code What failed Client sees
STS-ACME-0001 ACME is turned off in this realm (acme.enabled is false). HTTP 503, ACME serverInternal problem
STS-ACME-0002 An ACME request was refused by the transport rule and the core gave no code of its own (fallback for STS-ENROLL-0060). HTTP 403, ACME unauthorized problem
STS-ACME-0003 An ACME request was throttled and the core gave no code of its own (fallback for STS-ENROLL-0061). HTTP 429 with Retry-After, ACME rateLimited problem
STS-ACME-0010 An ACME POST did not carry Content-Type application/jose+json (RFC 8555 section 6.2). HTTP 415, ACME malformed problem
STS-ACME-0011 An ACME request body was larger than acme.maxRequestBytes. HTTP 413, ACME malformed problem
STS-ACME-0012 An ACME request body (or an external account binding) is not a flattened JWS JSON object with exactly protected, payload and signature. HTTP 400, ACME malformed problem
STS-ACME-0013 A member of an ACME flattened JWS is not strict base64url. HTTP 400, ACME malformed problem
STS-ACME-0014 An ACME JWS protected header is unreadable, fails its schema, or carries crit, b64, jku, x5u or x5c. HTTP 400, ACME malformed problem
STS-ACME-0015 An ACME JWS is signed with an algorithm this server does not accept for an account key. HTTP 400, ACME badSignatureAlgorithm problem with algorithms
STS-ACME-0016 An ACME request carried no Replay-Nonce, or one this server did not issue in this realm. HTTP 400, ACME badNonce problem with a fresh Replay-Nonce
STS-ACME-0017 An ACME request carried an expired Replay-Nonce. HTTP 400, ACME badNonce problem with a fresh Replay-Nonce
STS-ACME-0018 An ACME request carried a Replay-Nonce that had already been used. HTTP 400, ACME badNonce problem with a fresh Replay-Nonce
STS-ACME-0019 An ACME JWS protected header url is not the URL the request was sent to (RFC 8555 section 6.4). HTTP 403, ACME unauthorized problem
STS-ACME-0020 An ACME JWS carried both jwk and kid, neither, or the one the resource does not take. HTTP 400, ACME malformed problem
STS-ACME-0021 An ACME account key (jwk) is malformed, carries a private member, does not fit alg, is an RSA key under 2048 bits, or does not load. HTTP 400, ACME badPublicKey or malformed problem
STS-ACME-0022 An ACME kid is not the URL of an account on this server in this realm. HTTP 400, ACME accountDoesNotExist problem
STS-ACME-0023 An ACME request was signed by a deactivated account. HTTP 403, ACME unauthorized problem
STS-ACME-0024 An ACME JWS signature does not verify with the account key. HTTP 400, ACME malformed problem
STS-ACME-0025 An ACME JWS payload is unreadable, missing where one is required, present where POST-as-GET is required, or fails the resource schema. HTTP 400, ACME malformed problem
STS-ACME-0026 An ACME resource was requested with a method it does not answer (a GET on a POST-as-GET resource, a POST on the directory or renewal information). HTTP 405 with Allow, ACME malformed problem
STS-ACME-0027 An ACME resource (account, order, authorization, certificate) belongs to a different account from the one that signed the request. HTTP 403, ACME unauthorized problem
STS-ACME-0028 An ACME order, authorization or certificate id names nothing in this realm. HTTP 404, ACME malformed problem
STS-ACME-0030 An ACME newAccount with onlyReturnExisting found no account for the key. HTTP 400, ACME accountDoesNotExist problem
STS-ACME-0031 An ACME newAccount carried no externalAccountBinding, which this server requires. HTTP 403, ACME externalAccountRequired problem
STS-ACME-0032 An ACME externalAccountBinding is malformed: its header is not exactly alg, kid and url, its alg is not a MAC, its url is not the newAccount URL, or its payload is not the account key. HTTP 400, ACME malformed or badSignatureAlgorithm problem
STS-ACME-0033 An ACME externalAccountBinding names a key id that is not known in this realm. HTTP 403, ACME unauthorized problem
STS-ACME-0034 An ACME externalAccountBinding MAC does not verify with the key issued under its key id. HTTP 403, ACME unauthorized problem
STS-ACME-0035 An ACME externalAccountBinding key has expired before binding an account. HTTP 403, ACME unauthorized problem
STS-ACME-0036 An ACME externalAccountBinding key could not bind the account and the core gave no code of its own. HTTP 403, ACME unauthorized problem
STS-ACME-0037 An ACME account contact is not a single mailto: address. HTTP 400, ACME invalidContact or unsupportedContact problem
STS-ACME-0038 An ACME account update asked for a status other than deactivated. HTTP 400, ACME malformed problem
STS-ACME-0040 An ACME newOrder named an identifier type this server does not issue for. HTTP 400, ACME unsupportedIdentifier problem with subproblems
STS-ACME-0041 An ACME newOrder identifier value is not well formed for its type. HTTP 400, ACME malformed problem
STS-ACME-0042 An ACME newOrder named an identifier the account’s bound entry does not own (an unregistered host name, somebody else’s mail, another entry). HTTP 400, ACME rejectedIdentifier problem with subproblems
STS-ACME-0043 An ACME newOrder carried notBefore or notAfter, which this server does not accept. HTTP 400, ACME malformed problem
STS-ACME-0044 An ACME newOrder named a profile that is unknown, never issued over an enrollment protocol, or not in acme.allowedProfiles. HTTP 400, ACME invalidProfile problem
STS-ACME-0045 An ACME newOrder profile needs an identifier or attribute the order or entry lacks (a server profile with no host, email with no email identifier, smartcard logon with no UPN). HTTP 400, ACME malformed problem
STS-ACME-0046 An ACME newOrder named one identifier twice. HTTP 400, ACME malformed problem
STS-ACME-0047 An ACME newOrder replaces member names no certificate this account’s entry was issued over ACME in this realm (RFC 9773 section 5). HTTP 400, ACME malformed problem
STS-ACME-0048 The directory entry an ACME account or EAB key is bound to no longer exists in this realm. HTTP 403, ACME unauthorized problem
STS-ACME-0049 An ACME newOrder replaces a certificate that another order already replaced (RFC 9773 section 5). HTTP 409, ACME alreadyReplaced problem
STS-ACME-0050 An ACME finalize was sent for an order that is not ready (already valid, processing or invalid). HTTP 403, ACME orderNotReady problem
STS-ACME-0051 An ACME finalize csr is not strict base64url. HTTP 400, ACME badCSR problem
STS-ACME-0052 An ACME finalize CSR could not be read and the core gave no code of its own. HTTP 400, ACME badCSR problem
STS-ACME-0053 An ACME finalize CSR does not name exactly the order’s identifiers (RFC 8555 section 7.4). HTTP 400, ACME badCSR problem
STS-ACME-0054 An ACME finalize issuance failed and the core gave no code of its own. HTTP 500, ACME serverInternal problem
STS-ACME-0055 An ACME authorization update was not {“status”: “deactivated”}. HTTP 400, ACME malformed problem
STS-ACME-0056 An ACME challenge response was not the empty object. HTTP 400, ACME malformed problem
STS-ACME-0060 An ACME revokeCert certificate is not base64url DER of one certificate. HTTP 400, ACME malformed problem
STS-ACME-0061 An ACME revokeCert certificate was not issued over ACME in this realm. HTTP 404, ACME malformed problem
STS-ACME-0062 An ACME revokeCert reason is not one this server accepts from a subscriber (0, 1, 3, 4, 5 or 9). HTTP 400, ACME badRevocationReason problem
STS-ACME-0063 An ACME revokeCert was signed neither by an account bound to the certificate’s entry nor by the certificate’s own key. HTTP 403, ACME unauthorized problem
STS-ACME-0064 An ACME revokeCert named a certificate that is already revoked. HTTP 400, ACME alreadyRevoked problem
STS-ACME-0065 Revoking a certificate issued over ACME failed and the core gave no code of its own. HTTP 500, ACME serverInternal problem; console error notice
STS-ACME-0070 An ACME keyChange inner JWS is malformed, unverifiable or carries an unreadable payload. HTTP 400, ACME malformed problem
STS-ACME-0071 An ACME keyChange inner JWS breaks section 7.3.5: no jwk, a kid or nonce, a different url, or an account that is not the signer. HTTP 400, ACME malformed problem
STS-ACME-0072 An ACME keyChange oldKey is not the account’s current key. HTTP 400, ACME malformed problem
STS-ACME-0073 An ACME keyChange new key is already the key of another account. HTTP 409 with Location, ACME malformed problem
STS-ACME-0074 An ACME keyChange new key is the account’s current key. HTTP 400, ACME malformed problem
STS-ACME-0080 An ACME renewalInfo certificate identifier is malformed (RFC 9773 section 4.1). HTTP 400, ACME malformed problem
STS-ACME-0081 An ACME renewalInfo certificate identifier names no certificate issued over ACME in this realm. HTTP 404, ACME malformed problem
STS-ACME-0082 The query string of an ACME orders list failed validation. HTTP 400, ACME malformed problem
STS-ACME-0090 An ACME console or management API action is not one of the six. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-ACME-0091 An ACME console or management API action body failed validation. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-ACME-0092 An ACME console or management API deactivate-account named no account in this realm. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-ACME-0093 An ACME console or management API revoke-certificate named no certificate issued over ACME in this realm. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-ACME-0094 An ACME console or management API EAB or host name action was refused by the core with no code of its own. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-ACME-0095 An ACME endpoint, console action or management API action threw unexpectedly. HTTP 500, ACME serverInternal problem; console error notice
STS-ACME-0096 An ACME console or management API revoke-certificate named a certificate that is already revoked. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-ACME-0097 The query string of an ACME console page failed validation. HTTP 400 text/plain
STS-ACME-0098 An ACME finalize was refused because the order is already being finalized by another request, on this node or another. HTTP 403, ACME orderNotReady problem
STS-ACME-0099 An ACME Replay-Nonce or an order’s finalize could not be claimed because the cluster store could not be asked, so the request was refused. HTTP 500, ACME serverInternal problem

STS-EST

EST (RFC 7030). Enrollment over Secure Transport: cacerts, simpleenroll, simplereenroll, serverkeygen and csrattrs, HTTP Basic and TLS client certificate authentication, and its console pages.

Raised from: est/.

Code What failed Client sees
STS-EST-0001 An EST request reached a realm whose est.enabled is off. HTTP 503 with a text/plain sentence
STS-EST-0002 An EST path named a label that is not a certificate profile (RFC 7030 section 3.2.2). HTTP 404 with a text/plain sentence
STS-EST-0003 An EST operation was asked with a method it does not answer. HTTP 405 with an Allow header
STS-EST-0004 A client asked /fullcmc, which this server does not implement (RFC 7030 section 4.3 is optional). HTTP 501
STS-EST-0005 A client asked /serverkeygen in a realm whose est.serverKeyGeneration is off. HTTP 501
STS-EST-0006 An EST enrollment body was not sent as application/pkcs10. HTTP 415
STS-EST-0007 An EST enrollment body was larger than est.maxRequestBytes. HTTP 413
STS-EST-0008 An EST enrollment body was empty, or was not base64 (RFC 8951: only the base64 alphabet, padding and whitespace). HTTP 400
STS-EST-0009 An EST request that must be authenticated carried no credential. HTTP 401 with WWW-Authenticate: Basic realm=”EST”
STS-EST-0010 An EST request carried HTTP Basic in a realm whose est.basicAuthentication is off. HTTP 401
STS-EST-0011 An EST request carried a malformed HTTP Basic credential (not base64, no colon, or an unusable username). HTTP 401
STS-EST-0012 An EST request authenticated only by a TLS client certificate in a realm whose est.certificateAuthentication is off. HTTP 401
STS-EST-0013 An EST request carried an Authorization scheme other than Basic. HTTP 401 with WWW-Authenticate: Basic realm=”EST”
STS-EST-0014 EST /cacerts was asked in a realm with no certificate hierarchy, so there is no CA certificate to return. HTTP 503
STS-EST-0015 A /simplereenroll named no certificate this entry holds whose subject and subjectAltName the request repeats (RFC 7030 section 4.2.2). HTTP 400
STS-EST-0016 A /simplereenroll request’s subject or subjectAltName differs from the TLS client certificate being renewed (RFC 7030 section 4.2.2). HTTP 400
STS-EST-0017 A /serverkeygen template asked for a key this service cannot generate for that profile (a KEM key outside key-encipherment). HTTP 400
STS-EST-0018 A /serverkeygen template asked for the private key to be encrypted (DecryptKeyIdentifier or AsymmetricDecryptKeyIdentifier), which this server does not implement. HTTP 501
STS-EST-0019 An EST request carried a query string; no EST operation takes one. HTTP 400
STS-EST-0020 An EST handler failed unexpectedly; the client is told nothing about why. HTTP 500 with a generic sentence
STS-EST-0021 A /simplereenroll named a certificate that has expired or been revoked. HTTP 400
STS-EST-0022 An EST label named a trust realm where the realm was already named — by the /realm/ prefix or by an earlier label segment (#251). A request names its realm once. HTTP 404 with a plain-text sentence
STS-EST-0030 A query string on /admin/est or /admin/est/monitor failed validation. HTTP 400 on the console
STS-EST-0031 An EST console or /admin-api action body failed validation. HTTP 400 on the console or /admin-api
STS-EST-0032 An EST console or /admin-api action named an action that does not exist. HTTP 400 on the console or /admin-api
STS-EST-0033 An EST /admin-api action was refused and carried no more specific code. HTTP 400 on /admin-api

STS-SCEP

SCEP (RFC 8894). The Simple Certificate Enrolment Protocol: GetCACaps, GetCACert, GetNextCACert and PKIOperation, the CMS envelope, the RA certificate, challenge passwords, and its console pages.

Raised from: scep/.

Code What failed Client sees
STS-SCEP-0001 A SCEP request reached a realm where scep.enabled is off. HTTP 503 text/plain
STS-SCEP-0002 A SCEP request named no operation, an operation RFC 8894 does not define, or a malformed or repeated query parameter. HTTP 400 text/plain
STS-SCEP-0003 A SCEP operation other than PKIOperation was sent as a POST. HTTP 405 text/plain
STS-SCEP-0004 GetNextCACert was asked for; this server does not pre-announce a CA rollover. HTTP 501 text/plain
STS-SCEP-0005 GetCACert or PKIOperation was asked of a realm with no certificate authority, so there is no SCEP Issuing CA or RA certificate. HTTP 503 text/plain
STS-SCEP-0006 The SCEP RA certificate could not be issued or its replacement could not be recorded. HTTP 503 text/plain, or the console/API refusal
STS-SCEP-0007 A PKIOperation POST carried a Content-Type other than application/x-pki-message, application/octet-stream or none. HTTP 415 text/plain
STS-SCEP-0008 A pkiMessage was larger than scep.maxRequestBytes. HTTP 413 text/plain
STS-SCEP-0009 A GET PKIOperation carried no message parameter, or one that is not strict base64. HTTP 400 text/plain
STS-SCEP-0010 A pkiMessage is not one complete CMS ContentInfo carrying a well-formed SignedData. HTTP 400 text/plain (no CertRep can be built)
STS-SCEP-0011 A pkiMessage does not have exactly one signer whose certificate is in the SignedData. HTTP 400, or CertRep FAILURE badMessageCheck
STS-SCEP-0012 A pkiMessage lacks signed attributes, or its transactionID or senderNonce is missing or malformed. HTTP 400 text/plain (no CertRep can be built)
STS-SCEP-0013 The profile segment of a /enroll/scep URL is not a profile identifier. HTTP 400 text/plain
STS-SCEP-0020 A pkiMessage is signed over a digest this server does not accept (SHA-1, MD5 or unknown). CertRep FAILURE badAlg
STS-SCEP-0021 A pkiMessage names a signature algorithm this server does not verify, or one that disagrees with its digest or the signer key. CertRep FAILURE badAlg
STS-SCEP-0022 The messageDigest signed attribute is not the digest of the encapsulated content. CertRep FAILURE badMessageCheck
STS-SCEP-0023 The signature over a pkiMessage’s signed attributes does not verify with its signer certificate. CertRep FAILURE badMessageCheck
STS-SCEP-0024 The contentType signed attribute is missing or does not agree with the encapsulated content. CertRep FAILURE badMessageCheck
STS-SCEP-0025 A pkiMessage signer certificate carries a key that is not RSA, so no reply can be encrypted to it. CertRep FAILURE badAlg (unencrypted)
STS-SCEP-0026 The pkcsPKIEnvelope is not a readable CMS EnvelopedData. CertRep FAILURE badMessageCheck
STS-SCEP-0027 The pkcsPKIEnvelope is not encrypted to this realm’s current RA certificate. CertRep FAILURE badMessageCheck
STS-SCEP-0028 The pkcsPKIEnvelope transports its content key with an algorithm other than RSAES-PKCS1-v1_5 or RSAES-OAEP. CertRep FAILURE badAlg
STS-SCEP-0029 The pkcsPKIEnvelope content is encrypted with a cipher other than AES-CBC (DES-EDE3-CBC is refused). CertRep FAILURE badAlg
STS-SCEP-0030 The pkcsPKIEnvelope content did not decrypt with the RA key (a wrong key or bad padding, deliberately not told apart). CertRep FAILURE badMessageCheck
STS-SCEP-0031 A pkiMessage carried a messageType this server does not answer. CertRep FAILURE badRequest
STS-SCEP-0032 A PKCSReq or RenewalReq envelope did not hold a PKCS#10 request, or a CertPoll, GetCert or GetCRL envelope did not hold its structure. CertRep FAILURE badRequest
STS-SCEP-0033 A SCEP certificate request carries a key that is not RSA; SCEP encrypts its reply with RSA key transport. CertRep FAILURE badAlg
STS-SCEP-0034 A PKCSReq was signed by a certificate whose key is not the key in the PKCS#10 request, and which this realm did not issue (RFC 8894 section 2.3; one this realm issued makes it a renewal). CertRep FAILURE badMessageCheck
STS-SCEP-0035 A PKCSReq carried no challengePassword attribute. CertRep FAILURE badRequest
STS-SCEP-0036 The profile named in the /enroll/scep URL is not the profile the challenge or the renewed certificate is for. CertRep FAILURE badRequest
STS-SCEP-0037 (retired) A transactionID that already completed was sent again with a different request. Retired 2026-09-26 (#249, #250): such a request is a new transaction, authorized afresh. CertRep FAILURE badRequest
STS-SCEP-0038 A CertPoll (GetCertInitial) named a transactionID this realm holds no result for. CertRep FAILURE badCertId
STS-SCEP-0039 A CertPoll or a retried request for a completed transaction was signed with a different key from the request that completed it. CertRep FAILURE badCertId
STS-SCEP-0040 A RenewalReq, GetCert or GetCRL was not signed by a certificate this realm issued to an entry that still holds it. CertRep FAILURE badMessageCheck
STS-SCEP-0041 A GetCert named a certificate that is not one the signer’s entry holds. CertRep FAILURE badCertId
STS-SCEP-0042 A GetCRL named an issuer that is not this realm’s SCEP Issuing CA. CertRep FAILURE badCertId
STS-SCEP-0043 The SCEP Issuing CA’s CRL could not be built for a GetCRL. CertRep FAILURE badRequest
STS-SCEP-0044 A CertRep could not be built or signed (an internal failure). HTTP 500 text/plain
STS-SCEP-0045 The certificate authority refused a SCEP certificate for a reason the enrollment core did not code. CertRep FAILURE badRequest
STS-SCEP-0046 A pkiMessage signer certificate is outside its validity period. CertRep FAILURE badTime
STS-SCEP-0060 A /admin/scep or /admin-api/scep query string failed input validation. HTTP 400 text/plain or { ok: false, errors }
STS-SCEP-0061 A /admin/scep or /admin-api/scep action body failed input validation. the console redirect with error=, or HTTP 400 { ok: false, errors }
STS-SCEP-0062 A /admin/scep or /admin-api/scep action named no action, or one that does not exist. the console redirect with error=, or HTTP 400 { ok: false, errors }
STS-SCEP-0063 A SCEP certificate revocation from the console or /admin-api named an unknown RFC 5280 reason. the console redirect with error=, or HTTP 400 { ok: false, errors }
STS-SCEP-0064 A SCEP message was refused because another request with the same transactionID was still being answered, on this node or another, when the wait ran out. SCEP CertRep FAILURE badRequest
STS-SCEP-0065 A SCEP message was refused because its transaction could not be claimed: the cluster store could not be asked. SCEP CertRep FAILURE badRequest
STS-SCEP-0066 This node runtime refuses PKCS#1 v1.5 private decryption (its OpenSSL has no implicit rejection), so no SCEP request whose content key is wrapped with rsaEncryption can be decrypted. Logged once per process; node 24 or later is required. SCEP CertRep FAILURE badMessageCheck (the content does not decrypt)

STS-AUTHN

Sign-in, second factors and sessions. The sign-in screen, WebAuthn, TOTP and recovery codes, password verification, the sign-on session, and the OpenID Connect relying party the console and the portal sign in through.

Raised from: authn/, common/credentials.ts, common/totp.ts, common/backup_codes.ts, common/password_policy.ts, common/oidc_rp.ts.

Code What failed Client sees
STS-AUTHN-0001 A request to the sign-in screen or the federation chooser carried a pending sign-in id that failed input validation. invalid_request (HTTP 400)
STS-AUTHN-0002 The sign-in form POST failed input validation (an unknown action, an oversized field, a malformed id). invalid_request (HTTP 400)
STS-AUTHN-0003 No sign-in is pending under the id the sign-in screen, the federation chooser or the form POST named: it expired, was already spent, or never existed. invalid_request (HTTP 400)
STS-AUTHN-0004 The person pressed Cancel at the sign-in screen; the calling protocol is told the user declined. HTTP 303 back to the calling protocol with authn_error=access_denied
STS-AUTHN-0005 The issuance policy refused an unauthenticated (‘continue without signing in’) session for the application at the sign-in screen. HTTP 200 sign-in page, redrawn with the reason
STS-AUTHN-0006 The sign-in form was submitted with no username. HTTP 200 sign-in page, redrawn with the reason
STS-AUTHN-0007 A passwordless security-key sign-in was asked for where the calling protocol demanded a second factor. HTTP 200 sign-in page, redrawn with the reason
STS-AUTHN-0008 Too many sign-in attempts for this identity or address; the password check was not attempted (rate limiter lockout). HTTP 200 sign-in page, redrawn with the reason
STS-AUTHN-0009 The issuance policy refused a session for the application to the person who just authenticated at the sign-in screen (a required role is not held). HTTP 200 sign-in page, redrawn with the reason
STS-AUTHN-0010 The issuance policy refused to start a sign-on session at the session funnel, for a door other than the sign-in screen (federation, SPNEGO, client certificate, WS-Trust, a second-factor screen). —
STS-AUTHN-0011 A sign-out was asked for and there was no session to end: it had already expired or been signed out. —
STS-AUTHN-0012 An arrival session could not be started for a browser reaching a protocol front door; the request continued without one. —
STS-AUTHN-0013 setSessionObserver() was given something that is not a function and was ignored; no Shared Signals transmitter will hear about sessions. —
STS-AUTHN-0014 The installed session observer (the CAEP transmitter) threw while being told about a session event; the event was dropped and the sign-in or sign-out went ahead. —
STS-AUTHN-0015 A session cookie could not be written because the response object has neither set() nor setHeader(); the session exists and the browser was not told. —
STS-AUTHN-0016 The application registry threw while resolving an application’s federation relationships or declared authentication mechanism on the way to the sign-in screen; the shortcut was skipped. —
STS-AUTHN-0017 The federation register threw while resolving a brokering relationship or building the sign-in screen’s partner buttons; they were omitted. —
STS-AUTHN-0018 A request to a second-factor screen (security key, one-time code, recovery code) carried a step id that failed input validation. invalid_request (HTTP 400)
STS-AUTHN-0019 The second-factor step named by the request has expired or does not exist. invalid_request (HTTP 400)
STS-AUTHN-0020 The WebAuthn ceremony POST failed input validation. invalid_request (HTTP 400)
STS-AUTHN-0021 The WebAuthn ceremony result posted by the browser was not JSON. HTTP 200 security-key page, redrawn with the reason
STS-AUTHN-0022 The browser reported that the WebAuthn ceremony failed (declined, timed out, no authenticator), or sent no credential at all. HTTP 200 security-key page, redrawn with the reason; on the portal, its own refusal
STS-AUTHN-0023 In product mode the configured webauthn.rpId does not fit the host the request arrived on, so the ceremony is refused. HTTP 200 security-key page with the reason
STS-AUTHN-0024 Product mode refused to enrol a credential (security key or authenticator app) for a person who has no directory entry, because enrolling would create them. HTTP 200 page / action result with the reason
STS-AUTHN-0025 No security key is enrolled for this person in the role the step needs (second factor or passwordless). invalid_request (HTTP 400), or HTTP 200 security-key page with the reason
STS-AUTHN-0026 A WebAuthn assertion named a credential that is not one of the security keys enrolled for this person in this role. HTTP 200 security-key page with the reason
STS-AUTHN-0027 The WebAuthn registration or assertion could not be parsed or checked (malformed CBOR, authenticator data or clientDataJSON). HTTP 200 security-key page with the reason; on the portal, its own refusal
STS-AUTHN-0028 WebAuthn verification failed: clientDataJSON’s type is not the ceremony’s (webauthn.create / webauthn.get). HTTP 200 page naming the failed check
STS-AUTHN-0029 WebAuthn verification failed: the challenge in clientDataJSON is not the one this service issued for the step. HTTP 200 page naming the failed check
STS-AUTHN-0030 WebAuthn verification failed: the origin in clientDataJSON is not this service’s origin or on webauthn.allowedOrigins. HTTP 200 page naming the failed check
STS-AUTHN-0031 WebAuthn verification failed: the RP ID hash in the authenticator data is not SHA-256 of the expected RP ID. HTTP 200 page naming the failed check
STS-AUTHN-0032 WebAuthn verification failed: the authenticator data does not have the user-present (UP) flag set. HTTP 200 page naming the failed check
STS-AUTHN-0033 WebAuthn verification failed: webauthn.userVerification is required and the authenticator did not set the user-verified (UV) flag. HTTP 200 page naming the failed check
STS-AUTHN-0034 WebAuthn registration failed: the authenticator data carries no attested credential data (AT flag clear). HTTP 200 page naming the failed check
STS-AUTHN-0035 WebAuthn assertion failed: the signature counter did not advance past the stored value, which is the signature of a cloned authenticator. HTTP 200 page naming the failed check
STS-AUTHN-0036 WebAuthn assertion failed: the signature over authenticatorData and the clientDataJSON hash does not verify against the enrolled public key. HTTP 200 page naming the failed check
STS-AUTHN-0037 A WebAuthn ceremony failed a check this service has no specific code for; the check-name table in authn/webauthn_policy.ts is behind the verifier. HTTP 200 page naming the failed check
STS-AUTHN-0038 A security key’s signature counter could not be recorded after a successful assertion; the sign-in stands and the replay defence has nothing new to check next time. —
STS-AUTHN-0039 The one-time code form POST failed input validation. invalid_request (HTTP 400)
STS-AUTHN-0040 Too many one-time code attempts for this identity or address; the code was not checked (rate limiter lockout). HTTP 200 one-time code page, redrawn with the reason
STS-AUTHN-0041 The recovery code form POST failed input validation. invalid_request (HTTP 400)
STS-AUTHN-0042 Too many recovery code attempts for this identity or address; the code was not checked (rate limiter lockout). HTTP 200 recovery code page, redrawn with the reason
STS-AUTHN-0043 Checking a recovery code threw (the worker pool or the store failed part way). HTTP 200 recovery code page asking to try again
STS-AUTHN-0044 Security keys are switched off in this realm (webauthn.enabled), so no new key may be enrolled. HTTP 200 page / action result with the reason
STS-AUTHN-0045 A passwordless (primary) security key may not be enrolled in this realm (webauthn.primaryAllowed). HTTP 200 page / action result with the reason
STS-AUTHN-0046 A second-factor security key may not be enrolled in this realm (webauthn.mfaAllowed). HTTP 200 page / action result with the reason
STS-AUTHN-0047 The credential store’s setDirectory() hooks were refused whole because readPassword or writePassword was missing. —
STS-AUTHN-0048 A password was refused because it is the reserved refusal password ‘invalid’, refused in every mode. the calling protocol’s own authentication failure (sign-in page, LDAP invalidCredentials (49), SOAP fault, HTTP 401)
STS-AUTHN-0049 A password verification was asked for with no username, in product mode. the calling protocol’s own authentication failure
STS-AUTHN-0050 Product mode is in force and no credential store is installed, so every password verification is refused (fail closed). the calling protocol’s own authentication failure
STS-AUTHN-0051 The stored password could not be read because the credential store threw; the verification was refused. the calling protocol’s own authentication failure
STS-AUTHN-0052 The person holds no stored password (userPassword), so product mode cannot verify one. the calling protocol’s own authentication failure
STS-AUTHN-0053 The stored userPassword is not in the hashed form this service writes, so it was refused rather than compared as plaintext. the calling protocol’s own authentication failure
STS-AUTHN-0054 The presented password does not match the stored hash. the calling protocol’s own authentication failure
STS-AUTHN-0055 Setting a password was asked for with no password given. action result with the reason (HTTP 200 page / JSON / LDAP result)
STS-AUTHN-0056 A new password was refused by the realm’s password policy (length, symbols, uppercase, digit). action result with the reason; LDAP constraintViolation where written over the socket
STS-AUTHN-0057 A new password was refused because it is the current password or one of the remembered previous ones (pwdInHistory). action result with the reason; LDAP constraintViolation where written over the socket
STS-AUTHN-0058 A credential operation (set a password, enrol an authenticator, generate recovery codes, issue an activation link) named no person. action result with the reason
STS-AUTHN-0059 A credential operation was refused because no credential store is installed in this process (or it lacks the functions for that credential). action result with the reason
STS-AUTHN-0060 Writing a password to the credential store threw. action result with the reason
STS-AUTHN-0061 A credential write named a person who has no entry in this realm’s directory. action result with the reason
STS-AUTHN-0062 The product-mode bootstrap could not ask the store whether anybody holds a credential, so no bootstrap account was attempted. —
STS-AUTHN-0063 The product-mode bootstrap account could not be created in the directory. —
STS-AUTHN-0064 The product-mode bootstrap could not set a password: this service is in product mode and nobody can sign in. —
STS-AUTHN-0065 Reading a person’s security keys from the credential store threw; they were reported as holding none. —
STS-AUTHN-0066 A security key was to be recorded or enrolled in a role that is neither ‘primary’ nor ‘mfa’. action result with the reason
STS-AUTHN-0067 A security key was not enrolled because the person already holds webauthn.maxKeysPerPerson keys. action result with the reason
STS-AUTHN-0068 Writing a security key to the credential store threw, or the store refused to record a verified key. action result with the reason
STS-AUTHN-0069 Removing a security key named a credential id that is not enrolled for that person. action result with the reason
STS-AUTHN-0070 Removing a security key was refused because it is the person’s last way in (no password and no other primary key). action result with the reason
STS-AUTHN-0071 Reading a person’s authenticator-app enrolment from the credential store threw; it was reported as none. —
STS-AUTHN-0072 An authenticator-app shared secret could not be sealed under the key-encryption key, so it was not stored. action result with the reason
STS-AUTHN-0073 Writing or clearing an authenticator-app enrolment in the credential store threw. action result with the reason
STS-AUTHN-0074 An authenticator-app enrolment was refused because authenticator apps are switched off (the authentication policy). action result with the reason
STS-AUTHN-0075 A pending authenticator-app or security-key enrolment was not found to confirm: it expired or was never begun. action result with the reason
STS-AUTHN-0076 No authenticator app is enrolled for the person a one-time code step, verification or removal named. invalid_request (HTTP 400) at the sign-in screen; action result elsewhere
STS-AUTHN-0077 The person’s authenticator-app enrolment cannot be read (not JSON, or sealed under a different key-encryption key), so the second factor is refused rather than skipped. HTTP 200 one-time code page with the reason
STS-AUTHN-0078 A one-time code verified but the accepted step could not be written back, so that code could be replayed inside its window. —
STS-AUTHN-0079 Listing this realm’s people for the second-factor roster threw; the roster lists only people otherwise known. —
STS-AUTHN-0080 Reading a person’s recovery codes from the credential store threw; they were reported as none. —
STS-AUTHN-0081 Writing or clearing a person’s recovery codes in the credential store threw. action result with the reason
STS-AUTHN-0082 Generating recovery codes was refused because they are switched off (the authentication policy). action result with the reason
STS-AUTHN-0083 A set of distinct recovery codes could not be generated at the configured count and length. action result with the reason
STS-AUTHN-0084 No pending set of recovery codes was found to confirm: it expired, or the handle is not this person’s. action result with the reason
STS-AUTHN-0085 A confirmed set of recovery codes could not be stored; the set is still pending and confirming again retries. action result with the reason
STS-AUTHN-0086 A request to show a person’s recovery codes again was refused: only hashes are stored. action result with the reason
STS-AUTHN-0087 No recovery codes have been issued for the person a recovery-code screen, verification or removal named. invalid_request (HTTP 400) at the sign-in screen; action result elsewhere
STS-AUTHN-0088 Every recovery code in the person’s set has already been used, so the recovery-code screen was refused. invalid_request (HTTP 400)
STS-AUTHN-0089 The person’s stored recovery codes cannot be read, so a presented code was refused rather than let through. HTTP 200 recovery code page with the reason
STS-AUTHN-0090 A presented recovery code is not the shape of one (letters and digits of the code alphabet); no comparison was made. HTTP 200 recovery code page with the reason
STS-AUTHN-0091 A presented recovery code has already been spent. HTTP 200 recovery code page with the reason
STS-AUTHN-0092 A presented recovery code is not one of the person’s codes. HTTP 200 recovery code page with the reason
STS-AUTHN-0093 A recovery code verified but could not be marked spent, so it was refused: a code that cannot be spent works for ever. HTTP 200 recovery code page with the reason
STS-AUTHN-0094 A security-key enrolment was confirmed with an enrolment id that is not the one in progress (another tab). action result with the reason
STS-AUTHN-0095 A security-key enrolment was refused because that authenticator is already enrolled for the person. action result with the reason
STS-AUTHN-0096 An activation link was checked with no username or no token. the portal’s activation refusal page
STS-AUTHN-0097 Reading an activation token from the credential store threw; the link was refused. the portal’s activation refusal page
STS-AUTHN-0098 An activation link was presented for a person with no outstanding activation token. the portal’s activation refusal page
STS-AUTHN-0099 An activation link was presented after its token expired (security.activationTtlMinutes). the portal’s activation refusal page
STS-AUTHN-0100 An activation link’s token does not match the one issued for that person. the portal’s activation refusal page
STS-AUTHN-0101 Writing an activation token to the credential store threw; no link was issued. action result with the reason
STS-AUTHN-0102 A spent activation token could not be cleared from the credential store, so the link may still work. —
STS-AUTHN-0103 A presented one-time code is not the configured number of digits; no comparison was made. HTTP 200 one-time code page with the reason; action result at enrolment
STS-AUTHN-0104 A stored TOTP shared secret could not be decoded from base32, so the code could not be checked. HTTP 200 one-time code page with the reason
STS-AUTHN-0105 A presented one-time code matched no time step in the allowed window: wrong, or expired. HTTP 200 one-time code page with the reason; action result at enrolment
STS-AUTHN-0106 A presented one-time code was already used (RFC 6238 section 5.2): its time step is at or below the last one accepted. HTTP 200 one-time code page with the reason
STS-AUTHN-0107 A password policy save or reset named a profile other than ‘default’. action result with the reason
STS-AUTHN-0108 A password policy save was refused because a field is missing, out of range, unreadable, or inconsistent with another. action result with the reason
STS-AUTHN-0109 A password policy save was refused because this process has no embedded directory to keep ou=passwordPolicies in. action result with the reason
STS-AUTHN-0110 The directory refused to store the password policy profile (it is at its maximum number of entries). action result with the reason
STS-AUTHN-0111 No generated password satisfied the password policy within the draw limit, so none was generated. the caller’s own failure (usually HTTP 500 or an action refusal)
STS-AUTHN-0112 A hosted surface (console or portal) cannot sign anybody in: its seeded OIDC client is not in this realm’s registry. the console’s or portal’s sign-in refusal page
STS-AUTHN-0113 A hosted surface’s OIDC client declares a client secret method (client_secret_basic or client_secret_post) and carries no client secret, so it cannot authenticate at the token endpoint. The seeded entries use private_key_jwt and hold no secret (#138). the console’s or portal’s sign-in refusal page
STS-AUTHN-0114 Product mode refused a hosted-surface sign-in because this service was reached at an address that is not a registered redirect URI of its client. the console’s or portal’s sign-in refusal page
STS-AUTHN-0115 In development a hosted surface’s client could not learn the redirect URI for the address it was reached at; the sign-in went ahead. —
STS-AUTHN-0116 The OIDC back channel could not read this service’s own TLS certificate to verify the loopback connection against. the console’s or portal’s sign-in refusal page
STS-AUTHN-0117 The OIDC back channel’s token or JWKS request was answered with a redirect, which is not followed. the console’s or portal’s sign-in refusal page
STS-AUTHN-0118 The OIDC back channel’s answer was larger than the limit and was abandoned. the console’s or portal’s sign-in refusal page
STS-AUTHN-0119 The OIDC back channel did not get an answer from this service within oidcRp.backChannelTimeoutS. the console’s or portal’s sign-in refusal page
STS-AUTHN-0120 The OIDC back channel’s loopback request to this service failed (connection refused, reset, TLS error). the console’s or portal’s sign-in refusal page
STS-AUTHN-0121 A hosted surface’s callback carried an error from the authorization endpoint (for example the person declined). the console’s or portal’s sign-in refusal page
STS-AUTHN-0122 A hosted surface’s callback carried no code or no state. the console’s or portal’s sign-in refusal page
STS-AUTHN-0123 A hosted surface’s callback named a state this service did not start, already completed, or has forgotten. the console’s or portal’s sign-in refusal page
STS-AUTHN-0124 A hosted surface’s callback presented a state that belongs to the other surface. the console’s or portal’s sign-in refusal page
STS-AUTHN-0125 A hosted surface’s sign-in flow took longer than authn.pendingTtlS and expired before the callback. the console’s or portal’s sign-in refusal page
STS-AUTHN-0126 The token endpoint refused a hosted surface’s authorization code redemption (a non-200 answer). the console’s or portal’s sign-in refusal page
STS-AUTHN-0127 The token response to a hosted surface carried no id_token. the console’s or portal’s sign-in refusal page
STS-AUTHN-0128 A hosted surface could not read this service’s own JWKS to verify the ID Token. the console’s or portal’s sign-in refusal page
STS-AUTHN-0129 The ID Token issued to a hosted surface has a header that is not base64url JSON. the console’s or portal’s sign-in refusal page
STS-AUTHN-0130 The ID Token issued to a hosted surface has no alg in its header. the console’s or portal’s sign-in refusal page
STS-AUTHN-0131 The ID Token issued to a hosted surface says alg=none. the console’s or portal’s sign-in refusal page
STS-AUTHN-0132 The ID Token issued to a hosted surface names a kid the JWKS does not publish, or the JWKS publishes no keys. the console’s or portal’s sign-in refusal page
STS-AUTHN-0133 The ID Token issued to a hosted surface did not verify against any published key (signature, issuer, audience or lifetime). the console’s or portal’s sign-in refusal page
STS-AUTHN-0134 The ID Token issued to a hosted surface carries a nonce that is not the one the sign-in sent. the console’s or portal’s sign-in refusal page
STS-AUTHN-0135 The ID Token issued to a hosted surface names nobody: no preferred_username and no sub. the console’s or portal’s sign-in refusal page
STS-AUTHN-0136 A console or portal session’s ID Token and access token ran out and its sign-in was issued no refresh token to renew them with; the session was ended. none — the next page runs the authorization code flow again
STS-AUTHN-0137 The token endpoint refused the refresh token grant a console or portal session made to renew its tokens (a revoked, replayed or expired refresh token); the session was ended. none — the next page runs the authorization code flow again
STS-AUTHN-0138 The ID Token a console or portal renewal was issued names a different issuer, subject or authentication time from the sign-in (OpenID Connect Core section 12.2); the session was ended. none — the next page runs the authorization code flow again
STS-AUTHN-0139 A console or portal session could not renew its tokens because the trust realm its sign-in ran in no longer exists; the session was ended. none — the next page runs the authorization code flow again
STS-AUTHN-0140 Renewing a console or portal session’s tokens threw; the request went on and the renewal is tried again on the next one. none
STS-AUTHN-0141 A console or portal session’s tokens ran out after the window it could renew them in (the refresh token’s lifetime from the sign-in) had closed; the session was ended. none — the next page runs the authorization code flow again
STS-AUTHN-0142 A correct password was refused at a door that cannot ask for a new one (an LDAP bind, the password grant, WS-Trust, SCIM or EST Basic) because pwdReset is TRUE on the entry; in product mode only. that protocol’s own authentication failure
STS-AUTHN-0143 pwdReset could not be written on a person’s entry. none — logged
STS-AUTHN-0144 A forced password change named a step that does not exist or has expired. invalid_request (HTTP 400)
STS-AUTHN-0145 A forced password change request was refused by the input validator. invalid_request (HTTP 400)
STS-AUTHN-0146 A forced password change was refused: no new password, two that differ, the reserved refusal password, or one the password policy refused; the page is drawn again with the reason. the change page again with the reason
STS-AUTHN-0160 Disabling somebody’s passwordless sign-in was refused: they hold no security key in the primary role. HTTP 400 (API) or a 303 with error=
STS-AUTHN-0161 Disabling somebody’s passwordless sign-in was refused: they have no password, so their primary security keys are their only way in. HTTP 400 (API) or a 303 with error=
STS-AUTHN-0162 Disabling somebody’s second factors was refused: they hold no authenticator app, no mfa-role security key and no recovery codes. HTTP 400 (API) or a 303 with error=
STS-AUTHN-0163 The credential store refused a write while security keys or second factors were being removed; what went before it is reported. HTTP 400 (API) or a 303 with error=
STS-AUTHN-0164 A password reset link could not be written onto, or cleared from, the person’s entry. HTTP 400 (API) or a 303 with error=
STS-AUTHN-0165 A password reset link was presented for somebody with none outstanding (never issued, or already spent). the reset page’s one refusal sentence, HTTP 400
STS-AUTHN-0166 A password reset link was presented after it expired (security.passwordResetTtlMinutes). the reset page’s one refusal sentence, HTTP 400
STS-AUTHN-0167 A password reset link was presented whose token does not match the hash on the entry. the reset page’s one refusal sentence, HTTP 400
STS-AUTHN-0168 A password reset link was presented with no username or no token. the reset page’s one refusal sentence, HTTP 400
STS-AUTHN-0169 The password could not be removed from somebody’s entry while a password reset link was being issued, so the link was withdrawn. HTTP 400 (API) or a 303 with error=
STS-AUTHN-0170 The per-account second-factor requirement (stsMfaRequired) could not be written. HTTP 400 (API) or a 303 with error=
STS-AUTHN-0171 A passwordless security-key sign-in was refused because a second factor is required of the person (their account or the realm’s authentication policy). the sign-in screen again with the reason
STS-AUTHN-0172 A sign-in was refused: a second factor is required of the person, they hold none, and neither an authenticator app nor a security key can be enrolled in the realm. the sign-in screen again with the reason
STS-AUTHN-0173 The second-factor set-up step named by the request is expired, unknown, or not a set-up step. OAuth-style invalid_request page, HTTP 400
STS-AUTHN-0174 A request to the second-factor set-up step was malformed, or asked to confirm a code before an authenticator app was chosen. HTTP 400 page
STS-AUTHN-0175 A second-factor set-up choice was refused: the mechanism is switched off in the realm, or the person holds a second factor already. HTTP 400 page
STS-AUTHN-0176 An authenticator app enrolment at sign-in could not be started. HTTP 400 page
STS-AUTHN-0177 The code confirming an authenticator app enrolled at sign-in was refused; the same secret is drawn again. HTTP 400 page
STS-AUTHN-0180 A signed-in session was refused because the directory holds no entry for the person, so there is no subject to give it (ldap.autocreateUsers off, or a federation relationship with dynamic provisioning off and nobody provisioned). the calling door’s own refusal
STS-AUTHN-0181 A security-key assertion verified and was refused because its ceremony challenge had already been answered, by another node or a request racing this one (#46). HTTP 200 security-key page with the reason
STS-AUTHN-0182 A single-use credential (a one-time code step, a recovery code, a security-key assertion, an activation or password reset link) could not be proved unspent because the cluster store could not be asked, so it was refused. the calling door’s own refusal page
STS-AUTHN-0183 An activation or password reset link was refused because another request, on this node or another, is spending it or has spent it. HTTP 400 portal page (one sentence for every link failure)
STS-AUTHN-0184 Recovery codes another node spent could not be written as spent on the person’s entry; their claims still refuse them. none (log only)
STS-AUTHN-0185 The product-mode bootstrap was not attempted on this node: the store could not be asked whether another node is running it. none (log only)
STS-AUTHN-0189 A hosted surface’s token renewal was in flight on another node (its claim was held) and its renewed tokens had not reached this node within the wait; this request went on without renewing. none — logged only
STS-AUTHN-0190 A hosted surface could not renew a session’s tokens because the claim store could not be asked; the request went on without renewing, rather than risk a second redemption of the refresh token. none — logged only
STS-AUTHN-0191 A sign-out ended a session whose end another process had already reported, so no second event or success row was written. none — audit row only; the sign-out is answered as usual
STS-AUTHN-0192 Whether another process had already reported a session’s end could not be asked — the claim answered that the store could not say, or rejected three times (#242) — so it was reported here and a receiver may be told twice. none — logged
STS-AUTHN-0193 A security key registration was refused because the same credential id was being (or had just been) registered by another request or node. WebAuthn Level 3 section 7.1 step 26 (a credential id already registered is refused)
STS-AUTHN-0194 A security key registration was refused because the store that decides whether its credential id is already registered elsewhere could not be asked. none — fail closed
STS-AUTHN-0195 A recovery-code set written before 2026-09-11 (codes, not hashes) could not be sealed under the key-encryption key when it was rewritten, so the change was not stored. none — the spend that asked is refused (STS-AUTHN-0093)
STS-AUTHN-0196 A password presented as the second factor after a wallet sign-in was refused. HTTP 200 page at /authn/password-factor, with the reason
STS-AUTHN-0200 A password was presented for an account that is disabled (pwdAccountLockedTime on its entry), and it was refused before it was compared, in every mode. the door’s own refusal: “authentication failed” on the sign-in screen, LDAP 49, invalid_grant, a SOAP fault, SCIM 401
STS-AUTHN-0201 A session, or anything issued on a person’s behalf, was refused because the account is disabled — at authn.startSession(), a live session presented again, or the issuance gate. the door’s own refusal (the sign-in screen again, a 403 page, access_denied)
STS-AUTHN-0202 Disabling or enabling an account could not write pwdAccountLockedTime onto the person’s entry. the caller’s refusal (errors on a console or /admin-api reply)
STS-AUTHN-0203 An account was disabled and ending what the person held (the global logout) failed; the lock stands and every door refuses them. none — logged; the disable’s reply says what failed
STS-AUTHN-0204 A sign-in that demands a security key (a WS-Federation HardwareToken wauth, or OAuth acr_values naming only key aliases) was answered with something else — a one-time code, a recovery code — or the account holds a second factor and no key to present. HTTP 400 invalid_request, or the sign-in screen again
STS-AUTHN-0205 The product-mode bootstrap was given a password through admin.bootstrapPassword that the password policy refuses, so no bootstrap account was created and nobody can sign in. It is NOT replaced with a generated one: the operator set it so that the only way in would not be in a log, and generating one would put a working credential there and leave theirs not working. none — logged, and the service starts with nobody able to sign in
STS-AUTHN-0206 Product mode: a passwordless sign-in named a person who holds no security key that signs in on its own, and the sign-in screen does not enrol one — enrolling there would give the account to whoever claimed the name first. A primary key is added on /portal/keys, by an activation link or by an operator. Development enrols on first use (mode.enrolsKeysOnFirstUse()). none — the sign-in screen is drawn again with the reason
STS-AUTHN-0207 A hosted surface (the console, the portal or the embedded debugger) could not get the key it signs its private_key_jwt client assertion with: this realm has no certificate authority to issue one, the issue failed, or the key could not be written onto the surface’s application entry. The surface cannot authenticate at the token endpoint, so the sign-in or renewal stops (#138). RFC 7523 section 2.2; OIDC Core section 9
STS-AUTHN-0208 A hosted surface’s key was being issued by another process, and neither the key nor an answer from the claim store arrived in time; the sign-in or renewal stops rather than issuing a second key (#138). Since #296 the claim is released when an issuance ends, so this means the issuer is still at work or the store cannot be asked. none — a refusal of this service’s own
STS-AUTHN-0209 A hosted surface’s application entry declares a token endpoint authentication method the surface does not implement. It implements private_key_jwt, and client_secret_basic or client_secret_post for an entry an operator set so (#138). RFC 7591 section 2
STS-AUTHN-0210 A hosted surface refused the JWT-secured authorization response (JARM) it was sent back with: not a signed JWT, a key the realm’s JWKS does not hold, a signature that does not verify, or the wrong issuer, audience or expiry (#139). the console’s, portal’s or debugger’s sign-in refusal page
STS-AUTHN-0211 Under FAPI 1.0 Advanced, a hosted surface could not push its signed authorization request to /oauth2/par, so its sign-in could not start (#139). the console’s, portal’s or debugger’s sign-in refusal page
STS-AUTHN-0212 A passwordless security-key sign-in was asked for at the sign-in screen federation’s link-at-first-sign-in draws, which signs in with the password (#109). HTTP 200 sign-in screen with an error
STS-AUTHN-0213 Product mode: a person who holds a second factor, or of whom one is required, presented their own RIGHT password at a password-only door (an LDAP bind, a WS-Security UsernameToken, SCIM, SSF or EST Basic), which cannot ask for the second factor. Refused, and counted as a failed attempt. An app password scoped to the door is what such a person uses there (authn.passwordAloneDoors lists doors that accept the password anyway). the door’s own wrong-password answer, unchanged: LDAP invalidCredentials (49), the WS-Trust FailedAuthentication fault, HTTP 401 at SCIM, SSF and EST
STS-AUTHN-0214 An app password was presented where it is not accepted: at a door it is not scoped to, or at a browser sign-in, where no app password is ever accepted. the door’s own wrong-password answer, unchanged
STS-AUTHN-0215 An app password was not made: its name is empty, longer than sixty-four characters or not printable text, or the person already holds one of that name. HTTP 400 (API) or the page redrawn with the reason
STS-AUTHN-0216 An app password was not made: it named no door, or a door that is not one of ldap, wstrust, scim, ssf and est. HTTP 400 (API) or the page redrawn with the reason
STS-AUTHN-0217 An app password was not made: the person already holds appPasswords.maxPerPerson of them. HTTP 400 (API) or the page redrawn with the reason
STS-AUTHN-0218 An app password was not made: app passwords are turned off in this realm (appPasswords.enabled). One already made goes on working. HTTP 400 (API) or the page redrawn with the reason
STS-AUTHN-0219 An app password was not revoked: the person holds none with that id. HTTP 400 (API), or 404 on the portal, where somebody else’s is answered as one that does not exist
STS-AUTHN-0220 The app passwords on a person’s entry could not be read or written: the directory threw, refused the write, or holds a value this service did not write. A value it cannot read is refused rather than compared. HTTP 400 (API), the page redrawn, or the door’s wrong-password answer
STS-AUTHN-0221 An app password was not made: the name is not a person in this realm’s directory. An application authenticates with its own client credentials, and an app password is a person’s. HTTP 400 (API)
STS-AUTHN-0222 A password being set was refused because it has appeared in a data breach: Pwned Passwords lists it (#62 P6, product mode). NIST SP 800-63B section 3.1.1.2
STS-AUTHN-0223 A password was set in product mode by a door that did not screen it against Pwned Passwords first, so no breach verdict was there to read. The door is named in the line; it needs a screen(). —
STS-AUTHN-0224 The Pwned Passwords range API did not answer (off, unreachable, refused by the outbound rules, or too slow); a password was set unscreened. —
STS-AUTHN-0225 The browser fingerprint script was asked for while risk.fingerprinting is off in the realm; nothing draws a page that uses it, so it is not served (#62 P6). HTTP 404
STS-AUTHN-0226 A delegation flag on a person (stsNotDelegated or stsMayAct) could not be written onto their entry, or the credential store is not installed (#108). none — the caller’s refusal
STS-AUTHN-0227 A person’s delegate (stsMayAct) was refused: it names no person or application entry in this realm, or names the person themselves (#108). none — the caller’s refusal
STS-AUTHN-0228 A WebAuthn registration was refused: the credential’s algorithm is not one of the pubKeyCredParams this realm offered (webauthn.algorithms) (#105). W3C WebAuthn Level 3 section 7.1
STS-AUTHN-0229 A WebAuthn registration was refused: the credential id is longer than 1023 bytes (#105). W3C WebAuthn Level 3 section 7.1
STS-AUTHN-0230 A WebAuthn registration was refused: the authenticator data says the credential is backed up (BS) and not backup eligible (BE) (#105). W3C WebAuthn Level 3 section 7.1
STS-AUTHN-0231 A WebAuthn registration was refused: its attestation statement format is not one of section 8’s eight (#105). W3C WebAuthn Level 3 sections 7.1 and 8
STS-AUTHN-0232 A WebAuthn registration was refused: its attestation statement does not conform to its format’s syntax — a member missing, of the wrong type, or not defined by the format (#105). W3C WebAuthn Level 3 section 8
STS-AUTHN-0233 A WebAuthn registration was refused: the attestation signature does not verify (#105). W3C WebAuthn Level 3 section 8
STS-AUTHN-0234 A WebAuthn registration was refused: a requirement of its attestation format failed — the certificate’s fields, the key it certifies, the TPM certInfo, the Android challenge or authorization list, the SafetyNet or Apple nonce (#105). W3C WebAuthn Level 3 section 8
STS-AUTHN-0235 A WebAuthn registration was refused: its attestation does not chain to a trust anchor — to the roots the FIDO Metadata Service lists for a model it lists, or to any anchor where the realm requires a trusted statement (#105). W3C WebAuthn Level 3 section 7.1 steps 23-25
STS-AUTHN-0236 A WebAuthn registration was refused: the authenticator model’s AAGUID is not in webauthn.attestationAllowedAaguids (#105). —
STS-AUTHN-0237 A WebAuthn registration was refused: the FIDO Metadata Service reports the authenticator model REVOKED, USER_VERIFICATION_BYPASS or one of the KEY_COMPROMISE statuses (#105). FIDO Metadata Service section 3.1.4
STS-AUTHN-0238 A WebAuthn registration was refused: the authenticator model does not hold the certification level, or the FIPS 140 certification, the realm requires — or the FIDO Metadata Service does not list it (#105). FIDO Metadata Service section 3.1.4.1
STS-AUTHN-0239 A WebAuthn registration was refused: a certificate in the attestation chain is revoked, or its status could not be established under pki.revocationCheck (#105). W3C WebAuthn Level 3 section 7.1; RFC 5280 section 6.3
STS-AUTHN-0240 A WebAuthn registration was refused: the authenticator sent no attestation or a self attestation, and the realm requires a trusted one (#105). W3C WebAuthn Level 3 section 7.1 step 24
STS-AUTHN-0241 A WebAuthn registration was refused because its attestation statement could not be checked: the verifier threw. The line names the format and the stack (#105). —
STS-AUTHN-0242 An authentication policy save or reset named a profile other than ‘default’ (#64). action result with the reason
STS-AUTHN-0243 An authentication policy save was refused because a field is missing, out of range or unreadable, or because it would leave no first factor, or require a second factor with none allowed (#64). action result with the reason
STS-AUTHN-0244 An authentication policy save would turn an email mechanism on in a realm that cannot send mail (#64). action result with the reason
STS-AUTHN-0245 An authentication policy save found no embedded directory to keep the profile in (#64). action result with the reason
STS-AUTHN-0246 The directory would not store an authentication policy profile: it is at its maximum number of entries (#64). action result with the reason
STS-AUTHN-0247 An emailed second factor was asked for that is neither code nor link (#64). action result with the reason
STS-AUTHN-0248 A person opted in to an emailed second factor that this realm’s authentication policy does not accept as one (#64). portal page with the reason
STS-AUTHN-0249 A person opted in to an emailed second factor while this realm cannot send mail (#64). portal page with the reason
STS-AUTHN-0250 A person opted in to an emailed second factor while their address is not verified (#64). portal page with the reason
STS-AUTHN-0251 A person’s emailed second factor could not be written to their entry (#64). portal page with the reason
STS-AUTHN-0252 A person reached the authentication policy’s limit of consecutive failed emailed codes or links, and their emailed factor was turned off (NIST SP 800-63B-4 section 3.2.2, #64). —
STS-AUTHN-0253 A security key or passkey was refused as a first factor: this realm’s authentication policy does not accept one (#64). sign-in screen with the reason
STS-AUTHN-0254 A new security key was refused as a second factor: this realm’s authentication policy does not accept one (#64). sign-in screen or portal page with the reason
STS-AUTHN-0255 A password was refused as a first factor: this realm’s authentication policy does not accept one (#64). sign-in screen with the reason
STS-AUTHN-0256 A second factor was needed after a first and none this realm accepts was available: the person holds none, and the policy does not accept a password as one (#64). sign-in refused with the reason
STS-AUTHN-0257 No more emailed codes or links may be sent for one sign-in step (#64). the page, with the reason
STS-AUTHN-0258 Another emailed code or link was asked for sooner than the policy’s resend interval (#64). the page, with the reason
STS-AUTHN-0259 An emailed code or link could not be queued by the mail channel; the line names the channel’s refusal (#64). the page offers the other factors
STS-AUTHN-0260 An emailed code or link was asked for as a first factor where this realm does not offer one, or where a key or a password is demanded (#64). sign-in screen with the reason
STS-AUTHN-0261 An emailed first factor was asked for an account that has no verified address, is disabled, or does not exist; nothing was mailed and the page does not say so (#64). the same page as a sent one
STS-AUTHN-0262 An emailed code or link was presented after it had already been used (#64). the page, with the reason
STS-AUTHN-0263 Whether an emailed code or link had been used could not be asked of the store, so it was not accepted (#64). the page, with the reason
STS-AUTHN-0264 A wrong emailed code or link was presented (#64). the page, with the attempts left
STS-AUTHN-0265 An emailed code or link was presented after it expired (#64). the page, with the reason
STS-AUTHN-0266 An emailed sign-in link was opened in a browser other than the one that started the sign-in (#64, D3). the page, with the reason
STS-AUTHN-0267 The emailed code or link door failed unexpectedly; the line carries the stack (#64). an error page
STS-AUTHN-0268 A session was refused: this realm’s authentication policy does not accept the mechanism the door named as a first factor (a certificate, a Kerberos ticket, a federation partner, a wallet, a passkey, a password or an emailed code or link) (#64). the door’s own refusal page
STS-AUTHN-0269 A session was refused: this realm’s authentication policy does not accept the mechanism that answered as a second factor (a password or wallet after another factor, or an emailed code or link) (#64). the door’s own refusal page
STS-AUTHN-0270 Ignore was posted on a second-factor set-up step that was REQUIRED rather than offered (#246): only an administrator the authentication policy OFFERS a second factor may decline it. HTTP 400, the set-up page again
STS-AUTHN-0290 A session was ended by a caller that did not say who initiated it (#242): CAEP session-revoked says system, and the caller should state admin, user, policy or system. none — logged; the session is ended
STS-AUTHN-0291 Reporting a session’s end (its audit row, CAEP session-revoked and back-channel Logout Tokens) threw after the claim that decides who reports it was won (#242); it is not tried again, because a second try could tell a receiver twice. none — logged
STS-AUTHN-0292 A realm held authn.maxSessions sign-on sessions when another was created, so the least recently used session was ended to make room (#345) — through the same end an expiry takes: its audit row (which carries this code), CAEP session-revoked and back-channel Logout Tokens. none — audited; logged at most once a minute per process
STS-AUTHN-0293 The directory’s credential census threw (#352), so the users list’s counts and second-factor filter asked each person’s credentials one at a time instead — slower, and the same answer. none — logged
STS-AUTHN-0294 A passkey assertion was refused because the key’s algorithm is insecure (SHA-1’s RS1) and webauthn.insecureAlgorithms is off in this realm, or the service is in product mode. none — the sign-in screen is drawn again
STS-AUTHN-0295 A person’s delegation semantics named something other than delegation or impersonation (#186). none (a console or management API refusal, HTTP 400)

STS-OAUTH

OAuth 2.0 and OpenID Connect. The authorization server: every endpoint, client authentication, DPoP, mTLS, RFC 9700 mode, consent, and the RFC 7521/7522/7523 assertion grants.

Raised from: oauth-oidc/, common/person_assertions.js.

Code What failed Client sees
STS-OAUTH-0001 A JWT client assertion could not be read as a JWT (its header is not base64url JSON). invalid_client (HTTP 401)
STS-OAUTH-0002 A client_secret_jwt client assertion was signed with an algorithm other than HS256, HS384 or HS512. invalid_client (HTTP 401)
STS-OAUTH-0003 A client_secret_jwt client assertion arrived for a client whose registry entry holds no client_secret to verify it with. invalid_client (HTTP 401)
STS-OAUTH-0004 A private_key_jwt client assertion named a symmetric algorithm or none — the alg-confusion forgery — and was refused. invalid_client (HTTP 401)
STS-OAUTH-0005 A private_key_jwt client registered only a jwks_uri, which this service will not fetch, so there was no key to verify its assertion with. invalid_client (HTTP 401)
STS-OAUTH-0006 A private_key_jwt client has no keys registered or issued, so its client assertion could not be verified. invalid_client (HTTP 401)
STS-OAUTH-0007 A JWT client assertion did not verify: wrong key, wrong issuer, wrong audience or expired. invalid_client (HTTP 401)
STS-OAUTH-0008 A JWT client assertion’s sub is not the client it authenticates (RFC 7523 section 3). invalid_client (HTTP 401)
STS-OAUTH-0009 A JWT client assertion carried no exp, which product mode refuses (RFC 7523 section 3 claim 4). invalid_client (HTTP 401)
STS-OAUTH-0010 A JWT client assertion is valid for longer than oauth2.jwtBearerMaxLifetimeS allows. invalid_client (HTTP 401)
STS-OAUTH-0011 A JWT client assertion carried no jti, so a replay of it could not be refused. invalid_client (HTTP 401)
STS-OAUTH-0012 A JWT client assertion was replayed: its issuer and jti are already in the used-assertion history, spent or held by a request in flight, as a client assertion or as a grant. invalid_client (HTTP 401)
STS-OAUTH-0013 The used-assertion history for the realm holds oauth2.assertionReplayCacheSize unexpired rows, so a new client assertion was refused rather than a live row forgotten. invalid_client (HTTP 401)
STS-OAUTH-0014 A client registered for RFC 8705 certificate authentication connected with no TLS client certificate. invalid_client (HTTP 401)
STS-OAUTH-0015 A self_signed_tls_client_auth client has no certificate thumbprint registered to compare against. invalid_client (HTTP 401)
STS-OAUTH-0016 A self_signed_tls_client_auth client presented a certificate whose thumbprint is not the registered one (RFC 8705 section 2.2). invalid_client (HTTP 401)
STS-OAUTH-0017 (retired) A tls_client_auth client has no subject DN registered to compare against. invalid_client (HTTP 401)
STS-OAUTH-0018 (retired) A tls_client_auth client presented a certificate whose subject DN is not the registered one (RFC 8705 section 2.1.2). invalid_client (HTTP 401)
STS-OAUTH-0019 A client_secret_basic or client_secret_post client presented no client_secret. invalid_client (HTTP 401)
STS-OAUTH-0020 The client_secret presented does not match the one on the client’s registry entry. invalid_client (HTTP 401)
STS-OAUTH-0021 A client_secret_jwt or private_key_jwt client sent no client_assertion. invalid_client (HTTP 401)
STS-OAUTH-0022 A JWT client assertion arrived under a client_assertion_type other than RFC 7523’s. invalid_client (HTTP 401)
STS-OAUTH-0023 A saml2_bearer client sent no client_assertion (RFC 7522 section 2.2). invalid_client (HTTP 401)
STS-OAUTH-0024 A SAML client assertion arrived under a client_assertion_type other than RFC 7522’s. invalid_client (HTTP 401)
STS-OAUTH-0025 The client’s registry entry names a token_endpoint_auth_method this service cannot verify. invalid_client (HTTP 401)
STS-OAUTH-0026 A JWKS registered for an RFC 7523 party (client or assertion issuer) is not valid JSON. invalid_client (HTTP 401) or invalid_grant (HTTP 400)
STS-OAUTH-0027 A JWKS registered for an RFC 7523 party contains no keys. invalid_client (HTTP 401) or invalid_grant (HTTP 400)
STS-OAUTH-0028 None of the keys in a JWKS registered for an RFC 7523 party could be read. invalid_client (HTTP 401) or invalid_grant (HTTP 400)
STS-OAUTH-0029 An encrypted (five-part) JWT assertion has a protected header that is not base64url JSON. invalid_client (HTTP 401) or invalid_grant (HTTP 400)
STS-OAUTH-0030 An encrypted JWT assertion names an algorithm, curve or kid for which this authorization server holds no decryption key. invalid_client (HTTP 401) or invalid_grant (HTTP 400)
STS-OAUTH-0031 An encrypted JWT assertion could not be decrypted with any candidate key. invalid_client (HTTP 401) or invalid_grant (HTTP 400)
STS-OAUTH-0032 An encrypted JWT assertion’s protected header carries a cty other than JWT. invalid_client (HTTP 401) or invalid_grant (HTTP 400)
STS-OAUTH-0033 An encrypted JWT assertion decrypted to something that is not a signed JWT (RFC 7523 section 3 claim 9). invalid_client (HTTP 401) or invalid_grant (HTTP 400)
STS-OAUTH-0034 The x5c certificate chain in a JWT assertion’s header could not be path-checked at all. invalid_client (HTTP 401) or invalid_grant (HTTP 400)
STS-OAUTH-0035 The x5c certificate in a JWT assertion does not chain to this realm’s own certificate authority. invalid_client (HTTP 401) or invalid_grant (HTTP 400)
STS-OAUTH-0036 The x5c leaf certificate in a JWT assertion chains here but could not be read for its public key. invalid_client (HTTP 401) or invalid_grant (HTTP 400)
STS-OAUTH-0037 An RFC 7523 JWT bearer grant was requested while oauth2.jwtBearerGrant is off. unsupported_grant_type (HTTP 400)
STS-OAUTH-0038 An RFC 7523 JWT bearer grant request carried no assertion parameter. invalid_request (HTTP 400)
STS-OAUTH-0039 An RFC 7523 authorization-grant assertion is not a JWT. invalid_grant (HTTP 400)
STS-OAUTH-0040 An RFC 7523 authorization-grant assertion says alg=none. invalid_grant (HTTP 400)
STS-OAUTH-0041 An RFC 7523 authorization-grant assertion is signed with an algorithm this service does not verify. invalid_grant (HTTP 400)
STS-OAUTH-0042 An RFC 7523 authorization-grant assertion carries no iss (section 3 claim 1). invalid_grant (HTTP 400)
STS-OAUTH-0043 An RFC 7523 authorization-grant assertion names an issuer nobody in the realm has declared, and no x5c chain vouches for it. invalid_grant (HTTP 400)
STS-OAUTH-0044 The application declared as an RFC 7523 assertion issuer registered only a jwks_uri, and its keys could not be fetched (#120; STS-OAUTH-0599 logs why). invalid_grant (HTTP 400)
STS-OAUTH-0045 The keys registered for an RFC 7523 assertion issuer could not be read. invalid_grant (HTTP 400)
STS-OAUTH-0046 No key is registered or issued for an RFC 7523 assertion issuer, so its assertion could not be verified. invalid_grant (HTTP 400)
STS-OAUTH-0047 An RFC 7523 authorization-grant assertion did not verify: wrong key, wrong audience or expired. invalid_grant (HTTP 400)
STS-OAUTH-0048 An RFC 7523 authorization-grant assertion carries no sub (section 3 claim 2). invalid_grant (HTTP 400)
STS-OAUTH-0049 A person’s RFC 7523 assertion named somebody other than that person as its subject. invalid_grant (HTTP 400)
STS-OAUTH-0050 An RFC 7523 authorization-grant assertion carries no exp (section 3 claim 4). invalid_grant (HTTP 400)
STS-OAUTH-0051 An RFC 7523 authorization-grant assertion’s iat is in the future beyond the allowed clock skew. invalid_grant (HTTP 400)
STS-OAUTH-0052 An RFC 7523 authorization-grant assertion is valid for longer than oauth2.jwtBearerMaxLifetimeS allows. invalid_grant (HTTP 400)
STS-OAUTH-0053 An RFC 7523 authorization-grant assertion carries no jti, so it could not be spent. invalid_grant (HTTP 400)
STS-OAUTH-0054 An RFC 7523 authorization-grant assertion was replayed: its issuer and jti are already in the used-assertion history, spent or held by a request in flight, as a grant or as a client assertion. invalid_grant (HTTP 400)
STS-OAUTH-0055 The used-assertion history for the realm holds oauth2.assertionReplayCacheSize unexpired rows, so a new RFC 7523 grant was refused rather than a live row forgotten. invalid_grant (HTTP 400)
STS-OAUTH-0056 An RFC 7522 SAML 2.0 bearer grant was requested while oauth2.saml2BearerGrant is off. unsupported_grant_type (HTTP 400)
STS-OAUTH-0057 An RFC 7522 SAML assertion was missing or would not decode from base64url XML. invalid_request (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0058 An encrypted RFC 7522 SAML assertion would not decrypt. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0059 An RFC 7522 SAML document would not parse as a SAML 2.0 Assertion. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0060 An RFC 7522 SAML assertion carries a Version other than 2.0. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0061 An RFC 7522 SAML assertion carries no Issuer (section 3 item 1). invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0062 An RFC 7522 SAML assertion names an Issuer no application in the realm has declared as oauthSamlAssertionIssuer. invalid_grant (HTTP 400)
STS-OAUTH-0063 The certificates registered for an RFC 7522 assertion issuer or client could not be read. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0064 No RFC 7522 certificate is registered for the assertion issuer or client, so its SAML assertion could not be verified. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0065 An RFC 7522 SAML assertion carries no signature of its own (section 3 item 9). invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0066 An RFC 7522 SAML assertion’s KeyInfo certificate is not one registered for RFC 7522 against its issuer or client. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0067 An RFC 7522 SAML assertion’s signature did not verify against any registered certificate. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0068 An RFC 7522 SAML assertion carries a Condition this authorization server cannot evaluate. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0069 A timestamp in an RFC 7522 SAML assertion (NotBefore, NotOnOrAfter or IssueInstant) is not an xsd:dateTime. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0070 An RFC 7522 SAML assertion is not yet valid (Conditions NotBefore). invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0071 An RFC 7522 SAML assertion has expired (Conditions NotOnOrAfter). invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0072 An RFC 7522 SAML assertion carries no AudienceRestriction (section 3 item 2). invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0073 An RFC 7522 SAML assertion is addressed to an audience that is not this token endpoint. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0074 An RFC 7522 SAML assertion has no usable Subject NameID (section 3 item 3). invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0075 An RFC 7522 SAML client assertion’s Subject is not the client_id (section 3 item 3B). invalid_client (HTTP 401)
STS-OAUTH-0076 An RFC 7522 SAML assertion carries no bearer SubjectConfirmation (section 3 item 5). invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0077 None of an RFC 7522 SAML assertion’s bearer SubjectConfirmations is usable (expired, or no matching Recipient). invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0078 An RFC 7522 SAML assertion has no expiry at all (section 3 item 4). invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0079 An RFC 7522 SAML assertion’s IssueInstant is in the future beyond the allowed clock skew. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0080 An RFC 7522 SAML assertion is valid for longer than oauth2.saml2BearerMaxLifetimeS allows. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0081 An RFC 7522 SAML assertion carries no ID, so it could not be spent. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0082 An RFC 7522 SAML assertion was replayed: its Issuer and ID are already in the used-assertion history, spent or held by a request in flight, under either section. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0083 The used-assertion history for the realm holds oauth2.assertionReplayCacheSize unexpired rows, so a new SAML assertion was refused rather than a live row forgotten. invalid_grant (HTTP 400) or invalid_client (HTTP 401)
STS-OAUTH-0084 The person-assertion register was handed an incomplete directory slot at startup and refused it whole, so no person can hold an RFC 7523 key pair in this process. —
STS-OAUTH-0085 A person’s RFC 7523 key pair could not be stored because this process has no directory. —
STS-OAUTH-0086 A person’s RFC 7523 private key could not be sealed under the key-encryption key; nothing was written and the issued key pair is lost. —
STS-OAUTH-0087 An attribute of a person’s RFC 7523 key pair could not be written to their directory entry; the issued key pair is lost. —
STS-OAUTH-0088 A person’s sealed RFC 7523 private key will not open under this process’s key-encryption key (it was sealed under a different one). —
STS-OAUTH-0089 Taking a person’s RFC 7523 key pair off was refused: this process has no directory, or no person was named. —
STS-OAUTH-0090 Taking a person’s RFC 7523 key pair off was refused: nobody by that name holds one. —
STS-OAUTH-0091 A certificate-bound token (cnf x5t#S256) was presented on a connection carrying no client certificate (RFC 8705 section 3.1). invalid_token (HTTP 401 at a protected endpoint; HTTP 400 invalid_grant at the refresh grant)
STS-OAUTH-0092 A certificate-bound token was presented on a connection made with a different client certificate (RFC 8705 section 3.1). invalid_token (HTTP 401 at a protected endpoint; HTTP 400 invalid_grant at the refresh grant)
STS-OAUTH-0093 A DPoP proof was required and none was presented. invalid_dpop_proof (HTTP 400 at the token endpoint, HTTP 401 at a protected endpoint)
STS-OAUTH-0094 More than one DPoP header field was sent (RFC 9449 permits exactly one). invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0095 The DPoP proof is not a compact JWS with three parts. invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0096 The DPoP proof could not be base64url-decoded. invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0097 The DPoP proof’s header or payload is not a JSON object. invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0098 The DPoP proof’s typ is not dpop+jwt. invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0099 The DPoP proof is signed with an algorithm this server does not accept (none, a MAC, or unregistered). invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0100 The DPoP proof header carries no jwk public key. invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0101 The DPoP proof header’s jwk carries private key material. invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0102 The DPoP proof header’s jwk key type or curve does not match its alg. invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0103 The DPoP proof is missing one of jti, htm, htu or iat. invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0104 The DPoP proof’s signature does not verify with the key in its own header. invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0105 The DPoP proof’s htm does not match the request method. invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0106 The DPoP proof’s htu does not match the request URI (commonly a TLS-terminating proxy with global.trustProxy off). invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0107 The DPoP proof’s iat is outside the accepted clock window (oauth2.dpopIatSkewS). invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0108 Nonce mode is on and the DPoP proof carried no nonce; the client is sent one to retry with. use_dpop_nonce (HTTP 400 at the token endpoint, HTTP 401 at a protected endpoint)
STS-OAUTH-0109 The DPoP proof’s nonce is not one this server issued, or it has expired. use_dpop_nonce (HTTP 400 / 401)
STS-OAUTH-0110 The DPoP proof was replayed: its jti has already been used. invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0111 A DPoP proof accompanying an access token carries no ath. invalid_dpop_proof (HTTP 401)
STS-OAUTH-0112 A DPoP proof’s ath does not match the access token presented with it. invalid_dpop_proof (HTTP 401)
STS-OAUTH-0113 A DPoP-bound token was presented with a proof signed by a key other than the one in its cnf.jkt. invalid_dpop_proof (HTTP 401)
STS-OAUTH-0114 An access token this service issued does not name this resource server as its audience — compared whole against the address the request arrived on since 2026-09-13 (RFC 9068 section 4, RFC 9700 section 2.3). invalid_token (HTTP 401)
STS-OAUTH-0115 In RFC 9700 mode, an access token was sent in the URI query string (section 4.3.2). invalid_request (HTTP 400)
STS-OAUTH-0116 A protected endpoint was called with no Bearer or DPoP access token. invalid_token (HTTP 401, WWW-Authenticate challenge)
STS-OAUTH-0117 A DPoP-bound access token was presented with the Bearer scheme. invalid_token (HTTP 401)
STS-OAUTH-0118 A DPoP proof was refused for a reason the verifier did not name (fallback; the verifier normally names one of STS-OAUTH-0093 to -0113). invalid_dpop_proof (HTTP 400 at the token endpoint, HTTP 401 at a protected endpoint)
STS-OAUTH-0119 In RFC 9700 mode, the authorization request’s redirect_uri does not parse as an absolute URI; nothing is redirected. invalid_request (HTTP 400, not redirected)
STS-OAUTH-0120 In RFC 9700 mode, the redirect_uri uses http on a host that is not a loopback address (section 2.6). invalid_request (HTTP 400, not redirected)
STS-OAUTH-0121 In RFC 9700 mode, no redirect URIs are registered for the client, so the redirect_uri cannot be exact-matched. invalid_request (HTTP 400, not redirected)
STS-OAUTH-0122 In RFC 9700 mode, the redirect_uri matches none of the URIs registered for the client (section 2.1). invalid_request (HTTP 400, not redirected)
STS-OAUTH-0123 An RP-Initiated Logout post_logout_redirect_uri is not among the ones the client registered — in every mode since #124 — so it is not followed; the person is signed out and told on the page. none (the sign-out page says so)
STS-OAUTH-0124 In RFC 9700 mode, a state, code_challenge or nonce value already used by another client was presented (section 2.1.1). invalid_request (redirected error)
STS-OAUTH-0125 In RFC 9700 mode, a state, code_challenge or nonce value was reused after its authorization code was redeemed. invalid_request (redirected error)
STS-OAUTH-0126 In RFC 9700 mode, the authorization request asked for a response type that issues an access token from the authorization endpoint (section 2.1.2). unsupported_response_type (redirected error)
STS-OAUTH-0127 In RFC 9700 mode, a public client sent an authorization-code request with no PKCE code_challenge. invalid_request (redirected error)
STS-OAUTH-0128 In RFC 9700 mode, the code_challenge_method is not S256. invalid_request (redirected error)
STS-OAUTH-0129 In RFC 9700 mode, an S256 code_challenge is not 43 base64url characters. invalid_request (redirected error)
STS-OAUTH-0130 In RFC 9700 mode, a response type naming id_token was requested with no nonce. invalid_request (redirected error)
STS-OAUTH-0131 In RFC 9700 mode, the resource owner password credentials grant was requested (section 2.4). unsupported_grant_type (HTTP 400)
STS-OAUTH-0132 In RFC 9700 mode, a dynamic client registration asked for the password grant. invalid_client_metadata (HTTP 400)
STS-OAUTH-0133 In RFC 9700 mode, a dynamic client registration asked for the implicit grant. invalid_client_metadata (HTTP 400)
STS-OAUTH-0134 In RFC 9700 mode, a dynamic client registration asked for a response type that issues an access token. invalid_client_metadata (HTTP 400)
STS-OAUTH-0135 In RFC 9700 mode, a dynamic client registration carried a redirect URI that is not absolute. invalid_redirect_uri (HTTP 400)
STS-OAUTH-0136 In RFC 9700 mode, a dynamic client registration carried an http redirect URI off the loopback address. invalid_redirect_uri (HTTP 400)
STS-OAUTH-0137 A confidential client failed client authentication at the token endpoint and the verifier did not name a more specific cause (fallback; normally one of STS-OAUTH-0001 to -0083). invalid_client (HTTP 401)
STS-OAUTH-0138 In RFC 9700 mode, an already-redeemed refresh token was presented again; its whole family was revoked (section 2.2.2). invalid_grant (HTTP 400)
STS-OAUTH-0139 In RFC 9700 mode, a refresh token’s grant had been idle longer than oauth2.refreshIdleSeconds. invalid_grant (HTTP 400)
STS-OAUTH-0140 In RFC 9700 mode, a refresh request carried no client_id. invalid_request (HTTP 400)
STS-OAUTH-0141 A refresh token was presented by a client other than the one it was issued to (RFC 6749 section 6; every mode since #187). invalid_grant (HTTP 400)
STS-OAUTH-0142 A refresh request asked for scope the original grant did not carry (RFC 6749 section 6; every mode since #187). invalid_scope (HTTP 400)
STS-OAUTH-0143 An authorization code was presented a second time; the tokens it bought were revoked (RFC 6749 section 4.1.2, RFC 9700 section 4.5; every mode since #187 unless oauth2.codeReplayIdempotent). invalid_grant (HTTP 400)
STS-OAUTH-0144 In RFC 9700 mode, an authorization request named no client_id; it is answered rather than redirected (section 4.11.2). invalid_request (HTTP 400, not redirected)
STS-OAUTH-0145 In RFC 9700 mode, a code_verifier arrived for an authorization code issued without a code_challenge (PKCE downgrade, section 4.8.2). invalid_grant (HTTP 400)
STS-OAUTH-0146 In RFC 9700 mode, an authorization code was redeemed by a client other than the one it was issued to. invalid_grant (HTTP 400)
STS-OAUTH-0147 In RFC 9700 mode, the Token Request omitted the redirect_uri the authorization request carried. invalid_grant (HTTP 400)
STS-OAUTH-0148 The consent screen was reached with a malformed query or form (the input validator refused it). invalid_request (HTTP 400)
STS-OAUTH-0149 The consent screen was reached with a consent id that is not pending: expired, already answered, or never issued. invalid_request (HTTP 400)
STS-OAUTH-0150 A consent was answered from a browser with no sign-on session any more, so there is nobody to record it for. invalid_request (HTTP 400)
STS-OAUTH-0151 A consent was answered from a browser signed in as somebody other than the person it was asked of. invalid_request (HTTP 400)
STS-OAUTH-0152 The person declined consent on the consent screen; nothing was issued and the client is told access_denied. access_denied (HTTP 303 back to the authorization endpoint, then redirected to the client)
STS-OAUTH-0153 The authorization_details parameter is not readable JSON, not an array, names an unsupported type, or names a credential configuration this issuer does not offer. invalid_authorization_details (redirected error, or HTTP 400 at the token endpoint)
STS-OAUTH-0154 An RFC 8707 resource parameter is not an absolute URI or carries a fragment. invalid_target (redirected error, or HTTP 400 at the token endpoint)
STS-OAUTH-0155 A scope named a delegated permission the client has not been granted — in product mode always, in development when oauth2.delegatedPermissionsEnforced is on. invalid_scope (redirected error, or HTTP 400 at the token endpoint)
STS-OAUTH-0156 The issuance policy (the role gate) refused to issue an authorization code to this person for this application. access_denied (redirected error)
STS-OAUTH-0157 The OpenID Connect Core 5.5 claims request on an authorization request is malformed. invalid_request (redirected error)
STS-OAUTH-0158 RFC 9700 mode refused a request for a reason the policy did not name (fallback; the policy normally names one of STS-OAUTH-0119 to -0147). the error the RFC 9700 check named (HTTP 400 or redirected)
STS-OAUTH-0159 The authorization request is malformed (the input validator refused it); answered here rather than redirected. invalid_request (HTTP 400)
STS-OAUTH-0160 The authorization request has no redirect_uri, so the error cannot be redirected. (What is usable is the schema’s question since 2026-09-13; a value it refuses is STS-OAUTH-0159.) invalid_request (HTTP 400)
STS-OAUTH-0161 The authorization request named no client_id. invalid_request (redirected error, or HTTP 400 page before sign-in)
STS-OAUTH-0162 The authorization request asked for a response_type this service does not implement. unsupported_response_type (redirected error, or HTTP 400 page)
STS-OAUTH-0163 The authorization request asked for a response_type this authorization server profile does not advertise. unsupported_response_type (redirected error, or HTTP 400 page)
STS-OAUTH-0164 The authorization request asked for a response_mode this authorization server profile does not advertise. invalid_request (redirected error, or HTTP 400 page)
STS-OAUTH-0165 The authorization request asked for a code_challenge_method this authorization server profile does not advertise. invalid_request (redirected error, or HTTP 400 page)
STS-OAUTH-0166 The sign-in screen reported that authentication did not complete, and the authorization endpoint relayed that to the client. the error the sign-in screen named, e.g. access_denied (redirected error)
STS-OAUTH-0167 The consent screen reported a refusal, and the authorization endpoint relayed it to the client. the error the consent screen named, e.g. access_denied (redirected error)
STS-OAUTH-0168 Consent is outstanding and the request carried prompt=none, which forbids showing the consent screen. consent_required (redirected error)
STS-OAUTH-0169 The authorization response could not be issued because of an unexpected failure while minting it. server_error (redirected error, or HTTP 400 page)
STS-OAUTH-0170 The request carried prompt=none and there is no sign-on session. login_required (redirected error, or HTTP 400 page)
STS-OAUTH-0171 An RP-Initiated Logout request is malformed (the input validator refused it). Since #124 the session is NOT ended, and the answer is a page for the person. HTTP 400 (an HTML page)
STS-OAUTH-0172 An access token presented at UserInfo did not verify: expired, not yet valid, or not issued by this service. invalid_token (HTTP 401, WWW-Authenticate challenge)
STS-OAUTH-0173 The token presented at UserInfo is not an access token (its typ is not Bearer). invalid_token (HTTP 401, WWW-Authenticate challenge)
STS-OAUTH-0174 The access token presented at UserInfo has been revoked. invalid_token (HTTP 401, WWW-Authenticate challenge)
STS-OAUTH-0175 The access token presented at UserInfo was not issued with the openid scope. insufficient_scope (HTTP 403, WWW-Authenticate challenge)
STS-OAUTH-0176 A claims request sent directly to UserInfo is malformed. invalid_request (HTTP 400, WWW-Authenticate challenge)
STS-OAUTH-0177 The client’s registered UserInfo signing or encryption could not be applied (unusable algorithm, or no usable recipient key). server_error (HTTP 500)
STS-OAUTH-0178 POST /dpop/nonce-mode was refused because the realm is in product mode, where test controls are closed. access_denied (HTTP 403)
STS-OAUTH-0179 POST /dpop/nonce-mode carried something other than required=true or required=false. invalid_request (HTTP 400)
STS-OAUTH-0180 The DPoP nonce setting could not be written. server_error (HTTP 500)
STS-OAUTH-0181 The directory threw while a person’s profile claims were being read; the claims were omitted from what was issued. —
STS-OAUTH-0182 A token this service had just issued could not be re-read for its jti, so the delegation register records no identifier for it. —
STS-OAUTH-0183 The RFC 8414 signed_metadata document could not be signed; the metadata was published without it. —
STS-OAUTH-0184 The JWKS could not be published (a signing key could not be made or exported). HTTP 500
STS-OAUTH-0185 An Authorization: Basic header on a Token Request could not be decoded; the form parameters are read instead. —
STS-OAUTH-0186 A path naming an authorization server profile is malformed. invalid_request (HTTP 400)
STS-OAUTH-0187 A Token Request presented an authorization code this service holds no record of: never issued, issued before a restart, or issued by another authorization server. invalid_grant (HTTP 400)
STS-OAUTH-0188 An already-redeemed authorization code was presented again in a request that differs from the one it was redeemed with. invalid_grant (HTTP 400)
STS-OAUTH-0189 An already-redeemed authorization code was presented again after its own lifetime had run out. invalid_grant (HTTP 400)
STS-OAUTH-0190 The jti of a token issued for an authorization code could not be read, so it could not be revoked on a replay. —
STS-OAUTH-0191 The issuance policy (the role gate) refused a token the token endpoint was about to issue. access_denied (HTTP 400)
STS-OAUTH-0192 In product mode, a Token Request came from a client that did not authenticate, and no more specific cause was named (fallback). invalid_client (HTTP 401)
STS-OAUTH-0193 In product mode, a Token Request named a client this service has no entry for, so it could not authenticate. invalid_client (HTTP 401)
STS-OAUTH-0194 A Token Request came from a PUBLIC client (token_endpoint_auth_method none), which presented no credential — correctly. An OBSERVATION, recorded so the role gate and /admin/delegation know what the client is; since 2026-09-17 no mode refuses on it, because product mode allows public clients and holds them to RFC 9700 instead. It read “product mode has no public clients” and was answered 401 until then. none — an observation; the request is answered
STS-OAUTH-0195 In product mode, a confidential client has nothing on its entry to authenticate it against. invalid_client (HTTP 401)
STS-OAUTH-0196 A Token Request is malformed (the input validator refused it). invalid_request (HTTP 400)
STS-OAUTH-0197 A Token Request asked for a grant type this authorization server profile does not advertise. unsupported_grant_type (HTTP 400)
STS-OAUTH-0198 A client is configured for a token endpoint authentication method this authorization server profile does not advertise. invalid_client (HTTP 400)
STS-OAUTH-0199 A Token Request presented an authorization code that has expired. invalid_grant (HTTP 400)
STS-OAUTH-0200 An authorization code was redeemed at a different authorization server profile from the one that issued it. invalid_grant (HTTP 400)
STS-OAUTH-0201 A Token Request’s redirect_uri does not match the one on the authorization request. invalid_grant (HTTP 400)
STS-OAUTH-0202 An authorization code issued with PKCE was redeemed without a code_verifier. invalid_grant (HTTP 400)
STS-OAUTH-0203 A code_verifier does not match the authorization code’s code_challenge. invalid_grant (HTTP 400)
STS-OAUTH-0204 An authorization code bound to a DPoP key (dpop_jkt) was redeemed without a DPoP proof. invalid_grant (HTTP 400)
STS-OAUTH-0205 An authorization code bound to a DPoP key was redeemed with a proof from a different key. invalid_grant (HTTP 400)
STS-OAUTH-0206 A Token Request asked for an RFC 8707 resource the authorization code does not carry. invalid_target (HTTP 400)
STS-OAUTH-0207 An OpenID4VCI pre-authorized code is unknown or already used. invalid_grant (HTTP 400)
STS-OAUTH-0208 An OpenID4VCI pre-authorized code has expired. invalid_grant (HTTP 400)
STS-OAUTH-0209 An OpenID4VCI pre-authorized code requires a Transaction Code and none was sent. invalid_grant (HTTP 400)
STS-OAUTH-0210 An OpenID4VCI Transaction Code was wrong on the last allowed attempt, so the pre-authorized code was spent. invalid_grant (HTTP 400)
STS-OAUTH-0211 An OpenID4VCI Transaction Code was wrong. invalid_grant (HTTP 400)
STS-OAUTH-0212 A pre-authorized code Token Request’s authorization_details names a credential configuration the offer did not. invalid_authorization_details (HTTP 400)
STS-OAUTH-0213 A refresh token did not verify (bad signature, expired, or not issued here). invalid_grant (HTTP 400)
STS-OAUTH-0214 A refresh token has been revoked. invalid_grant (HTTP 400)
STS-OAUTH-0215 A DPoP-bound refresh token was presented without a DPoP proof. invalid_grant (HTTP 400)
STS-OAUTH-0216 A DPoP-bound refresh token was presented with a proof from a different key. invalid_grant (HTTP 400)
STS-OAUTH-0217 A refresh request asked for an RFC 8707 resource the original grant does not carry. invalid_target (HTTP 400)
STS-OAUTH-0218 A password grant request is missing its username or password. invalid_request (HTTP 400)
STS-OAUTH-0219 A password grant was rate limited: too many attempts for the account or the address. invalid_grant (HTTP 400, Retry-After)
STS-OAUTH-0220 A password grant’s credentials did not verify. invalid_grant (HTTP 400)
STS-OAUTH-0221 A password grant was refused because the person holds a second factor, which the grant cannot carry. invalid_grant (HTTP 400)
STS-OAUTH-0222 An RFC 7523 JWT bearer grant was refused for a reason the verifier did not name (fallback; normally one of STS-OAUTH-0026 to -0055). the error the verifier named (HTTP 400)
STS-OAUTH-0223 An RFC 7522 SAML 2.0 bearer grant was refused for a reason the verifier did not name (fallback; normally one of STS-OAUTH-0056 to -0083). the error the verifier named (HTTP 400)
STS-OAUTH-0224 An RFC 8693 token exchange request carried no subject_token. invalid_request (HTTP 400)
STS-OAUTH-0225 An RFC 8693 subject_token could not be read at all; the exchange continues with an empty subject. —
STS-OAUTH-0226 An RFC 8693 actor_token could not be read; the exchange continues without an actor. —
STS-OAUTH-0227 A Token Request named a grant_type this service does not implement. unsupported_grant_type (HTTP 400)
STS-OAUTH-0228 The token endpoint failed with an unexpected exception. server_error (HTTP 500)
STS-OAUTH-0229 An RFC 7662 introspection request is malformed (the input validator refused it). invalid_request (HTTP 400)
STS-OAUTH-0230 An RFC 7009 revocation request is malformed (the input validator refused it). invalid_request (HTTP 400)
STS-OAUTH-0231 Dynamic client registration was refused: the realm is in product mode and oauth2.openRegistration is off. access_denied (HTTP 403)
STS-OAUTH-0232 A dynamic client registration document was refused by the input validator. invalid_client_metadata (HTTP 400)
STS-OAUTH-0233 A dynamic client registration’s redirect_uris is not an array. invalid_redirect_uri (HTTP 400)
STS-OAUTH-0234 A client configuration endpoint path names a malformed client_id. invalid_request (HTTP 400)
STS-OAUTH-0235 The client configuration endpoint was asked about a client that does not exist; since #120 the registration access token is revoked and the answer is RFC 7592 section 3’s. HTTP 401 {error: invalid_token}
STS-OAUTH-0236 The registration access token presented at the client configuration endpoint does not match. invalid_token (HTTP 401, WWW-Authenticate challenge)
STS-OAUTH-0237 A refresh token was presented unencrypted. Every refresh token this service issues is a signed JWT encrypted to its realm, so a plain signed one is refused (or reported inactive at introspection). invalid_grant (HTTP 400); active: false at introspection
STS-OAUTH-0238 A refresh token could not be decrypted: it is not a compact JWE, names a key this realm does not hold (another realm, or keys since rotated), or its authentication tag did not verify. invalid_grant (HTTP 400); active: false at introspection
STS-OAUTH-0239 A refresh token decrypted to something that is not a signed JWT (its JWE did not carry cty JWT around a JWS). invalid_grant (HTTP 400)
STS-OAUTH-0240 A refresh token could not be encrypted at issuance, or the realm’s refresh-token encryption keys could not be read; no refresh token was issued. server_error (HTTP 500)
STS-OAUTH-0241 oauth2.refreshTokenEncryptionAlg or …Enc names an algorithm common/crypto.js does not implement; refresh tokens were encrypted with the default instead. —
STS-OAUTH-0242 An RFC 7522 SAML 2.0 bearer grant was signed by a PERSON’s registered RFC 7522 key pair and its names somebody other than that person; a person's key may only assert about themselves. invalid_grant (HTTP 400)
STS-OAUTH-0243 An RFC 7523 or RFC 7522 assertion verified and the used-assertion history could not be consulted or written, so it was refused: an assertion this service cannot prove unused is not one it accepts. invalid_client (HTTP 401) or invalid_grant (HTTP 400)
STS-OAUTH-0244 RFC 9068 section 3: the scope named more than one resource (two applications, or delegated permissions of two APIs), so a JWT access token would carry scopes whose resource is ambiguous; no token or code was issued. invalid_scope (redirected error, or HTTP 400 at the token endpoint)
STS-OAUTH-0245 RFC 9068 section 2.2.3: the request addressed one set of resources (resource, audience, or what a refresh token remembers) while its scope named a different application or API. invalid_scope (redirected error, or HTTP 400 at the token endpoint)
STS-OAUTH-0246 RFC 9068 section 3: the request addressed several resources and carried a scope that cannot be tied to exactly one of them (neither a delegated permission of one, nor an OpenID Connect scope with this service among them). invalid_target (redirected error, or HTTP 400 at the token endpoint)
STS-OAUTH-0247 RFC 9068 section 4: a token this service signed was presented to one of its resource servers (UserInfo, the OID4VCI credential endpoints, SCIM, SSF) with a typ header that is not at+jwt — an ID Token, another JWT, or an access token minted before at+jwt. invalid_token (HTTP 401), or the surface’s own 401
STS-OAUTH-0248 RFC 9068 section 4: a token this service signed names an iss that is not an issuer this service publishes at the address the request arrived on (the default authorization server or a named one). invalid_token (HTTP 401), or the surface’s own 401
STS-OAUTH-0270 An authorization request asked for response_mode=form_post at a native application’s private-use redirect URI, which a protocol handler can never receive a POST body at, so it was answered here rather than redirected (every mode). invalid_request (HTTP 400)
STS-OAUTH-0271 OAuth 2.1 mode: the authorization request names a client with no redirect URI of its own (section 2.3.1); oauth2.redirectUris is not read in that mode. invalid_request (HTTP 400)
STS-OAUTH-0272 OAuth 2.1 mode: the client’s only redirect URIs are addresses development observed and nobody confirmed, which product mode withholds. invalid_request (HTTP 400)
STS-OAUTH-0273 OAuth 2.1 mode: the authorization request named no redirect_uri and the client has registered more than one, so the parameter is required (section 4.1.1). invalid_request (HTTP 400)
STS-OAUTH-0274 OAuth 2.1 mode: the authorization request named no redirect_uri and the one URI registered for the client is not a usable redirect URI (it was put on the entry without passing any check). invalid_request (HTTP 400)
STS-OAUTH-0275 OAuth 2.1 mode: an authorization request issuing a code carried no code_challenge and does not meet the OpenID Connect nonce exemption (a confidential client with a credential on file, openid, a nonce) — section 7.5.1.1. invalid_request (HTTP 400, redirected once the redirect_uri is validated)
STS-OAUTH-0276 OAuth 2.1 mode: code_challenge was sent with no code_challenge_method, which that specification makes REQUIRED. invalid_request (HTTP 400, redirected)
STS-OAUTH-0277 OAuth 2.1 mode: an authorization code with no code_challenge was presented — either not issued under the nonce exemption, or issued under it and redeemed without client authentication (section 4.1.3). invalid_grant (HTTP 400)
STS-OAUTH-0278 OAuth 2.1 mode: a token request names a client whose entry declares nothing — never registered, or only ever sighted. invalid_client (HTTP 401)
STS-OAUTH-0279 OAuth 2.1 mode: the client credentials grant was asked for by a client that did not authenticate (section 4.2). invalid_client (HTTP 401)
STS-OAUTH-0280 OAuth 2.1 mode: the token request included client authentication that did not verify against anything on file — a public or unknown client sending a secret, or a credential that failed (section 3.2.2). invalid_client (HTTP 401)
STS-OAUTH-0281 OAuth 2.1 mode: a token or introspection request carried more than one client authentication method (section 2.4). invalid_request (HTTP 400)
STS-OAUTH-0282 OAuth 2.1 mode: SAML bearer client authentication, which draft-ietf-oauth-rfc7523bis-11 says must not be used for client authentication. invalid_client (HTTP 401)
STS-OAUTH-0283 OAuth 2.1 mode: a JWT client assertion does not name the issuer identifier as its sole audience (draft-ietf-oauth-rfc7523bis-11). invalid_client (HTTP 401)
STS-OAUTH-0284 Too many failed client-secret authentications for one client from one address in this realm, so the token request was refused before the secret was checked (wherever secrets are checked). invalid_client (HTTP 429, Retry-After)
STS-OAUTH-0285 OAuth 2.1 mode: a request parameter was repeated at the authorization or token endpoint (sections 3.1 and 3.2). invalid_request (HTTP 400)
STS-OAUTH-0286 OAuth 2.1 mode: a post_logout_redirect_uri was given for a client that registered none of its own; oauth2.redirectUris is not read in that mode. invalid_request (HTTP 400)
STS-OAUTH-0287 OAuth 2.1 mode: a client registration asked for token_endpoint_auth_method=saml2_bearer. invalid_client_metadata (HTTP 400)
STS-OAUTH-0288 A stored frontchannel_logout_uri is not an http or https URL, so the client was not notified and the value was not framed. none — the client is listed as not notified
STS-OAUTH-0289 OAuth 2.1 mode: a client registration asked for the client credentials grant with token_endpoint_auth_method=none. invalid_client_metadata (HTTP 400)
STS-OAUTH-0290 A private-use post_logout_redirect_uri was given and the client the request names has not registered it (every mode since #124): not followed. none (the sign-out page says so)
STS-OAUTH-0291 An RFC 9701 JWT introspection request (Accept: application/token-introspection+jwt) did not authenticate the resource server: no credential, an unknown or public client, nothing on file to verify, or a credential that did not verify. Refused in every mode, because the response is addressed to the caller. invalid_client (HTTP 400, RFC 9701 section 5)
STS-OAUTH-0292 Product mode: an RFC 7662 introspection request did not authenticate the caller as a client with a credential that verified. invalid_client (HTTP 401, RFC 7662 section 2.3)
STS-OAUTH-0293 The JWT introspection response a client registered could not be produced: an algorithm this service does not have (set by ldapmodify), an enc with no alg, no usable key in its jwks, or the signature failed. server_error (HTTP 500)
STS-OAUTH-0294 The introspection endpoint failed with an unexpected error outside every refusal it makes. server_error (HTTP 500)
STS-OAUTH-0295 A client authenticating at the introspection endpoint declares a token_endpoint_auth_method the selected authorization server does not list in introspection_endpoint_auth_methods_supported. invalid_client (HTTP 400 for a JWT request, 401 for JSON)
STS-OAUTH-0296 A resource server’s registered (or default) RFC 9701 introspection response algorithm is not one the selected authorization server advertises in its introspection_*_values_supported members. invalid_client (HTTP 400)
STS-OAUTH-0297 In OAuth 2.1 mode, a grant a client makes in its own name (authorization_code, refresh_token, client_credentials, token exchange) named no client_id at all. invalid_client (HTTP 401)
STS-OAUTH-0298 In OAuth 2.1 mode, an RFC 7523 or RFC 7522 assertion grant arrived with no client, so it was answered with an access token and NO refresh token (recorded, not refused). none — the token response is issued without refresh_token
STS-OAUTH-0299 In OAuth 2.1 mode, an RFC 7523 or RFC 7522 assertion grant named a client that is not registered or declared here. invalid_client (HTTP 401)
STS-OAUTH-0300 A software statement (RFC 7591 section 2.3) presented at registration is not a string holding a compact JWS — it is missing its three segments, or it is a JWE. invalid_software_statement (HTTP 400)
STS-OAUTH-0301 A software statement’s JOSE header or claims are not JSON objects. invalid_software_statement (HTTP 400)
STS-OAUTH-0302 A software statement says alg “none” (RFC 7591 section 2.3 requires it to be signed or MACed). invalid_software_statement (HTTP 400)
STS-OAUTH-0303 A software statement is signed with an algorithm this service does not verify statements with — an HMAC, for which no shared key exists, or an unknown one. invalid_software_statement (HTTP 400)
STS-OAUTH-0304 A software statement carries no iss claim (RFC 7591 section 2.3). invalid_software_statement (HTTP 400)
STS-OAUTH-0305 A software statement names an issuer this authorization server publishes and is not typed software-statement+jwt, so it is one of this service’s other tokens. invalid_software_statement (HTTP 400)
STS-OAUTH-0306 A software statement from a declared publisher carries an x5c certificate that chains to this realm and was issued to somebody other than that publisher. unapproved_software_statement (HTTP 400)
STS-OAUTH-0307 A software statement’s issuer is declared by an application that holds no key a statement can be verified with (no usable jwks, no key pair from /admin/pki). unapproved_software_statement (HTTP 400)
STS-OAUTH-0308 A software statement’s issuer is not declared in any application’s oauthSoftwareStatementIssuer, and oauth2.softwareStatementRequireTrustedIssuer is on. unapproved_software_statement (HTTP 400)
STS-OAUTH-0309 A software statement’s signature did not verify under any of its issuer’s keys, or it has expired or is not yet valid. invalid_software_statement (HTTP 400)
STS-OAUTH-0310 The registered certificate of the key that verified a software statement has a trust chain that does not hold. invalid_software_statement (HTTP 400)
STS-OAUTH-0311 A software statement’s iat is in the future beyond oauth2.clientAssertionSkewS. invalid_software_statement (HTTP 400)
STS-OAUTH-0312 A software statement carries an aud that names neither this authorization server’s issuer nor its registration endpoint. invalid_software_statement (HTTP 400)
STS-OAUTH-0313 A verified software statement’s claims were refused by the input validator. invalid_software_statement (HTTP 400)
STS-OAUTH-0314 A registration carried no software statement while oauth2.softwareStatementRequired is on. invalid_software_statement (HTTP 400)
STS-OAUTH-0315 An RFC 7592 update of a client that registered on the strength of a trusted software statement, at an endpoint otherwise closed, did not carry a trusted statement from the same issuer. unapproved_software_statement (HTTP 400)
STS-OAUTH-0340 An authorization request carried no request object where a signed one is required (oauth2.requireSignedRequestObject, the client’s require_signed_request_object, or the authorization server’s profile; RFC 9101 section 10.5). invalid_request (HTTP 400)
STS-OAUTH-0341 An authorization request carried both request and request_uri, or repeated one of them (RFC 9101 section 5). invalid_request (HTTP 400)
STS-OAUTH-0342 A request object was sent by value to an authorization server whose metadata says request_parameter_supported false. request_not_supported (HTTP 400)
STS-OAUTH-0343 A request object was sent by reference to an authorization server whose metadata says request_uri_parameter_supported false. request_uri_not_supported (HTTP 400)
STS-OAUTH-0344 An authorization request carried a request object and no client_id query parameter (RFC 9101 section 5). invalid_request (HTTP 400)
STS-OAUTH-0345 A request_uri is not one the client registered in request_uris, so it was refused and never fetched (RFC 9101 section 10.4). invalid_request_uri (HTTP 400)
STS-OAUTH-0346 A registered request_uri may not be fetched in this mode: plain http in product mode, or otherwise unusable. invalid_request_uri (HTTP 400)
STS-OAUTH-0347 A registered request_uri could not be fetched: a non-200 answer (a redirect included, which is not followed), a timeout, a network error, or more than oauth2.requestUriMaxBytes. invalid_request_uri (HTTP 400)
STS-OAUTH-0348 A registered request_uri answered with a media type other than application/oauth-authz-req+jwt or application/jwt, in product mode. invalid_request_uri (HTTP 400)
STS-OAUTH-0349 A request_uri’s fragment is a SHA-256 of different content from what it answered with (OpenID Connect Core section 6.2). invalid_request_uri (HTTP 400)
STS-OAUTH-0350 A request object’s encryption is not what the client registered: unencrypted where request_object_encryption_alg is registered, or a different alg or enc. invalid_request_object (HTTP 400)
STS-OAUTH-0351 A request object is encrypted with an algorithm or content encryption the selected authorization server does not decrypt. invalid_request_object (HTTP 400)
STS-OAUTH-0352 An encrypted request object has no key here to open it: a symmetric algorithm for a client with no secret, or a kid that is not this realm’s request object encryption key. invalid_request_object (HTTP 400)
STS-OAUTH-0353 An encrypted request object could not be decrypted, or its JWE header is unreadable. invalid_request_object (HTTP 400)
STS-OAUTH-0354 An encrypted request object decrypted to something that is not a JWS (RFC 9101 section 4: signed, then encrypted). invalid_request_object (HTTP 400)
STS-OAUTH-0355 A request object is not a compact JWT, or its header is unreadable. invalid_request_object (HTTP 400)
STS-OAUTH-0356 A request object is typed as another kind of JWT (RFC 9101 section 10.8). invalid_request_object (HTTP 400)
STS-OAUTH-0357 An unsigned request object (alg none) was refused: product mode, or a signed request object is required. invalid_request_object (HTTP 400)
STS-OAUTH-0358 A request object is signed with an algorithm other than the client’s registered request_object_signing_alg. invalid_request_object (HTTP 400)
STS-OAUTH-0359 A request object is signed with an algorithm the selected authorization server does not list in request_object_signing_alg_values_supported. invalid_request_object (HTTP 400)
STS-OAUTH-0360 A request object names a signing algorithm this service does not verify. invalid_request_object (HTTP 400)
STS-OAUTH-0361 A request object cannot be verified: the client holds no key for it (no jwks, only a jwks_uri, or no client secret for HMAC). invalid_request_object (HTTP 400)
STS-OAUTH-0362 A request object’s signature did not verify with any of the client’s keys, or it is expired or not yet valid. invalid_request_object (HTTP 400)
STS-OAUTH-0363 The certificate of the key that verified a request object does not have a valid trust chain. invalid_request_object (HTTP 400)
STS-OAUTH-0364 An unsigned request object’s claims are refused: not a JSON object, expired or not yet valid. invalid_request_object (HTTP 400)
STS-OAUTH-0365 A request object’s iss is not the client that sent it. invalid_request_object (HTTP 400)
STS-OAUTH-0366 A request object’s aud does not name this authorization server (its issuer or its authorization endpoint). invalid_request_object (HTTP 400)
STS-OAUTH-0367 A request object’s client_id claim differs from the client_id query parameter (RFC 9101 section 6.3). invalid_request_object (HTTP 400)
STS-OAUTH-0368 A request object is not explicitly typed oauth-authz-req+jwt and oauth2.requireRequestObjectType requires it. invalid_request_object (HTTP 400)
STS-OAUTH-0369 A request object lacks iss or aud and oauth2.requireRequestObjectIssuerAudience requires both. invalid_request_object (HTTP 400)
STS-OAUTH-0370 A request object’s kid names none of the client’s keys (RFC 9101 section 6.2). invalid_request_object (HTTP 400)
STS-OAUTH-0371 A response_type duplicated in the query differs from the request object’s (OpenID Connect Core section 6.1). invalid_request_object (HTTP 400)
STS-OAUTH-0372 A request_uri is a pushed authorization request URN and there is no pushed authorization request here to resolve it, or it resolved to nothing. request_uri_not_supported or invalid_request_uri (HTTP 400)
STS-OAUTH-0373 The authorization endpoint failed with an unexpected error while resolving a request object. server_error (HTTP 500)
STS-OAUTH-0374 A request object’s jti has been used already: an authorization response was issued on it, or a pushed authorization request kept it, or a response on it is still being written. invalid_request_object (HTTP 400)
STS-OAUTH-0375 A request object’s jti could not be recorded because the used-assertion history for the realm is full of unexpired rows (oauth2.assertionReplayCacheSize). temporarily_unavailable (HTTP 503)
STS-OAUTH-0376 A request object’s jti could not be recorded because the used-assertion history’s store could not be written or asked; nothing is issued on the object. server_error (HTTP 500)
STS-OAUTH-0400 A pushed authorization request arrived while oauth2.pushedAuthorizationRequests is off. invalid_request (HTTP 404)
STS-OAUTH-0401 The pushed authorization request endpoint was called with a method other than POST. HTTP 405 with Allow: POST (RFC 9126 section 2.3)
STS-OAUTH-0402 A pushed authorization request was larger than oauth2.parMaxBodyBytes. HTTP 413 (RFC 9126 section 2.3)
STS-OAUTH-0403 A pushed authorization request was not a form body, was malformed, or repeated a parameter that may not repeat. invalid_request (HTTP 400)
STS-OAUTH-0404 A pushed authorization request carried request_uri, which RFC 9126 section 2.1 says MUST NOT be provided. invalid_request (HTTP 400)
STS-OAUTH-0405 A pushed authorization request named no client — no client_id, no Basic header and no client assertion. invalid_request (HTTP 400)
STS-OAUTH-0406 A pushed authorization request named one client_id in its body and authenticated as another. invalid_request (HTTP 400)
STS-OAUTH-0407 A client pushed more authorization requests from one address in one window than oauth2.parRequestsPerMinute allows. HTTP 429 with Retry-After (RFC 9126 section 2.3)
STS-OAUTH-0408 A push was refused because the realm already holds oauth2.parMaxRequests live pushed requests. temporarily_unavailable (HTTP 503)
STS-OAUTH-0409 A push carrying a request object also carried authorization request parameters in the form body (RFC 9126 section 3). invalid_request (HTTP 400)
STS-OAUTH-0410 A request_uri at the authorization endpoint is not one this authorization server issued at /oauth2/par, or it was swept. invalid_request_uri (HTTP 400 on this server)
STS-OAUTH-0411 A pushed request_uri was used after it expired (oauth2.parRequestUriLifetimeS). invalid_request_uri (HTTP 400 on this server)
STS-OAUTH-0412 A pushed request_uri was used again after an authorization response had been issued on it. invalid_request_uri (HTTP 400 on this server)
STS-OAUTH-0413 A pushed request_uri was used with a client_id other than the client that pushed it. invalid_request_uri (HTTP 400 on this server)
STS-OAUTH-0414 A pushed request_uri was used at a different authorization server from the one it was pushed at. invalid_request_uri (HTTP 400 on this server)
STS-OAUTH-0415 A push carried plain parameters where a signed request object is required (RFC 9126 section 2.3, RFC 9101 section 10.5). invalid_request (HTTP 400)
STS-OAUTH-0416 The DPoP proof sent with a pushed authorization request was refused, or a nonce was required. invalid_dpop_proof or use_dpop_nonce (HTTP 400)
STS-OAUTH-0417 A push carried a DPoP proof and a dpop_jkt naming a different key (RFC 9449 section 10.1). invalid_dpop_proof (HTTP 400)
STS-OAUTH-0419 An authorization request was not pushed, and the setting, the client or the authorization server requires pushed authorization requests (RFC 9126 section 4). invalid_request (HTTP 400 on this server)
STS-OAUTH-0420 The pushed authorization request endpoint failed with an unexpected error. server_error (HTTP 500)
STS-OAUTH-0421 A client pushed an authorization request while configured for an authentication method the selected authorization server does not list in token_endpoint_auth_methods_supported. invalid_client (HTTP 400)
STS-OAUTH-0422 RFC 9700 mode refused a client’s authentication at the pushed authorization request endpoint and named no more specific code. invalid_client (HTTP 401)
STS-OAUTH-0423 Product mode refused an unauthenticated client at the pushed authorization request endpoint. invalid_client (HTTP 401)
STS-OAUTH-0424 An authenticated client pushed a request object that carries no client_id claim (RFC 9126 section 3). invalid_request_object (HTTP 400)
STS-OAUTH-0426 A request_uri pushed as plain parameters was used after a signed request object became required (RFC 9126 section 7.4). invalid_request (HTTP 400 on this server)
STS-OAUTH-0427 An OAuth monitoring counter (/admin/oauth2/monitor) threw or was asked for an event outside its vocabulary; nothing else was affected. none — logged only
STS-OAUTH-0450 authorization_details is not readable JSON, not an array, or carries more entries than oauth2.authorizationDetailsMaxEntries. invalid_authorization_details (HTTP 400, or redirected)
STS-OAUTH-0451 An authorization_details entry is not a JSON object, or has no string type (RFC 9396 section 2). invalid_authorization_details (HTTP 400, or redirected)
STS-OAUTH-0452 An authorization_details entry’s common data field (locations, actions, datatypes, identifier, privileges) has the wrong shape (RFC 9396 section 2.2). invalid_authorization_details (HTTP 400, or redirected)
STS-OAUTH-0453 An authorization_details entry is of a type no application in the realm declares and this service does not understand (RFC 9396 section 5). invalid_authorization_details (HTTP 400, or redirected)
STS-OAUTH-0454 An authorization_details entry is of a type outside the client’s registered authorization_details_types (RFC 9396 section 10). invalid_authorization_details (HTTP 400, or redirected)
STS-OAUTH-0455 An authorization_details entry is of a type the named authorization server does not publish in authorization_details_types_supported. invalid_authorization_details (HTTP 400, or redirected)
STS-OAUTH-0456 An authorization_details entry does not conform to the JSON Schema its type’s definition declares (RFC 9396 section 5). invalid_authorization_details (HTTP 400, or redirected)
STS-OAUTH-0457 An authorization_details entry names a location the resource declaring its type does not answer to. invalid_authorization_details (HTTP 400, or redirected)
STS-OAUTH-0458 A token request’s authorization_details asks for more than the grant authorized (RFC 9396 section 6). invalid_authorization_details (HTTP 400)
STS-OAUTH-0459 A request’s authorization_details address more than one resource server, which one JWT access token cannot carry unambiguously (RFC 9068 section 3). invalid_authorization_details (HTTP 400, or redirected)
STS-OAUTH-0460 A request names a resource or a scope for a different API from the one its authorization_details address. invalid_target or invalid_scope (HTTP 400, or redirected)
STS-OAUTH-0461 An application declares an oauthAuthorizationDetailsType value that cannot be read as a definition; it is ignored. none — logged only
STS-OAUTH-0462 Two applications declare the same authorization_details type; the first in identifier order answers for it. none — logged only
STS-OAUTH-0480 A tls_client_auth client presented a TLS client certificate whose chain did not verify against the client truststore (RFC 8705 section 2.1). invalid_client (HTTP 401)
STS-OAUTH-0481 A tls_client_auth client presented a certificate that chains to this service’s own Root and is not a TLS client identity in this realm (another realm’s, or a key pair issued for another purpose). invalid_client (HTTP 401)
STS-OAUTH-0482 A tls_client_auth client’s entry registers more than one of RFC 8705 section 2.1.2’s five certificate subject parameters. invalid_client (HTTP 401)
STS-OAUTH-0483 A tls_client_auth client presented a certificate this realm issued to it that its record no longer lists (taken off or replaced). invalid_client (HTTP 401)
STS-OAUTH-0484 A tls_client_auth client presented a certificate this realm issued as the identity of another application or of a person. invalid_client (HTTP 401)
STS-OAUTH-0485 A tls_client_auth client presented a verified certificate that does not carry the subject DN or subjectAltName it registered (RFC 8705 section 2.1.2). invalid_client (HTTP 401)
STS-OAUTH-0486 A tls_client_auth client presented a verified certificate this realm did not issue to it, and registers no certificate subject to match it against. invalid_client (HTTP 401)
STS-OAUTH-0487 A client that registered tls_client_certificate_bound_access_tokens made a token request on a connection with no client certificate (RFC 8705 section 3.4), refused in every mode. invalid_request (HTTP 400)
STS-OAUTH-0488 A client declaring an RFC 8705 certificate authentication method did not authenticate by certificate and no more specific reason was recorded; refused in every mode. invalid_client (HTTP 401)
STS-OAUTH-0500 An authorization request’s acr_values were not met by the authentication performed after the person was sent to sign in again (RFC 9470 section 5); refused in every mode. unmet_authentication_requirements (redirected error)
STS-OAUTH-0501 An authorization request’s max_age was still not met on the return from the sign-in it was sent to — the sign-in did not start a new authentication. unmet_authentication_requirements (redirected error)
STS-OAUTH-0502 The session did not meet an authorization request’s acr_values or max_age, and prompt=none forbids sending the person to sign in again. login_required (redirected error)
STS-OAUTH-0503 A resource server here challenged an access token whose acr meets none of the acr values the resource requires (RFC 9470 section 3). insufficient_user_authentication (HTTP 401, WWW-Authenticate challenge with acr_values)
STS-OAUTH-0504 A resource server here challenged an access token whose auth_time is older than the max_age the resource requires, or absent (RFC 9470 section 3). insufficient_user_authentication (HTTP 401, WWW-Authenticate challenge with max_age)
STS-OAUTH-0505 The step-up stand-in resource was asked for an application this realm has no entry for. invalid_request (HTTP 404)
STS-OAUTH-0506 An access token presented at the step-up stand-in resource does not name that application in its aud (RFC 9068 section 4 step 4). invalid_token (HTTP 401, WWW-Authenticate challenge)
STS-OAUTH-0507 An access token presented where only a token this realm can verify is accepted — the step-up stand-in resource, or an OpenID4VCI endpoint in product mode — did not verify against this realm’s signing key. invalid_token (HTTP 401, WWW-Authenticate challenge)
STS-OAUTH-0508 A configured step-up requirement (oauth2.stepUpAcrValues, or an application’s oauthStepUpAcrValues or oauthStepUpMaxAge written by hand) holds a value that cannot be one, and it was ignored. none — logged only
STS-OAUTH-0509 An authorization request’s acr_values carries a value that cannot be an acr value (a double quote, a backslash or a control character). invalid_request (redirected error)
STS-OAUTH-0510 A password or assertion grant was refused because the directory holds no entry for the person, so there is no subject to issue a token about. invalid_grant (HTTP 400)
STS-OAUTH-0511 A refresh was refused because the subject of the refresh token names nobody in the directory any more (the person was deleted, or deleted and re-created). invalid_grant (HTTP 400)
STS-OAUTH-0512 An authorization code was being redeemed by another Token Request at the same moment (its claim was held), and that redemption’s record did not appear within the wait, so this one was refused. invalid_grant (HTTP 400)
STS-OAUTH-0513 An authorization code could not be spent because the claim store could not be asked; the Token Request was refused and the code left unspent (fail closed). server_error (HTTP 500)
STS-OAUTH-0514 An authorization response on a pushed request_uri was refused because another response was issued on it at the same moment (its claim was held) (RFC 9126 section 4). invalid_request_uri (HTTP 400)
STS-OAUTH-0515 A pushed request_uri could not be spent because the claim store could not be asked, so nothing was issued on it (fail closed). server_error (HTTP 500)
STS-OAUTH-0516 In RFC 9700 mode, a refresh token was redeemed by another request, on this node or another, at the same moment or before this node heard of it (its claim was held); treated as a replay and its family revoked (section 2.2.2). invalid_grant (HTTP 400)
STS-OAUTH-0517 In RFC 9700 mode, a refresh token was presented whose family had already been revoked by a replay — possibly a token minted on another node that the revoking node never saw. invalid_grant (HTTP 400)
STS-OAUTH-0518 In RFC 9700 mode, a refresh token could not be redeemed because the claim store could not be asked; refused, and left unspent (fail closed). server_error (HTTP 500)
STS-OAUTH-0519 A DPoP proof was refused because another request carrying the same jti claimed it first, on this node or another (RFC 9449 section 11.1). invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0520 A DPoP proof was refused because the claim store could not be asked whether its jti had been used (fail closed). invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0521 A token request that would issue a refresh token carried no DPoP proof, and oauth2.refreshTokenRequireDpop is on. invalid_dpop_proof (HTTP 400)
STS-OAUTH-0522 A token request that would issue a refresh token was made over a connection with no verified client certificate, and oauth2.refreshTokenRequireMtls is on. invalid_client (HTTP 401)
STS-OAUTH-0523 A refresh token carrying no cnf.jkt was presented while oauth2.refreshTokenRequireDpop is on; it is refused rather than bound to the key presenting it. invalid_grant (HTTP 400)
STS-OAUTH-0524 A refresh grant carried no DPoP proof while oauth2.refreshTokenRequireDpop is on. invalid_dpop_proof (HTTP 400)
STS-OAUTH-0525 A refresh token carrying no cnf x5t#S256 was presented while oauth2.refreshTokenRequireMtls is on, by a client RFC 8705 section 7.1 does not cover. invalid_grant (HTTP 400)
STS-OAUTH-0526 A refresh grant was made over a connection with no verified client certificate while oauth2.refreshTokenRequireMtls is on. invalid_client (HTTP 401)
STS-OAUTH-0527 A setting requires mutual TLS, but the port the request arrived on is not bound as HTTPS and cannot ask for a client certificate (global.https). invalid_request (HTTP 400 / 401)
STS-OAUTH-0528 An access token carrying no cnf.jkt was presented at a resource while oauth2.accessTokenRequireDpop is on. invalid_token (HTTP 401)
STS-OAUTH-0529 A DPoP-bound access token was presented with no proof while oauth2.accessTokenRequireDpop is on. invalid_token (HTTP 401)
STS-OAUTH-0530 An access token carrying no cnf x5t#S256 was presented at a resource while oauth2.accessTokenRequireMtls is on. invalid_token (HTTP 401)
STS-OAUTH-0531 A certificate-bound access token was presented at a resource over a connection carrying no matching certificate, while oauth2.accessTokenRequireMtls is on. invalid_token (HTTP 401)
STS-OAUTH-0532 A back-channel Logout Token was not sent because federation.outbound is off, so this service makes no outbound request. none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0533 A back-channel Logout Token was not sent because the client’s backchannel_logout_uri cannot be dialled: not http(s), plain http refused (federation.outboundAllowHttp off, or product mode), or not a URL. none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0534 Product mode: a back-channel Logout Token was not sent because the backchannel_logout_uri resolves to a loopback, private, link-local or reserved address. none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0535 Product mode: a back-channel Logout Token was not sent because the backchannel_logout_uri’s host could not be resolved. none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0536 A relying party answered a back-channel Logout Token with 400, which Back-Channel Logout 1.0 section 2.8 makes a final refusal; it is not retried. none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0537 A relying party answered a back-channel Logout Token with a status other than 200, 204 or 400 — after every attempt where the status is one worth retrying (5xx, 408, 429). none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0538 A relying party did not answer a back-channel Logout Token within oauth2.backchannelLogoutTimeoutMs, on every attempt. none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0539 A back-channel Logout Token could not be delivered because the connection failed (DNS, refused, TLS), on every attempt. none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0540 A relying party answered a back-channel Logout Token with a redirect, which is not followed. none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0541 A back-channel Logout Token could not be signed — the client registered an id_token_signed_response_alg this service cannot use for it, or an HMAC algorithm with no client secret. none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0542 A back-channel Logout Token was not sent because the session did not record the issuer that client’s ID Token was issued by (a session older than the feature), and no fallback was available. none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0543 A back-channel Logout Token request could not be built from its options. none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0544 A stored backchannel_logout_uri is not an http or https URL without a fragment, so the client was not sent a Logout Token. none — the delivery is listed with the reason, and the value is logged
STS-OAUTH-0545 The periodic back-channel logout summary: Logout Token deliveries were dead-lettered, or deferred because the claim store could not be asked, since the last summary (counted by code). none — one warning per realm per oauth2.backchannelLogoutSummaryS; the rows are on /admin/logout
STS-OAUTH-0546 A client registered id_token_encrypted_response_alg and its ID Token (or back-channel Logout Token) could not be encrypted — the registration is no longer one this service can honour, or its jwks holds no key of the right type. the ID Token is not issued (server_error with the sentence); a Logout Token delivery is dead-lettered
STS-OAUTH-0547 A back-channel Logout Token attempt was not made because the cluster claim store could not be asked; the delivery stays pending and the next sweep tries again. none — counted in the STS-OAUTH-0545 summary
STS-OAUTH-0548 A back-channel Logout Token delivery was still pending when oauth2.backchannelLogoutRetentionS passed, and was dead-lettered. none — a logout.backchannel audit row and a dead letter on /admin/logout
STS-OAUTH-0549 The back-channel logout delivery sweep failed in a realm. none — logged; the next sweep runs as scheduled
STS-OAUTH-0550 A retry of a back-channel Logout Token delivery was refused: no delivery was named, it is unknown or not a dead letter, or the client has no usable backchannel_logout_uri or recorded issuer. HTTP 400 { ok: false, errors } / 303 with error=
STS-OAUTH-0551 A token request — any grant carrying a person, a refresh token included — was refused because the account is disabled. invalid_grant (HTTP 400)
STS-OAUTH-0552 A PUBLIC client (token_endpoint_auth_method=”none”) asked for the client credentials grant in product mode. RFC 6749 section 4.4 defines that grant for a client that HAS credentials and OAuth 2.1 section 4.2 limits it to confidential clients; a public client using it would mint a token for anybody who knows the client_id. unauthorized_client (HTTP 400)
STS-OAUTH-0553 A client whose application entry declares NO token_endpoint_auth_method presented no credential. Product mode reads the omission as RFC 7591 section 2’s default, client_secret_basic, and refuses it at the token endpoint and at PAR; development records it as an unauthenticated client and answers. Setting oauthTokenEndpointAuthMethod to “none” makes it a public client. An application created from the console or /admin-api has been given a method since 2026-09-18, so this is an entry made before that or by another door. invalid_client (HTTP 401) in product mode; none in development
STS-OAUTH-0554 A DPoP proof was refused because the realm’s proof-ID replay history held oauth2.dpopReplayCacheSize LIVE entries: forgetting one would let that proof be replayed, so the new proof is refused instead until entries age out (twice oauth2.dpopIatSkewS). invalid_dpop_proof (HTTP 400 / 401)
STS-OAUTH-0555 Product mode: an RFC 8693 subject_token that did not verify against this realm’s signing key (a forged, foreign, expired or unreadable token) was refused. Development exchanges it unverified (mode.exchangesUnverifiedTokens()). invalid_request (HTTP 400), RFC 8693 section 2.2.2
STS-OAUTH-0556 Product mode: an RFC 8693 actor_token that did not verify against this realm’s signing key was refused. Development reads its sub unverified into the act claim. invalid_request (HTTP 400), RFC 8693 section 2.2.2
STS-OAUTH-0557 An RFC 8693 subject_token or actor_token that verified was refused because this realm has revoked it. invalid_request (HTTP 400), RFC 8693 section 2.2.2
STS-OAUTH-0558 A client authenticated with a client_secret past its expiry (the expiry on that secret’s record on oauthClientSecret), in product mode. invalid_client (RFC 6749 section 5.2)
STS-OAUTH-0559 A client authenticated with an expired client_secret and was accepted, because the service is in development mode. none — logged; the request is answered
STS-OAUTH-0560 An authorization request asked for an ID Token without the openid scope (OIDC Core section 3.1.2.1). redirect: error=invalid_scope
STS-OAUTH-0561 An authorization request combined prompt=none with another prompt value (OIDC Core section 3.1.2.1). redirect: error=invalid_request
STS-OAUTH-0562 An authorization request whose response_type returns an ID Token from the authorization endpoint (implicit, or hybrid code id_token [token]) carried no nonce, which OIDC Core sections 3.2.2.1 and 3.3.2.1 make REQUIRED — in every mode (hybrid since #187). redirect: error=invalid_request
STS-OAUTH-0563 An implicit-flow authorization request named an http redirect_uri that is not a loopback address (OIDC Core section 3.2.2.1). HTTP 400 {error: invalid_request}
STS-OAUTH-0564 An authorization request sent with POST was not application/x-www-form-urlencoded (OIDC Core section 3.1.2.1). HTTP 400 {error: invalid_request}
STS-OAUTH-0565 The authorization endpoint failed while reading an id_token_hint. HTTP 500 {error: server_error}
STS-OAUTH-0566 An id_token_hint did not verify as an ID Token this authorization server issued to this client. redirect: error=invalid_request
STS-OAUTH-0567 The person signed in is not the one the id_token_hint names, and prompt=none (or the person signed in as somebody else again). redirect: error=login_required
STS-OAUTH-0568 A refresh token granted without offline_access was presented after the sign-on session it came from ended (OIDC Core section 11). HTTP 400 {error: invalid_grant}
STS-OAUTH-0569 A redirect_uri matched none of the redirect URIs the client registered (OIDC Core section 3.1.2.1), outside RFC 9700 mode. HTTP 400 {error: invalid_request}
STS-OAUTH-0570 A client assertion was not signed with the client’s registered token_endpoint_auth_signing_alg (OIDC Core section 9). HTTP 401 {error: invalid_client}
STS-OAUTH-0571 An access token was sent to the UserInfo endpoint in more than one place (RFC 6750 section 2). HTTP 400 {error: invalid_request}
STS-OAUTH-0572 A client’s stored frontchannel_logout_uri matches none of its redirect URIs by scheme, host and port (Front-Channel Logout 1.0 section 2), so a sign-out does not frame it. none — the client is listed on the sign-out page as not notified, with the reason
STS-OAUTH-0573 Under a FAPI profile, an authorization request carried no code_challenge with code_challenge_method S256 (FAPI 1.0 Part 1 section 5.2.2 item 7). redirect or HTTP 400 {error: invalid_request}
STS-OAUTH-0574 Under a FAPI profile, an authorization request carried no redirect_uri, or one that is not https (FAPI 1.0 Part 1 section 5.2.2 items 9 and 20). HTTP 400 {error: invalid_request}
STS-OAUTH-0575 Under a FAPI profile, an authorization request asked for openid without a nonce (FAPI 1.0 Part 1 section 5.2.2.2). redirect: error=invalid_request
STS-OAUTH-0576 Under a FAPI profile, an authorization request without openid carried no state (FAPI 1.0 Part 1 section 5.2.2.3). redirect: error=invalid_request
STS-OAUTH-0577 A client asked for one of this service’s own protected scopes (admin:read, admin:write, the SCIM or Shared Signals scopes, the debugger permission) that its oauthAllowedScope does not list. Held in every mode. invalid_scope (redirected error, or HTTP 400 at the token and pushed authorization request endpoints)
STS-OAUTH-0578 In product mode, a client asked for a scope outside its oauthAllowedScope — or, declaring none, outside the default set (OpenID Connect’s six and the OpenID4VCI credential scopes). invalid_scope (redirected error, or HTTP 400 at the token and pushed authorization request endpoints)
STS-OAUTH-0579 A grant carrying its scope from earlier (a refresh, a token exchange, an assertion grant) named a scope the client may no longer be issued; it was taken off the tokens and recorded. none — the token response’s scope says what was issued (RFC 6749 section 5.1)
STS-OAUTH-0580 Under a FAPI profile, a confidential client authenticated with client_secret_basic or client_secret_post (FAPI 1.0 Part 1 section 5.2.2 item 4). HTTP 401 {error: invalid_client}
STS-OAUTH-0581 Under a FAPI profile, a token or PAR request identified its client in two different ways — the Basic header, the body’s client_id, a client assertion’s sub (FAPI 1.0 Part 1 section 5.2.2 item 19). HTTP 401 {error: invalid_client}
STS-OAUTH-0582 Under FAPI 1.0 Advanced, an authorization request asked for a response type the profile does not allow: it allows code id_token, or code with a JARM response mode (Part 2 section 5.2.2 item 2). redirect: error=unsupported_response_type
STS-OAUTH-0583 Under FAPI 1.0 Advanced, a token request would have minted an access token bound to nothing — no TLS client certificate, and no DPoP proof (or oauth2.fapiRequireMtls is on and there was no certificate) (Part 2 section 5.2.2 items 5 and 6). HTTP 400 {error: invalid_request}
STS-OAUTH-0584 Under FAPI 1.0 Advanced, a request object lacked exp or nbf, lived more than 60 minutes after its nbf, or had an nbf more than 60 minutes old (Part 2 section 5.2.2 items 13 and 17). HTTP 400 {error: invalid_request_object}
STS-OAUTH-0585 Under FAPI 1.0 Advanced, a request object’s aud was not this authorization server’s issuer (Part 2 section 5.2.2 item 15). HTTP 400 {error: invalid_request_object}
STS-OAUTH-0586 Under FAPI 1.0 Advanced, a client assertion or request object was signed with an algorithm other than PS256 or ES256 (Part 2 section 8.6). HTTP 401 {error: invalid_client}, or HTTP 400 {error: invalid_request_object}
STS-OAUTH-0587 response_mode=query.jwt was asked for with a response type carrying token or id_token, and the client registered no encryption for its authorization responses (JARM section 2.3.1). redirect: error=invalid_request
STS-OAUTH-0588 A JWT-secured authorization response (JARM) could not be made: the client’s registered algorithm cannot be honoured, or it named encryption and its jwks holds no key for it. Answered on this server rather than sent unsecured. HTTP 400 {error: invalid_request}
STS-OAUTH-0589 Under the FAPI 2.0 Security Profile, a pushed authorization request did not authenticate its client (section 5.3.2.2 item 4). HTTP 401 {error: invalid_client}
STS-OAUTH-0590 Under the FAPI 2.0 Security Profile, a client assertion, a request object or a DPoP proof carried an iat or nbf more than 60 seconds in the future (section 5.3.2.1 item 13). HTTP 400 {error: invalid_request}, invalid_request_object, or invalid_dpop_proof
STS-OAUTH-0591 Under FAPI 2.0 Message Signing, an authorization request did not ask for a JWT-secured response (JARM), which the profile requires (section 5.4.2 item 1). redirect or HTTP 400 {error: invalid_request}
STS-OAUTH-0592 A WebFinger request carried no single resource parameter, or one that is not an acct: URI, an e-mail address, an https URL or a host (RFC 7033 section 4.2, OIDC Discovery section 2.1). HTTP 400
STS-OAUTH-0593 A WebFinger resource named a domain no realm has, or a path on this service that names no realm (RFC 7033 section 4.2). HTTP 404
STS-OAUTH-0594 A discovery path named no issuer: not [realm/][/], an unknown realm, or more than one server segment. Answered with Express's 404 and no authorization server created (#119). HTTP 404
STS-OAUTH-0595 An RFC 7592 update named a client_id other than the one it updates, or a client_secret other than the one this server issued (section 2.2) (#120). HTTP 400 {error: invalid_request}
STS-OAUTH-0596 A registration access token was presented for a client that no longer exists; the token was revoked and refused (RFC 7592 section 3) (#120). Logged at warn. HTTP 401 {error: invalid_token}
STS-OAUTH-0597 An authorization request asked for a response_type the client did not register in response_types (OpenID Connect Registration section 2) (#120). redirect {error: unauthorized_client}
STS-OAUTH-0598 A token request used a grant_type the client did not register in grant_types (RFC 7591 section 2) (#120). HTTP 400 {error: unauthorized_client}
STS-OAUTH-0599 A client’s registered jwks_uri could not be read: the outbound policy refused it, it did not answer 200, or it did not answer a JSON Web Key Set (#120). Logged at warn; the verification or encryption that needed the key is refused with its own code. none (log only)
STS-OAUTH-0600 A client that registered grant_types without refresh_token was answered with no refresh token (RFC 7591 section 2) (#120). Recorded, not refused. none (the token response omits refresh_token)
STS-OAUTH-0601 The OP iframe or its script was asked for while oauth2.sessionManagement is off in the realm (#121): a 404 naming the setting. HTTP 404
STS-OAUTH-0602 An RP-Initiated Logout id_token_hint did not verify as an ID Token this authorization server issued to the client the request names — or a client_id it was not issued to was given beside it (section 2’s MUST, #124, #115). Refused in every mode; the session is not ended. HTTP 400 (an HTML page)
STS-OAUTH-0603 In product mode, an RP-Initiated Logout post_logout_redirect_uri named no client that registered it (#124): not followed. Development still follows one. none (the sign-out page says so)
STS-OAUTH-0604 An RP-Initiated Logout request sent with POST was not a form (application/x-www-form-urlencoded, section 2) (#124). HTTP 400 (an HTML page)
STS-OAUTH-0605 The RP-Initiated Logout endpoint failed while answering (#124). HTTP 500 (an HTML page)
STS-OAUTH-0606 response_type none was combined with another response type; it asks for nothing to be issued (Multiple Response Type Encoding Practices section 4, #125). redirect {error: unsupported_response_type}
STS-OAUTH-0607 response_mode=query was asked for a response type that returns a token or an ID Token, which section 2.1 of Multiple Response Type Encoding Practices forbids (#125). The refusal goes in the fragment. redirect {error: invalid_request}
STS-OAUTH-0608 An RFC 7009 revocation request named no token: section 2.1 makes the token parameter REQUIRED (#102). In both modes. invalid_request (HTTP 400)
STS-OAUTH-0609 An RFC 7009 revocation request from a registered client did not authenticate: in product mode a confidential client presented no credential, or (in either mode) a credential that did not verify, or an entry that declares no method presented none (#102). invalid_client (HTTP 401, RFC 7009 section 2.1)
STS-OAUTH-0610 Product mode: an RFC 7009 revocation request named no client this realm has registered — no client_id at all, or one with no entry — so there is no client to validate (#102). invalid_client (HTTP 401, RFC 7009 section 2.1)
STS-OAUTH-0611 An RFC 7009 revocation request presented a token this realm signed that is neither an access token nor a refresh token — an ID Token, a logout token, a SET — which this server does not revoke (#102). unsupported_token_type (HTTP 400, RFC 7009 section 2.2.1)
STS-OAUTH-0612 An RFC 7009 revocation request from an authenticated or identified client presented a token issued to another client. Refused and nothing revoked; the audit row names both clients (#102). invalid_grant (HTTP 400, RFC 7009 section 2.1 and RFC 6749 section 5.2)
STS-OAUTH-0613 A client authenticating at the revocation endpoint declares a token_endpoint_auth_method the selected authorization server does not list in revocation_endpoint_auth_methods_supported (#102). invalid_client (HTTP 401)
STS-OAUTH-0614 The revocation endpoint failed with an unexpected error outside every refusal it makes (#102). server_error (HTTP 500)
STS-OAUTH-0615 A refresh was refused because a consent its grant stood on — the person’s own, or the application’s global consent that the person had not given themselves — was withdrawn at or after the grant was made (#172). The refresh token’s grant is revoked. HTTP 400 {error: invalid_grant}
STS-OAUTH-0616 A refresh of a grant made at the authorization endpoint was refused because no recorded consent covered one of its scopes when it was granted, while consent is required and oauth2.refreshRequiresConsent is on (#172). HTTP 400 {error: invalid_grant}
STS-OAUTH-0617 Withdrawing a consent could not revoke a refresh family by id; its members known on this node were revoked, and the refresh grant refuses any other at its first use (#172). none — logged
STS-OAUTH-0618 A token exchange was refused by the delegation policy (#108): the subject may not be delegated (stsNotDelegated, or a member of the console roster, a protected group), the actor has no entry or is a person without delegation.actorRole, or may not act for this subject (appDelegationSubjectGroup) — the issuance policy’s rules since #186. Product mode only; development records what would have been refused. invalid_request (HTTP 400), RFC 8693 section 2.2.2
STS-OAUTH-0619 A token exchange was refused because the delegation policy allows no target it names: neither appAllowedToDelegateTo on the client nor appAllowedToActOnBehalfOf on the target lists the other (#108). Product mode only. invalid_target (HTTP 400), RFC 8693 section 2.2.2
STS-OAUTH-0620 A token exchange was refused because the verified subject_token carries a may_act claim naming a party other than the actor (the actor_token’s subject, or the client when there is no actor_token). Held in every mode (#108). invalid_request (HTTP 400), RFC 8693 sections 2.2.2 and 4.4
STS-OAUTH-0621 A token exchange asked for a scope wider than the verified subject_token’s own scope claim, and product mode refuses an exchange that widens what the subject granted (#108). invalid_scope (HTTP 400), RFC 6749 section 5.2
STS-OAUTH-0622 A token exchange was refused because no issuance policy gave a verdict on it, or a realm’s policy refused it with no rule this service names (#186). Product mode only. invalid_request (HTTP 400), RFC 8693 section 2.2.2
STS-OAUTH-0623 A person’s recorded identity verifications (OpenID Connect for Identity Assurance, #127) could not be read — the value on the entry is not a JSON list — or recording one after a wallet or certificate sign-in threw. Read as none; the sign-in stands. none — verified_claims is omitted
STS-OAUTH-0624 device_sso (OpenID Connect Native SSO, #130) was asked for by a client not enabled for it — oauthNativeSso TRUE and an oauthNativeSsoGroup on its entry. In every mode. invalid_scope (HTTP 400, or at the redirect URI)
STS-OAUTH-0625 A Native SSO grant could not store its device in ou=devices — no entry for the person, or the directory full — so no device_secret was issued; the rest of the token response stood (#130). none — the response carries no device_secret
STS-OAUTH-0626 A token exchange named no subject_token_type, an actor_token without its actor_token_type, or an actor_token_type without its token (RFC 8693 section 2.1, #130). invalid_request (HTTP 400)
STS-OAUTH-0627 A token exchange named a token type this service does not exchange (a SAML assertion, an unknown URI), or a device secret anywhere but as the actor beside an ID Token (#130). invalid_request (HTTP 400)
STS-OAUTH-0628 A token exchange presented a token this realm verified that is not the type it was declared as — an ID Token declared an access token, a refresh token declared a JWT (#130). invalid_request (HTTP 400)
STS-OAUTH-0629 A Native SSO exchange came from a client not enabled for Native SSO, or the ID Token it presented was issued to a client outside its Native SSO group (#130). unauthorized_client (HTTP 400)
STS-OAUTH-0630 A Native SSO exchange’s audience was not this authorization server’s issuer (Native SSO section 4.1, #130). invalid_request (HTTP 400)
STS-OAUTH-0631 A Native SSO exchange’s subject_token is not an ID Token this realm issued — it does not verify, names another issuer, is another kind of token, or was revoked (#130). invalid_request (HTTP 400)
STS-OAUTH-0632 A Native SSO exchange’s actor_token names no device, or is not the device secret the ID Token’s ds_hash was made from (#130). invalid_request (HTTP 400)
STS-OAUTH-0633 A Native SSO exchange’s device secret is bound to a sign-on session that has ended, that is not the ID Token’s sid, or that is no longer the device owner’s (#130). invalid_request (HTTP 400)
STS-OAUTH-0634 A client not enabled for Native SSO asked the revocation endpoint to revoke a device secret (#130). Nothing was revoked. invalid_grant (HTTP 400)
STS-OAUTH-0635 A CIBA request was refused because the person already has oauth2.cibaMaxPendingPerPerson requests waiting (#131, section 14). access_denied (HTTP 403)
STS-OAUTH-0636 A CIBA notification endpoint answered a status other than 2xx or 400 — 5xx, 408 and 429 are retried, the rest are not (#131; the shared outbound queue since #151). none — the client polls, or never learns
STS-OAUTH-0637 The CIBA Backchannel Authentication Endpoint failed unexpectedly (#131). server_error (HTTP 500)
STS-OAUTH-0638 A CIBA request or token request arrived in a realm where oauth2.ciba is off (#131). invalid_request (HTTP 404) or unsupported_grant_type
STS-OAUTH-0639 A CIBA authentication request was malformed (#131). invalid_request (HTTP 400)
STS-OAUTH-0640 A CIBA client declared a client authentication method the authorization server does not advertise (#131). invalid_client (HTTP 401)
STS-OAUTH-0641 A CIBA client did not authenticate at the Backchannel Authentication Endpoint, which asks it in every mode (#131, section 7.1). invalid_client (HTTP 401)
STS-OAUTH-0642 A client that registered no backchannel_token_delivery_mode asked to use CIBA (#131). unauthorized_client (HTTP 400)
STS-OAUTH-0643 A CIBA signed request was missing where required, or did not verify, carried the wrong alg, iss, aud or lifetime, or was used before (#131, section 7.1.1). invalid_request (HTTP 400)
STS-OAUTH-0644 A CIBA request’s scope did not contain openid (#131, section 7.1). invalid_scope (HTTP 400)
STS-OAUTH-0645 A CIBA request carried no hint, or more than one of login_hint_token, id_token_hint and login_hint (#131). invalid_request (HTTP 400)
STS-OAUTH-0646 A CIBA hint named nobody this realm holds — in both modes (#131). unknown_user_id (HTTP 400)
STS-OAUTH-0647 A CIBA id_token_hint or login_hint_token is not a token this realm issued and still stands by (#131). invalid_request (HTTP 400)
STS-OAUTH-0648 A CIBA login_hint_token has expired (#131). expired_login_hint_token (HTTP 400)
STS-OAUTH-0649 A CIBA binding_message was longer than 200 characters or carried control characters (#131). invalid_binding_message (HTTP 400)
STS-OAUTH-0650 A CIBA request from a client that registered backchannel_user_code_parameter carried no user_code (#131). missing_user_code (HTTP 400)
STS-OAUTH-0651 A CIBA request’s user_code is not the one the person set (#131). invalid_user_code (HTTP 400)
STS-OAUTH-0652 A CIBA request’s requested_expiry was not a positive whole number (#131). invalid_request (HTTP 400)
STS-OAUTH-0653 A CIBA ping or push client sent no client_notification_token (#131). invalid_request (HTTP 400)
STS-OAUTH-0654 A CIBA token request came from a client registered for push, or for no CIBA mode (#131, section 10). unauthorized_client (HTTP 400)
STS-OAUTH-0655 A CIBA token request named an auth_req_id that is no request of this client (#131). invalid_grant (HTTP 400)
STS-OAUTH-0656 A CIBA token request found the request still waiting for the person (#131, section 11). authorization_pending (HTTP 400)
STS-OAUTH-0657 A CIBA token request came sooner than the interval; the interval grows by five seconds (#131, section 11). slow_down (HTTP 400)
STS-OAUTH-0658 A CIBA request expired before the person answered (#131). expired_token (HTTP 400)
STS-OAUTH-0659 The person denied the CIBA request (#131). access_denied (HTTP 400)
STS-OAUTH-0660 A CIBA request’s tokens had already been issued (#131). invalid_grant (HTTP 400)
STS-OAUTH-0661 The tokens for an approved CIBA push could not be minted — the issuance policy refused, or the person is gone — and the client is sent transaction_failed (#131). none — pushed as transaction_failed
STS-OAUTH-0662 FAPI-CIBA: a client registered for the push delivery mode asked for backchannel authentication under a FAPI profile, which allows poll and ping only (#142). unauthorized_client
STS-OAUTH-0663 FAPI-CIBA: a backchannel authentication request under a FAPI profile carried no binding_message (#142). invalid_request
STS-OAUTH-0664 A backchannel authentication request’s request_context was not a JSON object of at most 4096 characters (FAPI-CIBA section 5.3, #142). invalid_request
STS-OAUTH-0665 Grant Management: grant_management_action was unknown, or grant_id came with no action or with create, or merge or replace named no grant_id (#142). invalid_request
STS-OAUTH-0666 Grant Management was asked for by a public client; it is for confidential clients only (#142). invalid_request
STS-OAUTH-0667 Grant Management was asked for with a response_type that returns an access token from the authorization endpoint (#142). invalid_request
STS-OAUTH-0668 A grant_id names no grant of this client, or not the signed-in person’s (#142). invalid_grant_id
STS-OAUTH-0669 The grant a code or CIBA request was to merge or replace was revoked before its tokens were claimed (#142). invalid_grant
STS-OAUTH-0670 A refresh token’s grant was revoked, or merged or replaced since it was issued (#142). invalid_grant
STS-OAUTH-0671 The grant management API was called with no access token this service issued, or a revoked one (#142). invalid_token (HTTP 401)
STS-OAUTH-0672 The grant management API was called without the grant_management_query or grant_management_revoke scope a declaring client holds, or for another client’s grant (#142). insufficient_scope (HTTP 403)
STS-OAUTH-0673 The grant management API was asked about a grant_id nobody holds (#142). HTTP 404
STS-OAUTH-0674 The grant management endpoint failed unexpectedly (#142). server_error (HTTP 500)
STS-OAUTH-0675 A token request carried a client_assertion that names no client: no client_id in the body and no sub in the assertion, so there is no registered client to verify it against (RFC 7523 section 3 item B, #176). invalid_client (HTTP 401), RFC 6749 section 5.2
STS-OAUTH-0676 A request object carried request or request_uri as a claim, which RFC 9101 section 4 forbids; refused at the authorization endpoint and at PAR (#176). invalid_request_object, RFC 9101 sections 4 and 6.2
STS-OAUTH-0677 A token request’s JWT client_assertion named more than one client: its iss, its sub and the request’s client_id did not all agree, and for client authentication each must be the client_id (RFC 7523 section 3, OpenID Connect Core section 9, #176). invalid_client (HTTP 401), RFC 6749 section 5.2
STS-OAUTH-0678 A Claims Provider link was asked for a provider this realm has not registered, or its callback carried no code (#147). portal refusal (HTTP 400)
STS-OAUTH-0679 A Claims Provider link callback named a state that is unknown, expired or another person’s (#147). portal refusal (HTTP 400)
STS-OAUTH-0680 A Claims Provider refused the link: an error at its authorization endpoint, or its token endpoint refused the code (#147). portal refusal (HTTP 400)
STS-OAUTH-0681 A Claims Provider’s claims endpoint gave no signed claims its keys verify when a person linked it (#147). portal refusal (HTTP 400)
STS-OAUTH-0682 A Claims Provider gave nothing for a person at ID Token or UserInfo time — the fetch failed or did not verify — so its claims were left out (#147). none (logged; the response omits the claims, OIDC Core 5.5.1)
STS-OAUTH-0683 A _claim_sources entry from an upstream OP could not be honoured: an issuer or endpoint this realm has not registered as a Claims Provider, or a JWT its keys did not verify (#147). none (logged; the claims are not taken)
STS-OAUTH-0684 A person’s token at a Claims Provider could not be refreshed and was marked stale (#147). none (logged)
STS-OAUTH-0685 A person’s Claims Provider tokens could not be read or sealed (#147). portal refusal (HTTP 500), or logged
STS-OAUTH-0686 An administrator’s Claims Provider act was refused: an invalid or duplicate provider, an unknown action, or a link that does not exist (#147). console / /admin-api refusal (HTTP 400)
STS-OAUTH-0687 Registering a Claims Provider by discovery failed: its discovery document could not be fetched or does not name its issuer (#147). console / /admin-api refusal (HTTP 400)
STS-OAUTH-0688 An authorization request named a tenant other than the trust realm it was sent to (OpenID Connect Enterprise Extensions section 3.2, #148); a realm is chosen by the path, never by a parameter. redirect {error: invalid_request}
STS-OAUTH-0689 The device authorization grant or endpoint was used in a realm where oauth2.deviceAuthorization is off (RFC 8628, #150). HTTP 404 {error: invalid_request} at the endpoint; {error: unsupported_grant_type} at the token endpoint
STS-OAUTH-0690 A device authorization request was malformed (RFC 8628 section 3.1, #150). HTTP 400 {error: invalid_request}
STS-OAUTH-0691 A device authorization request’s client did not authenticate as it registered to (RFC 8628 section 3.1, #150). HTTP 401 {error: invalid_client}
STS-OAUTH-0692 A client that did not register the device_code grant asked the device authorization endpoint for codes (#150). HTTP 400 {error: unauthorized_client}
STS-OAUTH-0693 The DPoP proof on a device authorization request did not verify (RFC 9449, OpenID Connect Key Binding, #150). HTTP 400 {error: invalid_dpop_proof}
STS-OAUTH-0694 The device authorization endpoint failed unexpectedly (#150). HTTP 500 {error: server_error}
STS-OAUTH-0695 A device_code grant named no device authorization of this client (RFC 8628 section 3.5, #150). HTTP 400 {error: invalid_grant}
STS-OAUTH-0696 A device polled before the person answered (RFC 8628 section 3.5, #150). Expected, not a fault. HTTP 400 {error: authorization_pending}
STS-OAUTH-0697 A device polled sooner than its interval, which grows by five seconds (RFC 8628 section 3.5, #150). HTTP 400 {error: slow_down}
STS-OAUTH-0698 A device code expired before the person answered (RFC 8628 section 3.5, #150). HTTP 400 {error: expired_token}
STS-OAUTH-0699 The person denied a device’s sign-in on /portal/device (RFC 8628 section 3.5, #150). HTTP 400 {error: access_denied}
STS-OAUTH-0700 A device code whose tokens were already issued was presented again (#150). HTTP 400 {error: invalid_grant}
STS-OAUTH-0701 A device code bound to a DPoP key was redeemed without a proof from that key (#150). HTTP 400 {error: invalid_dpop_proof}
STS-OAUTH-0702 A grant holding bound_key was redeemed without a DPoP proof (OpenID Connect Key Binding, #150). HTTP 400 {error: invalid_dpop_proof}
STS-OAUTH-0703 A grant holding bound_key was redeemed with a DPoP proof whose c_s256 is not the hash of the code (OpenID Connect Key Binding, #150). HTTP 400 {error: invalid_dpop_proof}
STS-OAUTH-0704 An authorization request asked for bound_key without dpop_jkt (OpenID Connect Key Binding, #150). redirect {error: invalid_request}
STS-OAUTH-0705 An authorization request asked for bound_key outside response_type=code (OpenID Connect Key Binding, #150). redirect {error: invalid_request}
STS-OAUTH-0706 A refresh of a grant whose ID Token is key-bound carried no proof from that key (OpenID Connect Key Binding, #150). HTTP 400 {error: invalid_dpop_proof}
STS-OAUTH-0707 A key-bound ID Token was presented at token exchange without a DPoP proof from the key its cnf names (OpenID Connect Key Binding section 7, #150). HTTP 400 {error: invalid_dpop_proof}
STS-OAUTH-0708 A CIBA ping or push was not sent because federation.outbound is off (#151, the shared outbound queue). none (a dead letter)
STS-OAUTH-0709 A CIBA ping or push was not sent because the client’s notification endpoint cannot be dialled (#151). none (a dead letter)
STS-OAUTH-0710 A CIBA ping or push was refused because the notification endpoint resolves to an internal address in product mode (#151). none (a dead letter)
STS-OAUTH-0711 A CIBA notification endpoint’s host name did not resolve (#151). none (a dead letter)
STS-OAUTH-0712 A CIBA notification endpoint answered with a redirect, which is not followed (#151). none (a dead letter)
STS-OAUTH-0713 A CIBA ping or push could not be built (#151). none (a dead letter)
STS-OAUTH-0714 A CIBA ping or push timed out; retried with backoff (#151). none (retried, then a dead letter)
STS-OAUTH-0715 A CIBA ping or push failed to connect; retried with backoff (#151). none (retried, then a dead letter)
STS-OAUTH-0716 A CIBA notification endpoint answered 400, which is not retried (#151). none (a dead letter)
STS-OAUTH-0717 A CIBA notification attempt was deferred because the claim store was unavailable (#151). none (the sweep tries again)
STS-OAUTH-0718 A CIBA ping or push was still unsent past oauth2.cibaNotifyRetentionS and was dead-lettered (#151). none (a dead letter)
STS-OAUTH-0719 The CIBA notification summary line: some were dead- lettered or deferred since the last one (#151). none (a log line)
STS-OAUTH-0720 A request carried more than one OAuth-Client-Attestation header, or one that is not a JWT in token68 syntax (#229, section 7.1 item 1). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0721 The OAuth-Client-Attestation header does not hold a JWT whose header can be read (#229). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0722 A Client Attestation’s typ is not oauth-client-attestation+jwt (#229, section 4). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0723 A Client Attestation is signed with an algorithm this server does not accept: not an asymmetric one in the JWS table, or a MAC (#229, section 7.1 item 3). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0724 A client attestation was presented in a realm that trusts no client attester: oauth2.clientAttestationTrustAnchors and oauth2.clientAttestationTrustedKeys are both empty (#229). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0725 A Client Attestation’s x5c is unreadable, its signing certificate is self-signed, or its path does not hold to a trust anchor in oauth2.clientAttestationTrustAnchors (#229, section 10.8). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0726 No trusted attester key verifies a Client Attestation: no configured key with its kid, or the signature does not verify (#229, section 7.1 item 4). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0727 A Client Attestation lacks sub, exp or cnf, or a claim has the wrong type (#229, section 4). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0728 A Client Attestation has expired, or its nbf or iat is in the future (#229, section 4). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0729 A Client Attestation’s cnf carries no public jwk, a symmetric one, or private key material (#229, section 7.1 item 5). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0730 A Client Attestation is older than oauth2.clientAttestationMaxAgeS (#229, section 7.1 item 6). token / PAR {error: use_fresh_attestation} (HTTP 400)
STS-OAUTH-0731 A Client Attestation’s sub is not the client_id the request names (#229, sections 7.1 item 7 and 7.5). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0732 A request carried more than one OAuth-Client-Attestation-PoP header, or one that is not a JWT in token68 syntax (#229, section 7.2 item 1). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0733 A Client Attestation PoP’s typ is not oauth-client-attestation-pop+jwt, or its alg is not an accepted asymmetric one (#229, section 5.1). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0734 A Client Attestation PoP does not verify under the key in the attestation’s cnf (#229, section 7.2 item 4). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0735 A Client Attestation PoP lacks aud, jti or iat, or a claim has the wrong type (#229, section 5.1). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0736 A Client Attestation PoP does not name this authorization server’s issuer identifier as its single audience (#229, section 7.2 item 7). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0737 A Client Attestation PoP is older than oauth2.clientAttestationPopMaxAgeS, expired, or dated in the future (#229, section 7.2 item 6). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0738 A Client Attestation PoP carries no challenge where oauth2.clientAttestationChallengeRequired asks for one (#229, section 6.1). token / PAR {error: use_attestation_challenge} (HTTP 400) with an OAuth-Client-Attestation-Challenge header
STS-OAUTH-0739 A Client Attestation PoP’s challenge is not one this realm issued, has expired, or has been used (#229, section 6.1). token / PAR {error: use_attestation_challenge} (HTTP 400) with an OAuth-Client-Attestation-Challenge header
STS-OAUTH-0740 A Client Attestation PoP was presented again: its jti has been used (#229, section 12.1). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0741 The used-assertion history is full of unexpired rows, so a Client Attestation PoP or challenge is refused rather than accepted unrecorded (#229). token / PAR {error: invalid_client} (HTTP 503)
STS-OAUTH-0742 A Client Attestation PoP or challenge could not be recorded as used, so it is refused rather than accepted unrecorded (#229). token / PAR {error: invalid_client} (HTTP 503)
STS-OAUTH-0743 A request carried a Client Attestation and no proof of possession of its key: no OAuth-Client-Attestation-PoP header and no DPoP proof (#229, section 7). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0744 The DPoP combined mode was used at an endpoint that verifies no DPoP proof (introspection, revocation, CIBA) (#229, section 7.3). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0745 In the DPoP combined mode the DPoP proof’s key is not the key the Client Attestation binds (#229, section 7.3 item 4). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0746 A client that declared attest_jwt_client_auth proved its key with DPoP alone, or one that declared attest_jwt_client_auth_dpop sent an OAuth-Client-Attestation-PoP (#229, section 7). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0747 POST /oauth2/challenge in a realm that trusts no client attester (#229, section 6.3). /oauth2/challenge {error: invalid_request} (HTTP 400)
STS-OAUTH-0748 A refresh token issued on a client attestation was redeemed without an attestation of the same client instance key (#229, section 10.3). token {error: invalid_grant} (HTTP 400)
STS-OAUTH-0749 An authorization code pushed under a client attestation was redeemed without an attestation of the same client instance key (#229, section 10.4). token {error: invalid_grant} (HTTP 400)
STS-OAUTH-0750 oauth2.clientAttestationTrustAnchors holds a certificate that cannot be read, or oauth2.clientAttestationTrustedKeys is not a JWKS or holds a symmetric or private key; the unreadable part is ignored (#229). log only
STS-OAUTH-0751 A client that declared attest_jwt_client_auth or attest_jwt_client_auth_dpop sent no OAuth-Client-Attestation header, or did not authenticate with it (#229, section 7.5). token / PAR / introspection / revocation {error: invalid_client} (HTTP 401)
STS-OAUTH-0752 The CIBA notification sweep failed in a realm (#151). none (a log line)
STS-OAUTH-0753 An operator’s retry of a CIBA notification was refused: unknown, not a dead letter, or no endpoint now (#151). console / /admin-api refusal (HTTP 400)
STS-OAUTH-0754 An OpenID Provider Command was not sent because federation.outbound is off (#151). none (a dead letter)
STS-OAUTH-0755 An OpenID Provider Command was not sent because the client’s command_endpoint cannot be dialled (#151). none (a dead letter)
STS-OAUTH-0756 An OpenID Provider Command was refused because the command_endpoint resolves to an internal address in product mode (#151). none (a dead letter)
STS-OAUTH-0757 A command_endpoint’s host name did not resolve (#151). none (a dead letter)
STS-OAUTH-0758 A command_endpoint answered with a redirect, which is not followed (#151). none (a dead letter)
STS-OAUTH-0759 A Command Token could not be built or signed — the client registered alg none, or signing failed (#151). none (a dead letter)
STS-OAUTH-0760 An OpenID Provider Command timed out; retried with backoff (#151). none (retried, then a dead letter)
STS-OAUTH-0761 An OpenID Provider Command failed to connect; retried with backoff (#151). none (retried, then a dead letter)
STS-OAUTH-0762 A command_endpoint answered a status the draft does not name — 5xx, 408 and 429 are retried, the rest are not (#151). none (a dead letter)
STS-OAUTH-0763 A command attempt was deferred because the claim store was unavailable (#151). none (the sweep tries again)
STS-OAUTH-0764 An OpenID Provider Command was still unsent past oauth2.commandRetentionS and was dead-lettered (#151). none (a dead letter)
STS-OAUTH-0765 The provider commands summary line: some were dead- lettered or deferred since the last one (#151). none (a log line)
STS-OAUTH-0766 The provider commands sweep failed in a realm (#151). none (a log line)
STS-OAUTH-0767 No issuer is known for a Command Token: set global.publicBaseUrl, or send one command from the console so the realm’s address is learned (#151). none (a dead letter or a failed run)
STS-OAUTH-0768 A relying party answered a command with invalid_request (section 3) (#151). none (a dead letter)
STS-OAUTH-0769 A relying party answered a command with unrecognized_provider: it does not know this issuer (#151). none (a dead letter)
STS-OAUTH-0770 A relying party answered unsupported_command (#151). none (a dead letter)
STS-OAUTH-0771 A relying party answered incompatible_state: the account was not in a state the command may start from; the state it gave is recorded (#151). none (a dead letter)
STS-OAUTH-0772 A relying party answered access_denied to a migrate command (#151). none (a dead letter)
STS-OAUTH-0773 A relying party answered authentication_not_transferable to a migrate command (#151). none (a dead letter)
STS-OAUTH-0774 An operator’s retry of a command delivery was refused: unknown, not a dead letter, or no command_endpoint now (#151). console / /admin-api refusal (HTTP 400)
STS-OAUTH-0775 A relying party’s answer to a command is not the draft’s: no matching sub and account_state, a metadata answer without commands_supported or context, or a stream that is not text/event-stream (#151). none (a dead letter or a failed run)
STS-OAUTH-0776 A command was not sent: provider commands are off, the command is unknown, the client has no command_endpoint, the person has no subject there, or the client requires an aud_sub none is recorded for (#151). console / /admin-api refusal (HTTP 400)
STS-OAUTH-0777 A tenant command’s stream could not be resumed: the relying party answered last-event-id-unavailable (#151). none (a failed run)
STS-OAUTH-0778 A tenant command’s stream ended without command- complete after every resumption (#151). none (a failed run)
STS-OAUTH-0779 A call to /oauth2/commands/callback carried no callback token, or an unknown or expired one (#151). HTTP 401 {error: invalid_token} with WWW-Authenticate
STS-OAUTH-0780 A call to /oauth2/commands/callback was malformed: an async result not naming the command’s sub and an account_state, or a command_requested other than metadata or audit_tenant (#151). HTTP 400 {error: invalid_request}
STS-OAUTH-0781 An automatic OpenID Provider Command could not be queued after a directory change or a sign-out; the change stands (#151). none (a log line)
STS-OAUTH-0782 The mock relying party’s command endpoint refused a command — the development test control answering as a relying party would (#151). HTTP 400, 401, 409 or 404 {error}
STS-OAUTH-0783 Under FAPI 1.0 Advanced, an authorization request asked for response_type code with a response mode that is not JARM (Part 2 section 5.2.2 item 2, #187). invalid_request
STS-OAUTH-0784 Under FAPI 1.0 Advanced, an authorization request (its signed request object) named no scope; RFC 6749 section 3.3’s refusal rather than a default (#187). invalid_request
STS-OAUTH-0785 An RP-Initiated Logout request carried a post_logout_redirect_uri with neither an id_token_hint nor a client_id, so it was not followed (section 2: nothing confirms the address, #187). none (the sign-out page says so; no redirect)
STS-OAUTH-0786 A CAEP session-revoked (or, for a replay, risk-level-change) about a revoked OAuth grant could not be delivered; the revocation stands (#239). none (a log line)
STS-OAUTH-0787 A realm’s register of revoked token ids reached oauth2.maxRevokedJtis and none of its entries had expired, so the revocation whose token expires soonest was forgotten to make room (#345): that token, if it is still unexpired, is accepted again by a check that asks only this register. none — logged, at most once a minute per process
STS-OAUTH-0788 A person’s identity verifications could not be sealed under a durable key-encryption key, so they were not written; or the sealed value on the entry will not open under this process’s key and is read as none. none (a refusal of the console or API write; verified_claims is omitted on a read)
STS-OAUTH-0789 An authorization code was presented at the token endpoint a second time, and its first presentation redeemed nothing (it was refused, or is still being answered). A code is presented once whatever the outcome (#424) unless oauth2.codeReplayIdempotent relaxes it outside RFC 9700 mode. 400 invalid_grant (RFC 6749 section 4.1.2); the flow starts over
STS-OAUTH-0790 A token exchange was refused because the semantics chosen (delegation or impersonation) are not allowed by the actor’s or the subject’s entry (#186). 400 invalid_request (RFC 8693 section 2.2.2)
STS-OAUTH-0791 A token exchange was refused because the subject has no authority for the application the act stands on: it holds none of the roles that application requires (#186). 400 invalid_request (RFC 8693 section 2.2.2)
STS-OAUTH-0792 A token exchange named more than one audience or resource; an exchange is issued for exactly one (#186). 400 invalid_target (RFC 8693 section 2.2.2)
STS-OAUTH-0793 A token exchange named an audience or resource no application in the realm registers (#186). 400 invalid_target (RFC 8693 section 2.2.2)
STS-OAUTH-0794 A delegation or impersonation token exchange named no audience or resource; only a self exchange defaults to the subject token’s own audience (#186). 400 invalid_target (RFC 8693 section 2.2.2)
STS-OAUTH-0795 A token exchange’s exchange_semantics parameter was neither delegation nor impersonation, or was repeated (#186). 400 invalid_request (RFC 6749 section 5.2)
STS-OAUTH-0796 An RFC 7523 / RFC 7522 / SAML 1.1 assertion presented to a token exchange was addressed to an audience oauth2.tokenExchangeAudience does not accept: not this authorization server, nor (under any-declared-relying-party) an application registered here (#114). 400 invalid_request (RFC 8693 section 2.2.2)
STS-OAUTH-0797 A SAML assertion presented to a token exchange is not the version its declared token type says: saml2 for SAML 2.0, saml1 for SAML 1.1 (#114). 400 invalid_request (RFC 8693 sections 2.2.2 and 3)
STS-OAUTH-0798 An assertion presented to a token exchange verified, and the person it names has no directory entry, so there is nobody to issue a token about or to name as the actor (#114). 400 invalid_request (RFC 8693 section 2.2.2)
STS-OAUTH-0816 No index in the realm’s access-token status list could be allocated because the claim store could not be asked, so the OAuth or GNAP JWT access token was not minted (#432). server_error at the endpoint that was minting the token
STS-OAUTH-0817 The realm’s access-token status list had no free index in thirty-two random attempts (it holds 1,048,576), so the access token was not minted rather than share a live token’s index (draft-ietf-oauth-status-list section 13.3; #432). server_error at the endpoint that was minting the token
STS-OAUTH-0818 The access-token status list could not be built or signed (#432). HTTP 500
STS-OAUTH-0819 A historical access-token status list was asked for (?time=, draft-ietf-oauth-status-list section 8.4); none is kept (#432). HTTP 501
STS-OAUTH-0820 An access token was asked for without a reserved status-list index in a process with a shared claims table, where none can be claimed synchronously; the caller must mint with accessTokenAsync(). A defect in the caller, refused rather than minted on an index no other node was asked about (#432). server_error at the endpoint that was minting the token
STS-OAUTH-0876 An authorization_details entry carried limits, and its type declares no limits schema in the access-type catalogue (#432). 400 invalid_authorization_details (RFC 9396 section 5)
STS-OAUTH-0877 An authorization_details entry’s limits did not meet the limits schema its type declares (#432). 400 invalid_authorization_details (RFC 9396 section 5)
STS-OAUTH-0878 An access token would carry authorization_details of a type the access-type catalogue declares bearer: false, and the request presented neither a DPoP proof nor a client certificate (#432). 400 invalid_authorization_details (RFC 9396 section 5)
STS-OAUTH-0916 An authorization detail’s limits are not ones this service can read: an amount, count, receiver, repeating interval or window that common/access_limits.ts gives no meaning (#432 phase 5). 400 invalid_authorization_details (RFC 9396 section 5)
STS-OAUTH-0917 The authorization_details an Allow on the consent screen lowered would raise a limit, or are not the details the request carries; nothing was issued (#432 phase 5). RFC 9396 section 5 (invalid_authorization_details)
STS-OAUTH-0918 The consent screen was sent limits that raise an authorization detail’s limits rather than lower them, or that cannot be read (#432 phase 5). HTTP 400 invalid_request (the consent form)
STS-OAUTH-0919 Limits lowered on the consent screen no longer meet the authorization detail type’s limits schema (#432 phase 5). HTTP 400 invalid_request (the consent form)
STS-OAUTH-0936 An authorization request’s authorization_details carry a type whose catalogue entry requires an authentication level, and the session — after one sign-in for it — does not meet it (#432 phase 6, RFC 9470). RFC 9470 section 5 (unmet_authentication_requirements)
STS-OAUTH-0937 A token request would issue authorization_details of a type whose catalogue entry requires an authentication level the grant’s authentication does not meet — or a grant with no person behind it (#432 phase 6). RFC 9396 (invalid_authorization_details, HTTP 400)

STS-SAML

SAML 2.0 and SAML 1.1. Both browser SSO profiles, Single Logout, the SAML 1.1 SOAP responder, and service-provider metadata.

Raised from: saml/.

Code What failed Client sees
STS-SAML-0001 A SAML 2.0 sign-in resumed with a held-request id that is unknown or has expired (saml2.requestTtlMin), so there is no AuthnRequest to answer. HTTP 400 page
STS-SAML-0002 The SAMLRequest at the SAML 2.0 Single Sign-On service is not a readable : malformed XML, or another message. HTTP 400 page
STS-SAML-0003 A SAML 2.0 AuthnRequest names no and the path names no service provider, so there is no audience to issue for. HTTP 400 page
STS-SAML-0004 saml2.entityId is empty in a product-mode realm, so the SAML 2.0 identity provider has no name to issue or publish metadata under. HTTP 503 (a page at the SSO service, text/plain at the metadata endpoint)
STS-SAML-0005 In product mode, a SAML 2.0 AuthnRequest’s AssertionConsumerServiceURL is not a samlAssertionConsumerService registered on the service provider’s entry, or none is registered. HTTP 400 page
STS-SAML-0006 The SAML 2.0 assertion consumer service URL is not an absolute http(s) URL. HTTP 400 page
STS-SAML-0007 A SAML 2.0 AuthnRequest asked for a ProtocolBinding this identity provider does not implement (for example PAOS). HTTP 400 page
STS-SAML-0008 A SAML 2.0 AuthnRequest set IsPassive and there is no usable session, so the identity provider may not show the sign-in screen. samlp:Response with status Responder / NoPassive
STS-SAML-0009 The sign-in screen reported that a SAML 2.0 sign-in was cancelled or failed. samlp:Response with status Responder / AuthnFailed
STS-SAML-0010 The issuance policy refused a SAML 2.0 assertion for this person to this service provider. samlp:Response with status Responder / RequestDenied
STS-SAML-0011 In product mode, a SAML 2.0 assertion configured to be encrypted could not be encrypted (no usable certificate), so none was sent. samlp:Response with status Responder and no assertion
STS-SAML-0012 A SAML 2.0 assertion or logout NameID could not be encrypted to the service provider’s certificate (usually a non-RSA key) and went out in clear. —
STS-SAML-0013 A SAML 2.0 protocol message (Response, LogoutResponse or LogoutRequest) could not be signed and was sent unsigned. —
STS-SAML-0014 The SAML 2.0 identity provider metadata could not be signed and was served unsigned. —
STS-SAML-0015 The body posted to the SAML 2.0 Artifact Resolution Service is not XML. SOAP samlp:ArtifactResponse with status Requester (HTTP 200)
STS-SAML-0016 The SOAP body posted to the SAML 2.0 Artifact Resolution Service carries no . SOAP samlp:ArtifactResponse with status Requester (HTTP 200)
STS-SAML-0017 A SAML 2.0 ArtifactResolve carries no . SOAP samlp:ArtifactResponse with status Requester (HTTP 200)
STS-SAML-0018 A SAML 2.0 artifact does not resolve: never issued here, expired (saml2.artifactTtlS), or already resolved once. SOAP samlp:ArtifactResponse with status Requester (HTTP 200)
STS-SAML-0019 The SAMLRequest at the SAML 2.0 Single Logout service is not a readable . HTTP 400 page
STS-SAML-0020 A SAML 2.0 LogoutRequest carried an this service could not decrypt, so the session was not ended. HTTP 400 page
STS-SAML-0021 The mock SAML 2.0 service provider was handed an artifact that does not resolve (already resolved, expired or never issued). HTTP 200 error page
STS-SAML-0022 A response delivered to the mock SAML 2.0 service provider failed at least one of its verification checks. HTTP 200 page listing the failed checks
STS-SAML-0023 A SAML 2.0 assertion could not be signed and was returned unsigned. —
STS-SAML-0024 A SAML 1.1 assertion could not be signed and was returned unsigned. —
STS-SAML-0025 A SAML 1.1 browser flow resumed with a held-flow id that is unknown or has expired (saml11.requestTtlMin). HTTP 400 page
STS-SAML-0026 A SAML 1.1 flow named a profile other than post or artifact in the non-spec profile parameter. HTTP 400 page
STS-SAML-0027 saml11.providerId is empty in a product-mode realm, so the SAML 1.1 identity provider has no name to issue or publish metadata under. HTTP 503 page or text/plain at the inter-site transfer service and metadata; samlp:Response status Responder at the SAML responder
STS-SAML-0028 In product mode, a SAML 1.1 flow’s shire is not a samlAssertionConsumerService registered on the relying party’s entry, or none is registered. HTTP 400 page
STS-SAML-0029 The SAML 1.1 assertion consumer URL is not an absolute http(s) URL. HTTP 400 page
STS-SAML-0030 A SAML 1.1 flow names no relying party: no providerId, no path segment and no TARGET origin to take one from. HTTP 400 page
STS-SAML-0031 The sign-in screen reported that a SAML 1.1 sign-in was cancelled or failed. HTTP 400 page
STS-SAML-0032 The issuance policy refused a SAML 1.1 assertion for this person to this relying party. HTTP 403 page
STS-SAML-0033 A SAML 1.1 could not be signed and was sent unsigned. —
STS-SAML-0034 The SAML 1.1 identity provider metadata could not be signed and was served unsigned. —
STS-SAML-0035 The body posted to the SAML 1.1 SAML responder is not XML. SOAP samlp:Response with status samlp:Requester (HTTP 200)
STS-SAML-0036 The SOAP body posted to the SAML 1.1 SAML responder carries no . SOAP samlp:Response with status samlp:Requester (HTTP 200)
STS-SAML-0037 A SAML 1.1 artifact does not resolve: never issued here, expired (saml11.artifactTtlS), or already resolved once. SOAP samlp:Response with status samlp:Requester (HTTP 200)
STS-SAML-0038 A SAML 1.1 AssertionIDReference names an assertion this service does not hold. SOAP samlp:Response with status samlp:Requester (HTTP 200)
STS-SAML-0039 A SAML 1.1 AttributeQuery or AuthenticationQuery was refused in product mode: it names no registered relying party (Resource or the path segment), or its caller did not authenticate as that relying party (a signed Request or its registered certificate at the TLS handshake). Until #189 every query was refused in product. SOAP samlp:Response with status samlp:Requester (HTTP 200)
STS-SAML-0040 A SAML 1.1 query carries no with a NameIdentifier. SOAP samlp:Response with status samlp:Requester (HTTP 200)
STS-SAML-0041 A SAML 1.1 carries none of the four request types the responder answers (an AuthorizationDecisionQuery included). SOAP samlp:Response with status samlp:Requester (HTTP 200)
STS-SAML-0042 The mock SAML 1.1 relying party was handed an artifact that does not resolve (already resolved, expired or never issued). HTTP 400 page
STS-SAML-0043 A response delivered to the mock SAML 1.1 relying party failed at least one of its verification checks. HTTP 200 page listing the failed checks
STS-SAML-0044 A service provider metadata refresh named an application that is not in the registry. —
STS-SAML-0045 Service provider metadata was not fetched because federation.outbound is off. —
STS-SAML-0046 Service provider metadata was not fetched because samlSpMetadataUrl is empty, not a URL, or not a scheme the outbound policy dials. —
STS-SAML-0047 The service provider metadata URL answered with a redirect, which is not followed. —
STS-SAML-0048 The service provider metadata URL answered with a status other than 200. —
STS-SAML-0049 The service provider metadata document exceeded saml2.spMetadataMaxBytes and the fetch was abandoned. —
STS-SAML-0050 The service provider metadata URL did not answer within federation.outboundTimeoutMs. —
STS-SAML-0051 The service provider metadata request failed at the network or TLS layer (DNS, connection refused, untrusted certificate). —
STS-SAML-0052 Fetched service provider metadata is unusable: not well-formed, an EntitiesDescriptor, or no KeyDescriptor usable for encryption. —
STS-SAML-0053 Fetched service provider metadata carries a certificate this service cannot use (unreadable, or not an RSA key). —
STS-SAML-0054 The application entry refused the metadata and encryption certificate a refresh fetched. —
STS-SAML-0055 A SAML 2.0 sign-in came back from its one trip to the sign-in screen without a fresh authentication (ForceAuthn) or without a session, and was answered AuthnFailed rather than sent again. Response status AuthnFailed
STS-SAML-0056 A SAML 2.0 sign-in came back from its one trip to the sign-in screen with a session that still does not meet the RequestedAuthnContext, and was answered NoAuthnContext. Response status NoAuthnContext
STS-SAML-0057 A SAML 2.0 artifact this process still held was already resolved by another process against the same store (the cluster claim, #46); section 3.6.4.1 allows one resolution. ArtifactResponse with StatusCode Requester (HTTP 200)
STS-SAML-0058 A SAML 1.1 artifact this process still held was already resolved by another process against the same store (the cluster claim, #46); saml-bindings-1.1 section 3.2.3 allows one resolution. samlp:Response with StatusCode samlp:Requester (HTTP 200)
STS-SAML-0059 The cluster claim store could not be asked whether a SAML artifact (2.0 or 1.1) was already resolved, so it was refused rather than resolved unproven. StatusCode Responder (HTTP 200)
STS-SAML-0060 An artifact resolution (2.0 or 1.1) failed while its answer was being built or sent, after the artifact had been spent. StatusCode Responder (HTTP 200) when nothing was sent yet
STS-SAML-0061 A SAML 2.0 service provider’s AuthnRequest, LogoutRequest or LogoutResponse carried a signature (the Redirect binding’s query signature or an enveloped one) that does not verify against any of its registered signing certificates. Refused in every mode. an HTTP 403 page; no Response is sent and no session ends
STS-SAML-0062 A SAML 2.0 service provider’s request signature could not be checked at all — an algorithm common/crypto.js does not verify (MD5, a MAC, HSS/LMS…), an unreadable key, a reference naming something other than the message (signature wrapping), a malformed signature, or a Signature parameter without the SAMLRequest and SigAlg it signs. Refused in every mode. an HTTP 403 page; no Response is sent and no session ends
STS-SAML-0063 An unsigned SAML 2.0 AuthnRequest, LogoutRequest or LogoutResponse — or a signed one with no registered certificate to verify it — was refused because signed requests are required (saml2.requireSignedAuthnRequests, on in product by default, or the service provider’s metadata saying AuthnRequestsSigned). an HTTP 403 page; no Response is sent and no session ends
STS-SAML-0064 (retired) A SAML 2.0 service provider’s request was signed with an inclusive canonicalization, which this service did not verify. Retired 2026-09-17: the signed element is the message root, so inclusive c14n is verified like exclusive. an HTTP 403 page
STS-SAML-0065 A service provider’s metadata document was not consumed: samlSpMetadataSigningCertificate is set and the document is unsigned or its signature does not verify against that certificate. the caller’s refusal (errors on a console or /admin-api reply)
STS-SAML-0066 A service provider’s metadata document was not consumed: its entityID is not the application it was refreshed or uploaded for. the caller’s refusal (errors on a console or /admin-api reply)
STS-SAML-0067 An uploaded service provider metadata document exceeded saml2.spMetadataMaxBytes and was not read. the caller’s refusal (errors on a console or /admin-api reply)
STS-SAML-0068 A service provider’s metadata document was not consumed: its validUntil has already passed. the caller’s refusal (errors on a console or /admin-api reply)
STS-SAML-0069 An AuthnRequest named an AssertionConsumerServiceIndex that no endpoint in the service provider’s consumed metadata has, or whose endpoint is on a binding this identity provider does not deliver on. an HTTP 400 page; no Response is sent
STS-SAML-0070 An AuthnRequest named an AssertionConsumerServiceURL that is not one of the endpoints in the service provider’s consumed metadata (in every mode). an HTTP 400 page; no Response is sent
STS-SAML-0071 An AuthnRequest’s NameIDPolicy asked for a Format the service provider’s consumed metadata does not declare. a Response with StatusCode Requester / InvalidNameIDPolicy
STS-SAML-0072 An AuthnRequest named no assertion consumer service, and no endpoint in the service provider’s consumed metadata is on a binding this identity provider delivers on (or on the ProtocolBinding asked for). an HTTP 400 page; no Response is sent
STS-SAML-0073 A SAML 2.0 service provider’s AuthnRequest, LogoutRequest, LogoutResponse or ArtifactResolve was signed with SHA-1 (its SignatureMethod or a DigestMethod) and saml.allowSha1Signatures is off, the default. Refused in every mode. an HTTP 403 page (a SOAP ArtifactResponse with StatusCode Requester for ArtifactResolve); no Response is sent
STS-SAML-0074 A SAML 2.0 service provider’s AuthnRequest, LogoutRequest, LogoutResponse or ArtifactResolve was refused because the metadata consumed for it has EXPIRED — its effective validUntil (the earliest on the EntitiesDescriptor, EntityDescriptor and SPSSODescriptor) has passed. Refused in every mode until a newer document is consumed. an HTTP 403 page (a SOAP ArtifactResponse with StatusCode Requester for ArtifactResolve); no Response is sent
STS-SAML-0075 A Metadata Query (MDQ) import was asked for and saml2.mdqBaseUrl is not set in the realm. the caller’s refusal (errors on a console or /admin-api reply)
STS-SAML-0076 The background refresh of a service provider’s stale metadata failed (the fetch, or consuming what it fetched). Recorded when the state changes and summarised hourly while it persists; the last good document stays in force until its validUntil. —
STS-SAML-0077 A SAML 2.0 ArtifactResolve or SAML 1.1 artifact Request came from a caller that is not authenticated — no signature verifying against the party’s registered certificates and no TLS client certificate that is one of them — where authenticated callers are required (saml2.requireSignedAuthnRequests, on in product by default). The artifact is not spent. a SOAP response with StatusCode Requester (HTTP 200)
STS-SAML-0078 An artifact was asked for by a party other than the one it was issued to (an ArtifactResolve whose Issuer, or a SAML 1.1 responder path, names another). Refused in every mode; the artifact is not spent. a SOAP response with StatusCode Requester (HTTP 200)
STS-SAML-0079 A service provider metadata fetch (a refresh, the background refresher or an MDQ lookup) was refused because the host resolves to a loopback, private, link-local or reserved address, or did not resolve, in product mode (federation_http.ts vetHost()). the caller’s refusal (errors on a console or /admin-api reply)
STS-SAML-0080 A Metadata Query (MDQ) lookup started by a request from an entityID nobody registered was not made: the realm is in product mode (mode.registersFromMetadataQuery()) and has no saml2.metadataTrustAnchors, so no answer could be verified. Nothing is fetched or created; the entityID is listed as refused on the SAML 2.0 page. —
STS-SAML-0081 A Metadata Query (MDQ) answer for an entityID nobody registered, fetched for a lookup a request started, did not verify against any of the realm’s saml2.metadataTrustAnchors (product mode). Nothing is created; the entityID is listed as refused on the SAML 2.0 page. —
STS-SAML-0082 A SAML 2.0 per-service-provider path (/saml2/metadata/{sp}, /saml2/sso/{sp}, /saml2/slo/{sp} or /saml2/ars/{sp}) named something that is not a registered SAML 2.0 service provider, in product mode (mode.publishesMetadataForUnregisteredProviders()). an HTTP 404, text/plain
STS-SAML-0083 A SAML 1.1 per-relying-party path (/saml11/metadata/{rp}, /saml11/sso/{rp} or /saml11/responder/{rp}) named something that is not a registered SAML 1.1 relying party, in product mode (mode.publishesMetadataForUnregisteredProviders()). an HTTP 404, text/plain
STS-SAML-0084 An administrator’s Import from MDQ was refused: the realm is in product mode and has no saml2.metadataTrustAnchors, so the answer could not be verified, and saml2.mdqImportWithoutAnchors is off. the caller’s refusal (errors on a console or /admin-api reply)
STS-SAML-0085 A SAML 2.0 AuthnRequest or LogoutRequest was refused: its Destination is not the URL it arrived at (saml-core-2.0-os section 3.2.1), or it is signed and names no Destination (saml-bindings-2.0-os sections 3.4.5.2 and 3.5.5.2). #190. an HTTP 400 page
STS-SAML-0086 A SAML 2.0 AuthnRequest or LogoutRequest was refused: its IssueInstant is missing, not a dateTime, more than a minute in the future, or older than saml2.requestTtlMin (plus a minute). #190. an HTTP 400 page
STS-SAML-0087 A SAML 2.0 AuthnRequest or LogoutRequest was refused: its Version is not “2.0” (saml-core-2.0-os section 3.2.2.1). #190. an HTTP 400 page
STS-SAML-0088 A SAML 2.0 AuthnRequest was refused as a REPLAY: its issuer and ID arrived before, inside the freshness window (the claim scope saml2.authnrequest). #190. an HTTP 400 page
STS-SAML-0089 A SAML 2.0 AuthnRequest was refused because the claim store that records which requests were answered could not be asked (fail closed). #190. an HTTP 400 page
STS-SAML-0090 A SAML 2.0 LogoutRequest with no session cookie (a back-channel logout) named a SessionIndex whose session did not sign into that service provider, or was issued another NameID there. Nothing was ended. #192. a LogoutResponse with StatusCode Requester / UnknownPrincipal
STS-SAML-0091 An identity-provider-initiated sign-in (/saml2/unsolicited) was refused: saml2.unsolicitedSso is off in the realm. #189. an HTTP 403 page
STS-SAML-0092 An identity-provider-initiated sign-in (/saml2/unsolicited) named no service provider (providerId or the path segment). #189. an HTTP 400 page
STS-SAML-0093 An identity-provider-initiated sign-in asked for a binding a Response does not go on (anything but HTTP-POST, POST-SimpleSign or HTTP-Artifact). #189. an HTTP 400 page
STS-SAML-0094 A SAML 2.0 AttributeQuery named a subject no live session here gave the asking service provider (by the NameID it was issued), or that session has ended. #189. SOAP samlp:Response, Requester / UnknownPrincipal (HTTP 200)
STS-SAML-0095 The SAML 2.0 attribute authority received no , or one naming no Issuer. #189. SOAP samlp:Response, Requester (HTTP 200)
STS-SAML-0096 A SAML 1.1 AttributeQuery or AuthenticationQuery in product mode named a subject no live session here gave the asking relying party (by the NameIdentifier it was issued). #189. SOAP samlp:Response with status samlp:Requester (HTTP 200)
STS-SAML-0097 The TLS certificate the SAML back channel presents (this process’s main-port leaves, or another cluster node’s off its membership row) could not be read while a SAML 2.0 or SAML 1.1 metadata document was built, so the document went out without that KeyDescriptor and a service provider authenticating the back channel from metadata will refuse the node it names none for. #248. none — the metadata is served (HTTP 200) without the key

STS-WSTRUST

WS-Trust. The security token service, WS-Trust 1.0 through 1.4.

Raised from: ws-trust/.

Code What failed Client sees
STS-WSTRUST-0001 The RequestSecurityToken body is not well-formed XML (or is empty), so no operation could be read from it. SOAP Fault soap:Sender / soap:Client (HTTP 400)
STS-WSTRUST-0002 A WS-Security UsernameToken was presented without a username or without a password. SOAP Fault soap:Sender / soap:Client (HTTP 500)
STS-WSTRUST-0003 A WS-Security UsernameToken’s password was refused by the credential verifier (the reserved string in development, the stored userPassword in product). The fault does not say whether the user or the password was wrong. SOAP Fault soap:Sender / soap:Client (HTTP 500)
STS-WSTRUST-0004 Product mode: a SAML assertion presented as the requester’s credential or inside OnBehalfOf/ActAs does not verify against this STS’s own signing certificate. SOAP Fault soap:Sender / soap:Client (HTTP 500)
STS-WSTRUST-0005 Product mode: a SAML assertion presented to the STS is not yet valid (its Conditions NotBefore is in the future beyond the clock skew). SOAP Fault soap:Sender / soap:Client (HTTP 500)
STS-WSTRUST-0006 Product mode: a SAML assertion presented to the STS has expired (its Conditions NotOnOrAfter has passed beyond the clock skew). SOAP Fault soap:Sender / soap:Client (HTTP 500)
STS-WSTRUST-0007 Product mode: a SAML assertion presented to the STS carries no NameID, so it names nobody. SOAP Fault soap:Sender / soap:Client (HTTP 500)
STS-WSTRUST-0008 Product mode: a wst:OnBehalfOf or wst14:ActAs element carries no SAML assertion, so the delegated subject is only a name. SOAP Fault soap:Sender / soap:Client (HTTP 500)
STS-WSTRUST-0009 Product mode: a request delegates (OnBehalfOf/ActAs) but presents no credential of its own for the requester. SOAP Fault soap:Sender / soap:Client (HTTP 500)
STS-WSTRUST-0010 Product mode: a WS-Trust request presented no credential at all in its security header. SOAP Fault soap:Sender / soap:Client (HTTP 500)
STS-WSTRUST-0011 The issuance policy (the role gate) refused a token for this subject to this AppliesTo. SOAP Fault soap:Sender / soap:Client (HTTP 403)
STS-WSTRUST-0012 ?encrypt=1 was requested but the request carries no recipient X509Certificate to encrypt the assertion to. Product mode refuses; development returns the assertion in clear and logs this. SOAP Fault soap:Sender / soap:Client (HTTP 500) in product; none in development
STS-WSTRUST-0013 ?encrypt=1 was requested and encrypting the assertion to the request’s certificate failed. Product mode refuses; development returns the assertion in clear and logs this. SOAP Fault soap:Sender / soap:Client (HTTP 500) in product; none in development
STS-WSTRUST-0014 A Validate request carried no token in its ValidateTarget, so it was answered with a status of invalid. wst:Status wst:Code …/status/invalid (HTTP 200)
STS-WSTRUST-0015 The STS endpoint threw an unexpected exception while handling a RequestSecurityToken. SOAP 1.2 Fault soap:Sender (HTTP 500)
STS-WSTRUST-0016 A token was issued but starting the browser sign-on session the exchange also starts threw; the RSTR is unaffected. —
STS-WSTRUST-0017 A JWT was refused because the directory holds no entry for the person, so there is no subject to issue it about. SOAP Fault (HTTP 400)
STS-WSTRUST-0018 An OnBehalfOf or ActAs request was refused by the issuance policy (#186): the subject may not be delegated, the requester may not act for this subject, the subject token’s may_act names somebody else, or no delegation relationship allows the AppliesTo. Product mode only; development records what would have been refused. SOAP Fault wst:RequestFailed (HTTP 500), WS-Trust 1.4 section 11
STS-WSTRUST-0019 An OnBehalfOf or ActAs request was refused because its requester may not act for anybody here: it has no entry in this realm, or it is a person who does not hold the role delegation.actorRole names (#186). SOAP Fault wst:RequestFailed (HTTP 500), WS-Trust 1.4 section 11
STS-WSTRUST-0020 An OnBehalfOf or ActAs request was refused because no issuance policy gave a verdict on it, or a realm’s policy refused it with no rule this service names (#186). Product mode only. SOAP Fault wst:RequestFailed (HTTP 500), WS-Trust 1.4 section 11
STS-WSTRUST-0021 A Cancel request in the WS-Trust 2004/04 namespace, which defines no Cancel binding (no CancelTarget, no RequestedTokenCancelled); it was added in 2005/02 (#188). SOAP Fault wst:InvalidRequest (HTTP 500), in the request’s trust namespace
STS-WSTRUST-0022 An OnBehalfOf or ActAs request was refused because the semantics it asked for (impersonation or delegation) are not allowed by the requester’s or the subject’s entry (#186). SOAP Fault wst:RequestFailed (WS-Trust 1.4 section 11)
STS-WSTRUST-0023 An OnBehalfOf or ActAs request was refused because the subject has no authority for the application the act stands on (#186). SOAP Fault wst:RequestFailed (WS-Trust 1.4 section 11)
STS-WSTRUST-0024 An OnBehalfOf or ActAs request named no AppliesTo, or one no application registers, and is not a self request (#186). SOAP Fault wst:RequestFailed (WS-Trust 1.4 section 11)
STS-WSTRUST-0025 A request carried both and , which ask for impersonation and delegation at once (#186). SOAP Fault wst:InvalidRequest (WS-Trust 1.4 section 11)

STS-WSFED

WS-Federation. The passive requestor profile and the mock relying party.

Raised from: ws-federation/.

Code What failed Client sees
STS-WSFED-0001 A wsignin1.0 request carried wreqptr, which this service refuses to dereference (fetching a URL from a query parameter would be a server-side request forgery). HTTP 400 error page (the profile defines no error response)
STS-WSFED-0002 A wsignin1.0 request named no wtrealm, so there is no relying party to issue a token for. HTTP 400 error page (the profile defines no error response)
STS-WSFED-0003 Product mode: the wreply is not one of the wsfedReplyUrl values registered on the wtrealm’s application entry (or none is registered). HTTP 400 error page (the profile defines no error response)
STS-WSFED-0004 The resolved wreply is not an absolute http(s) URL, so the sign-in response form would post back to this service. HTTP 400 error page (the profile defines no error response)
STS-WSFED-0005 The request (wreq TokenType or the non-spec tokenType parameter) asked for a token type other than SAML 1.1 or SAML 2.0. HTTP 400 error page (the profile defines no error response)
STS-WSFED-0006 wauth demanded an authentication method this identity provider cannot perform or report. HTTP 400 error page (the profile defines no error response)
STS-WSFED-0007 The sign-in at the authentication service was cancelled or failed, so nothing is posted to the relying party. HTTP 200 error page; the relying party is never posted to
STS-WSFED-0008 wfresh is not a non-negative number of minutes. HTTP 400 error page (the profile defines no error response)
STS-WSFED-0009 wauth demanded a hardware token, the person was sent to sign in again with a second factor required (a step-up), and the session that came back still used no security key. HTTP 400 error page (the profile defines no error response)
STS-WSFED-0010 wauth demanded multi-factor authentication, the person was sent to sign in again with a second factor required (a step-up), and the session that came back still had only one factor. HTTP 400 error page (the profile defines no error response)
STS-WSFED-0011 The issuance policy (the role gate) refused a token for the signed-in person to this wtrealm. HTTP 403 error page
STS-WSFED-0012 The request asked for wattr1.0 (attribute service) or wpseudo1.0 (pseudonym service), neither of which is implemented. HTTP 501 error page
STS-WSFED-0013 The passive requestor endpoint was sent a wa value it does not understand. HTTP 400 error page (the profile defines no error response)
STS-WSFED-0014 The wreq parameter is not readable XML; it is ignored and the default token type is used. —
STS-WSFED-0015 The WS-Federation metadata document could not be signed and was served unsigned. —
STS-WSFED-0016 The mock relying party at /wsfed/rp received a sign-in response that failed one or more of its verification checks. HTTP 200 page listing the failed checks

STS-FED

Federation. Relationships with foreign identity providers and service providers, in either direction, including the outbound requests made to a partner.

Raised from: federation/.

Code What failed Client sees
STS-FED-0001 A federation endpoint (login or assertion consumer service) was reached while federation.enabled is off. HTTP 404 page
STS-FED-0002 A federation login or assertion consumer service request named a relationship that does not exist (or, at the ACS, is not service-provider side). HTTP 404 page
STS-FED-0003 Federation service provider metadata was asked for a relationship that is not a SAML service-provider-side relationship. HTTP 404 page
STS-FED-0004 A federated sign-in was started through an identity-provider-side relationship, which has nothing to sign in to. HTTP 400 page
STS-FED-0005 A federated sign-in or partner response arrived for a relationship that is disabled. HTTP 403 page
STS-FED-0006 A federated sign-in or partner response arrived for a relationship that is enabled but missing a field its protocol needs. HTTP 409 page at login, HTTP 403 page at the assertion consumer service
STS-FED-0007 The federation assertion consumer service received no SAMLResponse or no wresult. HTTP 400 page
STS-FED-0008 A partner’s SAMLResponse could not be base64-decoded. HTTP 400 page
STS-FED-0009 A partner’s SAMLResponse or WS-Federation wresult is not well-formed XML, or has no document element. HTTP 400 page
STS-FED-0010 A federation partner answered with a SAML status other than Success: it declined to authenticate the person. HTTP 400 page
STS-FED-0011 A partner’s SAML Response or WS-Federation token carried no and no , an encrypted one reached a SAML 1.1 relationship (which has no encryption construct), or what one decrypted to is not an assertion. HTTP 400 page
STS-FED-0012 A partner’s SAML assertion or response carries no XML signature at all, so it is refused as unauthenticated. HTTP 401 page
STS-FED-0013 A partner’s XML signature did not verify against the fedSigningCertificate configured on the relationship (a certificate inside the document is never used). HTTP 401 page
STS-FED-0014 A partner’s assertion arrived for a relationship with no fedSigningCertificate, so nothing can be verified and nothing is accepted. HTTP 401 page
STS-FED-0015 A partner’s verified assertion names an issuer other than the relationship’s fedPeer. HTTP 401 page
STS-FED-0016 A partner’s assertion arrived for a relationship with no fedPeer, so its issuer cannot be checked and it is refused. HTTP 401 page
STS-FED-0017 A partner’s assertion is not yet valid (NotBefore is in the future beyond oauth2.clockSkewS). HTTP 401 page
STS-FED-0018 A partner’s assertion has expired (NotOnOrAfter has passed beyond oauth2.clockSkewS); a replay or clock disagreement. HTTP 401 page
STS-FED-0019 A partner’s SAML 2.0 assertion carries no AudienceRestriction, which the Web Browser SSO profile requires. HTTP 401 page
STS-FED-0020 A partner’s assertion is addressed to an audience other than this service’s entityID or fedClientId for the relationship. HTTP 401 page
STS-FED-0021 A partner’s response came back with no RelayState, wctx or state, so it cannot be matched to a sign-in this service started (unsolicited). HTTP 401 page
STS-FED-0022 A partner’s response carried a RelayState, wctx or state this service did not mint, or whose sign-in expired or was already spent (a replay or forgery). HTTP 401 page
STS-FED-0023 A partner’s SAML 2.0 assertion InResponseTo names a different AuthnRequest from the one this sign-in sent. HTTP 401 page
STS-FED-0024 A sign-out arrived at the federation assertion consumer service — a WS-Federation wa other than wsignin1.0, or a SAML LogoutRequest — where it is not consumed: a partner’s sign-out goes to /federation/slo/{id} (#167). HTTP 400 page
STS-FED-0025 An OAuth 2.0 / OpenID Connect partner redirected back with an error instead of a code. HTTP 400 page
STS-FED-0026 An OpenID Connect partner configured for a front-channel ID Token posted back no id_token. HTTP 400 page
STS-FED-0027 An OAuth 2.0 / OpenID Connect partner redirected back with neither a code nor an error. HTTP 400 page
STS-FED-0028 An OpenID Connect partner’s token response carried no id_token. HTTP 502 page
STS-FED-0029 An OAuth 2.0 partner’s token response carried no access_token. HTTP 502 page
STS-FED-0030 fedJwks on the relationship is not valid JSON, so there is no key to verify a partner’s JWT with. HTTP 500 page
STS-FED-0031 Neither fedJwks nor fedJwksUri is configured on the relationship, so there is no key to verify a partner’s JWT with. HTTP 500 page
STS-FED-0032 A partner’s ID Token or access token has a header that is not base64url JSON, or names no alg. HTTP 401 page
STS-FED-0033 A partner’s ID Token or access token declares alg=none — an unsigned token presented as signed. HTTP 401 page
STS-FED-0034 A partner’s JWT names a kid the partner’s key set does not contain (a key rotation, or a forgery). HTTP 401 page
STS-FED-0035 The partner’s key set is empty, so no JWT from it can be verified. HTTP 401 page
STS-FED-0036 A partner’s JWT signature did not verify against any key in its set with the key’s algorithm family, or a key could not be read. HTTP 401 page
STS-FED-0037 A partner’s JWT is expired or not yet valid beyond oauth2.clockSkewS. HTTP 401 page
STS-FED-0038 A partner’s JWT audience is not fedClientId or its issuer is not fedPeer. HTTP 401 page
STS-FED-0039 A partner’s ID Token nonce does not match the nonce this sign-in sent (a replayed ID Token). HTTP 401 page
STS-FED-0040 The optional UserInfo request to an OpenID Connect partner failed; the sign-in continued on the verified ID Token without those attributes. —
STS-FED-0041 A plain OAuth 2.0 partner returned an access token this service cannot read and no fedUserinfoUrl is configured, so nobody can be named. HTTP 500 page
STS-FED-0042 This service threw while consuming a partner’s response or finishing a federated sign-in. HTTP 500 page
STS-FED-0043 A partner’s assertion verified but yielded no username: no subject, and no fedUsernameSource attribute. HTTP 400 page
STS-FED-0044 The issuance policy refused a session for a person arriving through a federation relationship. HTTP 403 page
STS-FED-0045 The application registry threw while recording the foreign identity provider after a federated sign-in; the sign-in stood. —
STS-FED-0046 A caller asked federation_http.js to dial an attribute outside DIALLABLE — a bug in the caller, refused. HTTP 502 or 500 page for the federated sign-in it was part of
STS-FED-0047 A back-channel request to a federation partner was not made because federation.outbound is off. HTTP 502 or 500 page for the federated sign-in it was part of
STS-FED-0048 A back-channel URL on a federation relationship cannot be dialled: empty, not a URL, plain http with federation.outboundAllowHttp off, or another scheme. HTTP 502 or 500 page for the federated sign-in it was part of
STS-FED-0049 A federation partner answered a back-channel request with a redirect, which is not followed. HTTP 502 or 500 page for the federated sign-in it was part of
STS-FED-0050 A federation partner’s back-channel response exceeded federation.maxResponseBytes and was abandoned. HTTP 502 or 500 page for the federated sign-in it was part of
STS-FED-0051 A federation partner answered a back-channel request with a non-2xx status. HTTP 502 or 500 page for the federated sign-in it was part of
STS-FED-0052 A federation partner’s back-channel response stream failed part way through. HTTP 502 or 500 page for the federated sign-in it was part of
STS-FED-0053 A back-channel request to a federation partner could not be built from its options. HTTP 502 or 500 page for the federated sign-in it was part of
STS-FED-0054 A federation partner did not answer a back-channel request within federation.outboundTimeoutMs. HTTP 502 or 500 page for the federated sign-in it was part of
STS-FED-0055 A back-channel request to a federation partner failed at the network or TLS layer (DNS, connection refused, untrusted certificate). HTTP 502 or 500 page for the federated sign-in it was part of
STS-FED-0056 A federation partner answered a back-channel request with a 2xx status whose body is not JSON. HTTP 502 or 500 page for the federated sign-in it was part of
STS-FED-0057 The application registry threw while checking whether an application is configured for a federation relationship; the per-application count was skipped. —
STS-FED-0058 The application registry threw while listing the applications using a federation relationship; the map is drawn without that half. —
STS-FED-0059 The federation register threw while recording a successful use of a relationship; the sign-in stood. —
STS-FED-0060 The federation register threw while recording a refused sign-in on a relationship (fedLastError). —
STS-FED-0061 Creating a federation relationship was refused: the id, role or protocol is not valid. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0062 Creating a federation relationship was refused: no embedded directory is loaded to hold it. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0063 Creating a federation relationship was refused: one with that id already exists. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0064 Creating a federation relationship was refused: ou=federations is at federation.max or the directory is full. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0065 An update or deletion named a federation relationship that does not exist. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0066 An update named a field that is not an attribute of a federation relationship. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0067 An update named a federation relationship field that is not editable (identity, or a recorded counter). action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0068 An update named a field belonging to the other direction of relationship. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0069 An update asked to remove a value a multi-valued relationship field does not carry. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0070 An update asked to add an empty value to a multi-valued relationship field. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0071 An update asked to add a value a multi-valued relationship field already carries. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0072 The directory refused the write for an update to a federation relationship. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0073 The directory would not delete a federation relationship. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0090 A federated sign-in verified, but the directory holds no entry for the person and none was created (dynamic provisioning off on the relationship, or the directory declined), so no session was started. HTTP 403 page
STS-FED-0091 A federated sign-in verified, but the relationship’s fedSubjectPolicy is pre-linked and no entry carries a federationLink for the partner’s subject. HTTP 403 page
STS-FED-0092 A federated sign-in verified, but the person it would sign in is outside the relationship’s subject rules (fedSubjectGroup, fedSubjectDomain or fedSubjectPattern). HTTP 403 page
STS-FED-0093 A federated sign-in named a console administrator (Admin Read or Admin Write) or a holder of REMOTE_PEPS, and the relationship does not set fedMayAssertAdministrators. HTTP 403 page
STS-FED-0094 A federated sign-in arrived at a relationship whose fedSubjectPolicy is any-existing, which product mode refuses (mode.matchesFederatedNames()). HTTP 403 page
STS-FED-0095 An update asked for fedSubjectPolicy any-existing in product mode. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0096 A federated sign-in carried no stable subject to link: an empty subject, a SAML 2.0 transient NameID, or an issuer that cannot be part of a federationLink. HTTP 403 page
STS-FED-0097 A federated sign-in’s federationLink is carried by more than one directory entry, so which person it names is ambiguous. HTTP 403 page
STS-FED-0098 A federated sign-in would create a namespaced entry, and an entry of that name already exists without a link to this subject. HTTP 403 page
STS-FED-0099 First-sign-in linking ended without a local sign-in: the person cancelled at the sign-in screen, or it refused them. HTTP 403 page
STS-FED-0100 The linking step named a handle this service did not mint, one already spent, or one that expired. HTTP 400 page
STS-FED-0101 The linking step was reached without a fresh local sign-in, through that step, as the person being linked. HTTP 403 page
STS-FED-0102 An update set fedSubjectPolicy to a value that is not one of the four. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0103 An update set fedSubjectPattern to a pattern that does not compile, is longer than 256 characters, or nests a quantifier or uses a backreference. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0104 A federation link or unlink named no person, or a person the directory holds no entry for. action result ok:false (console redirect, /admin-api HTTP 400, or SCIM 400 invalidValue)
STS-FED-0105 A federation link named no relationship, or one that is not a service-provider-side relationship in this realm. action result ok:false (console redirect, /admin-api HTTP 400, or SCIM 400 invalidValue)
STS-FED-0106 A federation link carried no subject, or an issuer or subject that cannot be written as a federationLink value. action result ok:false (console redirect, /admin-api HTTP 400, or SCIM 400 invalidValue)
STS-FED-0107 A federation link is already carried by a different person. action result ok:false (console redirect, /admin-api HTTP 400, or SCIM 409 uniqueness)
STS-FED-0108 A federation unlink named a link the person does not carry. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0109 The directory would not write a federation link or unlink. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0110 A federation link was removed and ending the sessions that partner had signed the person in to failed; the unlink stands. —
STS-FED-0111 The linking step was reached in a browser that did not start it: the cookie binding it to the browser the partner’s response arrived in was absent or different. HTTP 403 page
STS-FED-0112 An outbound federation request (a back channel, a metadata or status-list fetch, a Logout Token) was refused because its URL is plain http and the realm is in product mode, whatever federation.outboundAllowHttp says (#171). the caller’s failure: a sign-in page, a dead letter, a refusal
STS-FED-0113 Product mode ignored federation.outboundSkipTlsVerification: an outbound request verifies the certificate of whoever answers whatever it says. Logged once per process (#171). none — a warning in the log
STS-FED-0114 A SAML message at a federation single logout endpoint could not be decoded, or is not a well-formed LogoutRequest or LogoutResponse. HTTP 400 page
STS-FED-0115 A partner’s SAML LogoutRequest or LogoutResponse is unsigned, and the relationship requires a signed one (saml-profiles-2.0-os section 4.4.4.1; fedRequireSignedLogout). HTTP 403 page; no session was ended
STS-FED-0116 A partner’s SAML logout message carries a signature that does not verify against the relationship’s fedSigningCertificate, or that cannot be checked (an algorithm with no verifier, SHA-1 while it is off, incomplete Redirect-binding octets). HTTP 403 page; no session was ended
STS-FED-0117 A partner’s sign-out (a SAML logout message or a Logout Token) names an issuer other than the relationship’s fedPeer. HTTP 403 page, or HTTP 400 invalid_request on the back channel
STS-FED-0118 A partner’s signed SAML logout message names no Destination, or one that is not this relationship’s single logout endpoint (saml-bindings-2.0-os section 3.4.5.2). HTTP 403 page; no session was ended
STS-FED-0119 A partner’s sign-out is outside its validity window: a LogoutRequest past its NotOnOrAfter, or a LogoutRequest or Logout Token issued in the future or longer ago than federation.requestTtlMin. HTTP 403 page, or HTTP 400 invalid_request on the back channel
STS-FED-0120 A partner’s sign-out was replayed: its LogoutRequest ID or Logout Token jti has already been accepted (the used-assertion history, rule 3ae). HTTP 403 page, or HTTP 400 invalid_request on the back channel
STS-FED-0121 The used-assertion history could not be asked, or is full, so a partner’s sign-out could not be proved unused and was refused (fail closed). HTTP 503 page, or HTTP 503 on the back channel (the partner retries)
STS-FED-0122 A verified partner sign-out matched no session held here: no federated session carries that NameID and SessionIndex, sid or sub through this relationship. SAML LogoutResponse Requester/UnknownPrincipal; HTTP 200 on the back and front channels (there is nothing left to end)
STS-FED-0123 A partner’s sign-out was refused because fedAcceptSignout is off on the relationship. SAML LogoutResponse Responder/RequestDenied; HTTP 400 on the back channel; HTTP 403 page
STS-FED-0124 A LogoutResponse at a federation single logout endpoint answers no LogoutRequest this service sent: InResponseTo is absent, unknown, spent or expired. HTTP 400 page
STS-FED-0125 A partner answered this service’s LogoutRequest with a status other than Success, so the sign-out there did not complete. HTTP 200 page saying so; the local session had already ended
STS-FED-0126 A WS-Federation cleanup confirmation was posted with a handle this service did not draw, one already spent or expired, or in a browser whose session is not the one it was drawn for. HTTP 403 page; no session was ended
STS-FED-0127 A back-channel logout request carried no logout_token, or one that is not a signed JWT (an encrypted Logout Token is refused: this relying party registers no encryption with a partner). HTTP 400 invalid_request (Back-Channel Logout 1.0 section 2.8)
STS-FED-0128 A Logout Token did not verify against the relationship’s partner keys: its signature, algorithm, kid, audience or expiry. HTTP 400 invalid_request (Back-Channel Logout 1.0 section 2.8)
STS-FED-0129 A Logout Token failed Back-Channel Logout 1.0 section 2.6: a typ other than logout+jwt, no events member naming the back-channel logout event, a nonce, no jti, or neither sub nor sid. HTTP 400 invalid_request (Back-Channel Logout 1.0 section 2.8)
STS-FED-0130 A front-channel logout request carried no iss or no sid, or an iss that is not the relationship’s partner. HTTP 400 page
STS-FED-0131 A partner’s assertion carries an AuthnStatement SessionNotOnOrAfter that has already passed, so no session was started from it. HTTP 401 page
STS-FED-0132 fedRequireSignedLogout was set off in product mode, where an unsigned SAML logout message is never accepted. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0133 fedSloBinding was set to something other than HTTP-Redirect or HTTP-POST. action result ok:false (console redirect or /admin-api HTTP 400)
STS-FED-0134 A browser returned from a partner’s end_session_endpoint with a state this service did not mint, or one already spent or expired. HTTP 400 page
STS-FED-0135 A federation single logout endpoint was sent something its relationship’s protocol does not define — any sign-out for SAML 1.1 or OAuth 2.0, which define none, another protocol’s message, or nothing at all. HTTP 400 page
STS-FED-0136 A partner’s verified sign-out matched a session and ending it failed. HTTP 500 page, or HTTP 500 on the back channel (the partner retries)
STS-FED-0137 A partner’s encrypted assertion, identifier, attribute, ID Token or Logout Token arrived and the relationship holds no usable encryption key for it — none issued, one of the other key type, a previous key past its grace period, a kid naming no key held, or a sealed key that will not open. HTTP 500 page (400 JSON on the back channel)
STS-FED-0138 A partner’s encrypted element or JWE did not decrypt under the relationship’s key. ONE code for every cause — a wrong key, an altered ciphertext, a tag, an unwrap — so the answer is no oracle; which step failed is in the log line. HTTP 401 page (400 JSON on the back channel)
STS-FED-0139 A partner encrypted with an algorithm the relationship does not accept — not the key management or content encryption it publishes, or AES-CBC, rsa-1_5 or RSA1_5, which are refused in every mode — or a write tried to configure one of those three. HTTP 401 page; /admin-api: HTTP 400 { ok: false, errors }
STS-FED-0140 A partner sent a plaintext SAML 2.0 or WS-Federation assertion, or a signed-only id_token by form_post, to a relationship that requires encryption (product mode, fedAllowUnencrypted off). HTTP 401 page
STS-FED-0141 A JWE arrived where a JWS was expected: an encrypted ID Token or Logout Token whose plaintext is not a signed JWT (OpenID Connect Core section 10.2 is sign-then-encrypt), or an encrypted access token at a plain OAuth 2.0 relationship, which holds no decryption key. HTTP 401 page (400 JSON on the back channel)
STS-FED-0142 A federation relationship’s encryption key could not be issued, sealed or written — at create, at a rotation, or when its key type changed. console: the page’s error list; /admin-api: HTTP 400 { ok: false, errors }
STS-FED-0143 A write to a relationship’s encryption fields named a value outside the vocabulary for its protocol, a key management its key type cannot do, or an encryption field on a SAML 1.1 or OAuth 2.0 relationship. console: the page’s error list; /admin-api: HTTP 400 { ok: false, errors }
STS-FED-0144 An encryption key rotation named no relationship, or one that holds no key — identity-provider-side, SAML 1.1 or OAuth 2.0. console: the page’s error list; /admin-api: HTTP 400 { ok: false, errors }
STS-FED-0145 The scheduler job federation.encryption-key-retire could not remove a retired key from a relationship; the key already decrypts nothing, and the next run tries again. none — logged
STS-FED-0146 /federation/jwks/{id} named no OpenID Connect service-provider-side relationship. HTTP 404 page
STS-FED-0147 A partner’s SAML Response or wresult carried an encrypted assertion beside another assertion; which one a signature covered and which one was read must not be a choice. HTTP 400 page
STS-FED-0148 A relationship whose OpenID Provider is discovered through an OpenID Federation could not resolve it to its fedTrustAnchor (#134). HTTP 502 page
STS-FED-0149 An OpenID Provider resolved through an OpenID Federation cannot be used: no openid_provider metadata, an issuer that is not its Entity Identifier, no https endpoints, no automatic registration, or no keys (#134). HTTP 502 page
STS-FED-0150 A federation relationship field that takes a closed set of values (fedAuthnMechanism, fedBinding, fedResponseType, or any row with an enum) was set to a value outside it (#86). HTTP 400 (console and API)
STS-FED-0151 A fedAttributeMap value was not a mapping: it is = (#94). HTTP 400 (console and API)
STS-FED-0152 A fedAttributeMap value named a target no partner may write — an attribute this service keeps (sts, app, fed, pwd) or the entry’s identity, structure or authorization (uid, memberOf, userPassword, the operational attributes) (#94). HTTP 400 (console and API)
STS-FED-0153 A partner’s attribute was dropped at sign-in because the relationship maps it onto an attribute no partner may write (a mapping written before #94, or by an ldapmodify) (#94). none (logged; the sign-in proceeds without it)
STS-FED-0154 A federation relationship’s Shared Signals credential (fedSignalsClientSecret or fedSignalsBearer) could not be sealed under the key-encryption key where keys persist, so it was not written (#373). HTTP 400 (console and API)
STS-FED-0155 A federated sign-in was started through an ssf relationship, which only sends Shared Signals and signs nobody in (#374). HTTP 400 page
STS-FED-0156 A federated sign-in was refused because the partner’s own Shared Signals (a verified account-disabled) blocked its sign-ins of this person; its account-enabled, or an administrator, lifts it (#373). HTTP 403 page
STS-FED-0157 A federation relationship’s client secret (fedClientSecret) could not be sealed under a durable key-encryption key, so it was not written. HTTP 400 (console and API)

STS-OIDFED

OpenID Federation. OpenID Federation 1.1 (#132): Entity Statements, Trust Chains and their resolution, metadata policy and constraints, Trust Marks, the Federation Entity Keys, and the federation endpoints.

Raised from: oidfed/.

Code What failed Client sees
STS-OIDFED-0001 A metadata_policy is not the three levels of JSON objects section 6.1.2 describes, or an operator’s value is of a type the operator does not take (#132). invalid_metadata (resolving a Trust Chain)
STS-OIDFED-0002 A metadata parameter policy combines operators section 6.1.3.1 does not allow together — in one statement, or after the chain’s policies were merged (#132). invalid_metadata (resolving a Trust Chain)
STS-OIDFED-0003 Two superiors’ values for the same operator could not be merged (unequal value or default, an empty one_of) (#132, 6.1.3.1). invalid_metadata (resolving a Trust Chain)
STS-OIDFED-0004 A metadata policy operator the chain declares critical (metadata_policy_crit) is one this service does not understand (#132, 6.1.3.2). invalid_trust_chain
STS-OIDFED-0005 Applying the resolved metadata policy failed: a check did not hold, or an operator met a parameter of a type it does not act on (#132, 6.1.4.2). invalid_metadata
STS-OIDFED-0006 A metadata parameter the resolved policy marks essential is absent (#132, 6.1.3.1.7). invalid_metadata
STS-OIDFED-0007 A Trust Chain has more Intermediates than a superior’s max_path_length allows (#132, 6.2.1). invalid_trust_chain
STS-OIDFED-0008 An entity in a Trust Chain is outside, or excluded by, a superior’s naming_constraints (#132, 6.2.2). invalid_trust_chain
STS-OIDFED-0009 A Subordinate Statement’s constraints are malformed (#132, 6.2). invalid_trust_chain
STS-OIDFED-0010 A federation JWT is not a signed JWT whose header and claims are JSON objects (#132). invalid_trust_chain, or the endpoint’s invalid_request
STS-OIDFED-0011 A federation JWT is not typed as its kind requires (entity-statement+jwt, trust-mark+jwt, …) (#132, RFC 8725 3.11). invalid_trust_chain
STS-OIDFED-0012 A federation JWT is signed with an algorithm that is not an asymmetric one this service verifies, or none (#132, 3.2). invalid_trust_chain
STS-OIDFED-0013 A federation JWT names no kid, or its kid names no key (or more than one) of the JWK Set it is checked against (#132, 3.2). invalid_trust_chain
STS-OIDFED-0014 A federation JWT’s signature does not verify with the key its kid names (#132, 3.2). invalid_trust_chain
STS-OIDFED-0015 An Entity Statement claim is missing or malformed: iss, sub, jwks, the hints, the Trust Mark claims, constraints, metadata_policy_crit or source_endpoint (#132, 3.1, 3.2). invalid_trust_chain
STS-OIDFED-0016 An Entity Statement was issued in the future or has expired (#132, 3.2). invalid_trust_chain
STS-OIDFED-0017 An Entity Statement’s crit names a claim this specification defines, one it does not carry, or one this service does not understand (#132, 3.2, 13.4). invalid_trust_chain
STS-OIDFED-0018 A claim appears in the wrong kind of Entity Statement — a Subordinate Statement’s claim in an Entity Configuration, or the reverse (#132, 3.1.2, 3.1.3). invalid_trust_chain
STS-OIDFED-0019 An Entity Statement’s metadata is malformed: not objects, a null member, a JWK Set under federation_entity, or a federation endpoint that is not https (#132, 5). invalid_metadata
STS-OIDFED-0020 A Trust Chain is not an array of Entity Statements beginning with its subject’s Entity Configuration, with only the last an Entity Configuration besides (#132, 4, 10.2). invalid_trust_chain
STS-OIDFED-0021 A Trust Chain’s statements do not link: one statement’s issuer is not the next one’s subject (#132, 4, 10.2). invalid_trust_chain
STS-OIDFED-0022 A Trust Chain ends at an entity that is not a Trust Anchor this realm is configured with, or the realm has none (#132, 10.2). invalid_trust_anchor (HTTP 404)
STS-OIDFED-0023 A Subordinate Statement’s issuer is not among its subject’s authority_hints (#132, 3.2). invalid_trust_chain
STS-OIDFED-0024 An entity’s Entity Configuration could not be obtained, was not served as application/entity-statement+jwt, or is not about the entity it was fetched for (#132, 9, 10.1). none — the resolution reports it
STS-OIDFED-0025 A superior publishes no federation_fetch_endpoint, so a Subordinate Statement cannot be fetched from it (#132, 5.1.1, 8.1). none — the resolution reports it
STS-OIDFED-0026 A superior’s fetch endpoint answered with a statement about somebody else, by somebody else, or had none (#132, 8.1.2). none — the resolution reports it
STS-OIDFED-0027 An entity could not be resolved to any configured Trust Anchor (#132, 10). invalid_trust_chain (HTTP 400)
STS-OIDFED-0028 A resolution reached oidfed.maxFetchesPerResolution and stopped (#132, 18.1). invalid_trust_chain (HTTP 400)
STS-OIDFED-0029 A Trust Mark did not validate: its type, its issuer, its subject or its times (#132, 7.3). none — the mark is left out
STS-OIDFED-0030 A Trust Mark’s issuer is not one the Trust Anchor trusts to issue marks of its type (#132, 3.1.2, 7). none — the mark is left out
STS-OIDFED-0031 A Trust Mark of a type the Trust Anchor names an owner for carries no delegation, or one that does not validate against the owner’s keys (#132, 7.2.2, 7.3). none — the mark is left out
STS-OIDFED-0032 A fetch request named no sub, or named the fetching entity itself (#132, 8.1). invalid_request (HTTP 400)
STS-OIDFED-0033 A fetch request named an entity this realm does not vouch for (#132, 8.1.2). not_found (HTTP 404)
STS-OIDFED-0034 A resolve request lacked sub or trust_anchor (#132, 8.3.1). invalid_request (HTTP 400)
STS-OIDFED-0035 A resolve request, or an act, named no Trust Anchor this realm is configured with (#132, 8.3). invalid_trust_anchor (HTTP 404)
STS-OIDFED-0036 A resolve request named an entity this realm has not resolved, and an unauthenticated request does not start a resolution (#132, 18.1). not_found (HTTP 404)
STS-OIDFED-0037 A Trust Mark, Trust Mark Status or Trust Mark listing request lacked a required parameter (#132, 8.4.1, 8.5.1, 8.6.1). invalid_request (HTTP 400)
STS-OIDFED-0038 A Trust Mark request named a subject this realm holds no valid mark of that type for (#132, 8.6.2). not_found (HTTP 404)
STS-OIDFED-0039 A Trust Mark Status request carried a mark this realm did not issue (#132, 8.4.2). not_found (HTTP 404)
STS-OIDFED-0040 A Federation Entity Key is sealed under a key-encryption key this process does not hold, so the realm signs no federation statement until the key is rotated (#132). —
STS-OIDFED-0041 An administrator asked to revoke a Federation Entity Key the realm does not hold (#132). —
STS-OIDFED-0042 An administrator asked to revoke the current or next Federation Entity Key by hand, which only an emergency rotation does (#132). —
STS-OIDFED-0043 The realm had no Federation Entity Key to sign with — a cluster node that lost the race to mint the first one, until the directory catches up (#132). temporarily_unavailable (HTTP 503)
STS-OIDFED-0044 A Subordinate Listing request’s trust_marked or intermediate was not true or false (#132, 8.2.1). invalid_request (HTTP 400)
STS-OIDFED-0045 An OpenID Federation console or /admin-api act was refused for its input (#132). —
STS-OIDFED-0046 An OpenID Federation act named something the realm does not hold, or no act at all (#132). —
STS-OIDFED-0047 An administrator asked to issue a Trust Mark of a type this realm does not issue (#132). —
STS-OIDFED-0048 A Trust Mark offered for this realm to carry is not a trust-mark+jwt issued to it (#132). —
STS-OIDFED-0049 The keys of an entity being registered could not be read — neither given as a valid JWK Set nor obtained from its Entity Configuration (#132). —
STS-OIDFED-0050 A federation endpoint failed unexpectedly (#132). server_error (HTTP 500)
STS-OIDFED-0051 An Entity Statement carried an aud where none was expected, an aud naming somebody else, or a trust_anchor claim outside an Explicit Registration response (#134). invalid_request / invalid_trust_chain
STS-OIDFED-0052 A relying party registering through the federation resolved with no openid_relying_party metadata, or with no usable keys for its relying party role (#134). invalid_metadata
STS-OIDFED-0053 A Trust Chain presented for a registration was about another entity, or its peer_trust_chain did not begin at this OP and end at the same Trust Anchor (#134). invalid_trust_chain
STS-OIDFED-0054 An automatic registration carried no proof, or its request object or client assertion did not verify with the relying party’s keys or failed its aud, iss, sub, jti or exp checks (#134). invalid_request (HTTP 400, never redirected)
STS-OIDFED-0055 An automatic registration asked for a secret-based token endpoint authentication method, which nothing provisioned (#134). invalid_client_metadata
STS-OIDFED-0056 An Explicit Registration request was refused: the realm does not offer it, the media type was wrong, or the body was not the relying party’s Entity Configuration with authority_hints and openid_relying_party metadata (#134). invalid_request
STS-OIDFED-0057 A Subordinate Statement was asked for about a subordinate this realm has suspended, which it issues none about until it is reinstated (#137). not_found (HTTP 404)
STS-OIDFED-0058 A subordinate could not be suspended or reinstated: the realm has no such subordinate, or it was already suspended, or it was not (#137). —
STS-OIDFED-0059 A listing or collection page was asked for from a pointer this realm did not return as next — for this realm and endpoint (#135, #136). page_not_found (HTTP 404)
STS-OIDFED-0060 An Extended Subordinate Listing or Entity Collection request carried a limit that is not a positive integer, a time that is not a NumericDate, a boolean that is neither, or a single-valued parameter twice (#135, #136). invalid_request (HTTP 400)
STS-OIDFED-0061 An Entity Collection request asked for an entity_claims or ui_claims claim this realm does not return (#136). unsupported_claim (HTTP 400)
STS-OIDFED-0062 An Entity Collection request named a Trust Anchor other than the realm itself; the collection is of the realm’s own subtree (#136). invalid_trust_anchor (HTTP 404)
STS-OIDFED-0063 A Subordinate Events request carried no sub (#137). invalid_request (HTTP 400)
STS-OIDFED-0064 A Subordinate Events request named an entity that is not, and never was, a subordinate of this realm (#137). not_found (HTTP 404)
STS-OIDFED-0065 A subordinate’s event could not be written to the realm’s register; the act that caused it stands (#137). —
STS-OIDFED-0066 An Entity Collection crawl failed, or its result could not be kept in the realm’s register (#136). —
STS-OIDFED-0067 A request object from a relying party registered automatically through an OpenID Federation failed section 12.1.1.1: aud not this OP alone, iss or client_id not the RP, a sub, or no jti or exp (#187). invalid_request_object (HTTP 400)

STS-KRB

Kerberos and SPNEGO. The KDC on TCP/UDP 88 and MS-KKDCP, the Kerberos service, SPNEGO and the SPNEGO sign-in.

Raised from: kerberos/.

Code What failed Client sees
STS-KRB-0001 A cross-realm referral could not be issued because the trust account and the client share no encryption type. KDC_ERR_ETYPE_NOSUPP (14)
STS-KRB-0002 An S4U request sent both PA-FOR-USER and cname-in-addl-tkt, which are separate S4U2Self and S4U2Proxy requests. KDC_ERR_BADOPTION (13)
STS-KRB-0003 An S4U2Self request carried a PA-FOR-USER that does not decode. KDC_ERR_BADOPTION (13)
STS-KRB-0004 An S4U2Self request’s PA-FOR-USER checksum did not verify under the requester’s TGT session key. KDC_ERR_BADOPTION (13)
STS-KRB-0005 An S4U2Self request named a user this KDC does not know and will not create (reserved, service-shaped or in a realm it does not serve). KDC_ERR_C_PRINCIPAL_UNKNOWN (6)
STS-KRB-0006 An S4U2Self request asked for a ticket to a service other than the requester itself. KDC_ERR_BADOPTION (13)
STS-KRB-0007 An S4U2Proxy request set cname-in-addl-tkt but carried no additional ticket. KDC_ERR_BADOPTION (13)
STS-KRB-0008 An S4U2Proxy evidence ticket was addressed to a service other than the requester. KDC_ERR_BADOPTION (13)
STS-KRB-0009 An S4U2Proxy evidence ticket did not decrypt with the requester’s long-term key. KDC_ERR_BADOPTION (13)
STS-KRB-0010 S4U2Proxy was refused: neither appAllowedToDelegateTo on the requester’s entry nor appAllowedToActOnBehalfOf on the target’s (msDS-AllowedToDelegateTo and msDS-AllowedToActOnBehalfOfOtherIdentity) permits the delegation. KDC_ERR_BADOPTION (13)
STS-KRB-0011 S4U2Proxy permitted only by resource-based delegation was refused because PA-PAC-OPTIONS with the resource-based bit was missing. KDC_ERR_BADOPTION (13)
STS-KRB-0012 Classic constrained delegation was refused because the evidence ticket is not forwardable (the S4U2Self service does not allow impersonation, or the user is protected). KDC_ERR_BADOPTION (13)
STS-KRB-0013 An AS-REQ for an account that requires pre-authentication carried no PA-ENC-TIMESTAMP; the KDC answered with the pre-authentication methods it accepts. KDC_ERR_PREAUTH_REQUIRED (25)
STS-KRB-0014 The PA-ENC-TIMESTAMP, or the PA-ENC-TS-ENC inside it, was not well formed. KDC_ERR_PREAUTH_FAILED (24)
STS-KRB-0015 The PA-ENC-TIMESTAMP was encrypted with a different encryption type from the one the request negotiated. KDC_ERR_PREAUTH_FAILED (24)
STS-KRB-0016 The PA-ENC-TIMESTAMP did not decrypt under the client’s long-term key: a wrong password, salt or key usage. KDC_ERR_PREAUTH_FAILED (24)
STS-KRB-0017 The pre-authentication timestamp was outside the KDC’s clock-skew tolerance. KRB_AP_ERR_SKEW (37)
STS-KRB-0018 An AS-REQ named a realm this KDC does not serve. KDC_ERR_WRONG_REALM (68)
STS-KRB-0019 An AS-REQ carried no client name. KDC_ERR_C_PRINCIPAL_UNKNOWN (6)
STS-KRB-0020 An AS-REQ named a client this KDC does not know and will not create (a reserved or service-shaped name). KDC_ERR_C_PRINCIPAL_UNKNOWN (6)
STS-KRB-0021 An AS-REQ named a service principal this KDC does not know. KDC_ERR_S_PRINCIPAL_UNKNOWN (7)
STS-KRB-0022 The KDC has no krbtgt principal for the realm it is answering, so no ticket can be signed (in product mode, usually the published krbtgt password was refused). KDC_ERR_S_PRINCIPAL_UNKNOWN (7)
STS-KRB-0023 An AS-REQ was refused because the client account is disabled or locked out. KDC_ERR_CLIENT_REVOKED (18)
STS-KRB-0024 An AS-REQ was refused because the client’s password has expired. KDC_ERR_KEY_EXPIRED (23)
STS-KRB-0025 An AS-REQ was refused because the client and the KDC share no encryption type. KDC_ERR_ETYPE_NOSUPP (14)
STS-KRB-0026 A TGS-REQ carried no PA-TGS-REQ, so there was no ticket-granting ticket to verify. KDC_ERR_PREAUTH_REQUIRED (25)
STS-KRB-0027 A TGS-REQ’s PA-TGS-REQ did not contain a readable AP-REQ. KRB_ERR_GENERIC (60)
STS-KRB-0028 A TGS-REQ presented a ticket for a service principal this KDC does not know. KDC_ERR_S_PRINCIPAL_UNKNOWN (7)
STS-KRB-0029 A TGS-REQ’s ticket did not decrypt with this KDC’s key for the service it names. KRB_AP_ERR_BAD_INTEGRITY (31)
STS-KRB-0030 A TGS-REQ’s Authenticator did not decrypt with the ticket’s session key. KRB_AP_ERR_BAD_INTEGRITY (31)
STS-KRB-0031 A TGS-REQ’s Authenticator and ticket name different clients. KRB_AP_ERR_BADMATCH (36)
STS-KRB-0032 A TGS-REQ presented an expired ticket. KRB_AP_ERR_TKT_EXPIRED (32)
STS-KRB-0033 A TGS-REQ presented a ticket that is not yet valid. KRB_AP_ERR_TKT_NYV (33)
STS-KRB-0034 A TGS-REQ (a renewal included) was refused because the ticket was authenticated before its client signed out (logout.kerberosSignOut); a later AS exchange does not lift it. KDC_ERR_TGT_REVOKED (20)
STS-KRB-0035 A TGS-REQ’s Authenticator clock was outside the KDC’s clock-skew tolerance. KRB_AP_ERR_SKEW (37)
STS-KRB-0036 A TGS-REQ’s Authenticator carried no checksum over the request body. KRB_AP_ERR_INAPP_CKSUM (50)
STS-KRB-0037 A TGS-REQ’s Authenticator checksum did not match the request body. KRB_AP_ERR_INAPP_CKSUM (50)
STS-KRB-0038 A TGS-REQ named a service principal this KDC neither knows nor registers on demand, and no trust refers it elsewhere. KDC_ERR_S_PRINCIPAL_UNKNOWN (7)
STS-KRB-0039 The issuance policy refused a service ticket because the client does not hold a role the service requires. KDC_ERR_POLICY (12)
STS-KRB-0040 A TGS-REQ was refused because the service and the request share no encryption type. KDC_ERR_ETYPE_NOSUPP (14)
STS-KRB-0041 A FORWARDED request was refused because the presented ticket is not forwardable. KDC_ERR_BADOPTION (13)
STS-KRB-0042 A FORWARDED request was refused because the client is protected from delegation (stsNotDelegated or a protected group: NOT_DELEGATED, Protected Users). KDC_ERR_BADOPTION (13)
STS-KRB-0043 A RENEW request was refused because the ticket is not renewable. KDC_ERR_BADOPTION (13)
STS-KRB-0044 A RENEW request was refused because the renewable ticket carries no renew-till. KDC_ERR_BADOPTION (13)
STS-KRB-0045 A RENEW request was refused because the ticket’s renew-till has passed. KRB_AP_ERR_TKT_EXPIRED (32)
STS-KRB-0046 A RENEW request named a different service from the ticket being renewed. KDC_ERR_BADOPTION (13)
STS-KRB-0047 The KDC received a Kerberos message that is not a request a KDC answers. KRB_AP_ERR_MSG_TYPE (40)
STS-KRB-0048 The KDC could not decode or handle a request. KRB_ERR_GENERIC (60)
STS-KRB-0049 A TCP request to the KDC exceeded krb5.maxRequestBytes and the connection was closed. connection closed
STS-KRB-0050 A TCP request to the KDC carried a length prefix with the reserved top bit set and the connection was closed. connection closed
STS-KRB-0051 The KDC failed to build any reply at all, not even a KRB-ERROR (TCP, UDP or MS-KKDCP). TCP connection closed; no UDP datagram; HTTP 500 over /KdcProxy
STS-KRB-0052 The KDC’s TCP listener failed, usually because its port could not be bound. —
STS-KRB-0053 The KDC’s UDP listener failed, usually because its port could not be bound. —
STS-KRB-0054 A KDC reply was too large for a UDP datagram, so the client was told to retry over TCP. KRB_ERR_RESPONSE_TOO_BIG (52)
STS-KRB-0055 A POST to /KdcProxy carried an empty body. HTTP 400
STS-KRB-0056 A POST to /KdcProxy carried a body that does not decode as a KDC-PROXY-MESSAGE. HTTP 400
STS-KRB-0057 A POST to /KdcProxy carried a kerb-message too short to be framed. HTTP 400
STS-KRB-0058 The service did not start: krb5.enctypes names an encryption type the Kerberos codec does not implement. —
STS-KRB-0059 krb5.servicePrincipal is not a service/host name, so no account was created for the Kerberos acceptor. —
STS-KRB-0060 krb5.servicePassword is empty, so no account was created for the Kerberos acceptor. —
STS-KRB-0061 Product mode refused the published default krb5.servicePassword, so no account was created for the Kerberos acceptor. —
STS-KRB-0062 (retired) Product mode refused the published default krb5.krbtgtPassword, so no krbtgt was created and the KDC issues no ticket. RETIRED 2026-09-23 (#169): product keys krbtgt at random and reads no password for it. —
STS-KRB-0063 The Kerberos acceptor refused a token larger than krb5.serviceMaxTokenBytes. KRB_ERR_GENERIC (60)
STS-KRB-0064 The Kerberos acceptor could not decode the GSS InitialContextToken wrapper. KRB_ERR_GENERIC (60)
STS-KRB-0065 The Kerberos acceptor was sent a GSS token that is not an AP-REQ. KRB_AP_ERR_MSG_TYPE (40)
STS-KRB-0066 The Kerberos acceptor could not decode the AP-REQ. KRB_ERR_GENERIC (60)
STS-KRB-0067 The Kerberos acceptor refused a ticket for a service principal it holds no key for. KRB_AP_ERR_NOT_US (35)
STS-KRB-0068 The Kerberos acceptor refused a ticket encrypted with a key version it does not hold (a stale keytab). KRB_AP_ERR_BADKEYVER (44)
STS-KRB-0069 The ticket presented to the Kerberos acceptor did not decrypt with the service’s key. KRB_AP_ERR_BAD_INTEGRITY (31)
STS-KRB-0070 The Authenticator presented to the Kerberos acceptor did not decrypt with the ticket’s session key. KRB_AP_ERR_BAD_INTEGRITY (31)
STS-KRB-0071 The Authenticator and the ticket presented to the Kerberos acceptor name different clients. KRB_AP_ERR_BADMATCH (36)
STS-KRB-0072 The Authenticator presented to the Kerberos acceptor was outside the clock-skew tolerance. KRB_AP_ERR_SKEW (37)
STS-KRB-0073 The Kerberos acceptor refused an expired ticket. KRB_AP_ERR_TKT_EXPIRED (32)
STS-KRB-0074 The Kerberos acceptor refused a replayed Authenticator. KRB_AP_ERR_REPEAT (34)
STS-KRB-0075 The Kerberos acceptor refused a new Authenticator because its replay cache is full of entries still inside the replay window. KRB_ERR_GENERIC (60)
STS-KRB-0076 The Authenticator’s 0x8003 GSS checksum presented to the Kerberos acceptor is malformed. KRB_AP_ERR_INAPP_CKSUM (50)
STS-KRB-0077 The Authenticator presented to the Kerberos acceptor carried a checksum type other than 0x8003. KRB_AP_ERR_INAPP_CKSUM (50)
STS-KRB-0078 A request to the Kerberos service’s TCP listener exceeded krb5.serviceMaxTokenBytes and the connection was closed. connection closed
STS-KRB-0079 A request to the Kerberos service’s TCP listener carried a length prefix with the reserved top bit set and the connection was closed. connection closed
STS-KRB-0080 The Kerberos service failed to build a reply and closed the connection. connection closed
STS-KRB-0081 The Kerberos service’s TCP listener failed, usually because its port could not be bound. —
STS-KRB-0082 A SPNEGO request carried no Authorization header and was answered with the bare Negotiate challenge. HTTP 401 WWW-Authenticate: Negotiate
STS-KRB-0083 A SPNEGO request carried an Authorization header naming a scheme other than Negotiate. HTTP 401 WWW-Authenticate: Negotiate
STS-KRB-0084 A SPNEGO request carried Negotiate with an empty token. HTTP 401 WWW-Authenticate: Negotiate
STS-KRB-0085 A SPNEGO token was neither a NegToken nor a bare Kerberos token. HTTP 401, NegTokenResp negState reject
STS-KRB-0086 A SPNEGO NegTokenInit offered no mechanism this service performs. HTTP 401, NegTokenResp negState reject
STS-KRB-0087 A SPNEGO NegTokenInit carried no optimistic mechanism token, so the acceptor asked for one. HTTP 401, NegTokenResp negState accept-incomplete
STS-KRB-0088 The SPNEGO mechanism selected is not one this service performs. HTTP 401, NegTokenResp negState reject
STS-KRB-0089 The Kerberos acceptor threw while a SPNEGO token was being checked. HTTP 401, NegTokenResp negState reject
STS-KRB-0090 A SPNEGO Kerberos AP-REQ was refused without the acceptor naming a more specific condition. HTTP 401, NegTokenResp negState reject with a KRB-ERROR
STS-KRB-0091 A SPNEGO mechListMIC did not verify (RFC 4178 section 5). HTTP 401, NegTokenResp negState reject
STS-KRB-0092 A SPNEGO exchange required a mechListMIC and none was sent (RFC 4178 section 5). HTTP 401, NegTokenResp negState reject
STS-KRB-0093 The SPNEGO acceptor sent request-mic and is waiting for the client’s mechListMIC. HTTP 401, NegTokenResp negState request-mic
STS-KRB-0094 A bare SPNEGO NegTokenResp arrived with no negotiation in progress to continue. HTTP 401, NegTokenResp negState reject
STS-KRB-0095 A SPNEGO continuation carried no mechListMIC. HTTP 401, NegTokenResp negState reject
STS-KRB-0096 An unhandled failure on /spnego/protected. HTTP 500 page
STS-KRB-0097 A SPNEGO sign-in at /authn/spnego was refused because krb5.spnegoAuthentication is off. HTTP 403 page
STS-KRB-0098 A valid Kerberos ticket was accepted at /authn/spnego and the issuance policy refused to start a session. HTTP 403 page
STS-KRB-0099 An unhandled failure on the SPNEGO sign-in at /authn/spnego. HTTP 500 page
STS-KRB-0100 The principal database’s key source slot was offered something incomplete and refused it whole; no person and no stored service key will be used. —
STS-KRB-0101 A product-mode AS-REQ named a person and this process has no key source (no directory) to read Kerberos keys from. KRB-ERROR KDC_ERR_C_PRINCIPAL_UNKNOWN (6)
STS-KRB-0102 A product-mode AS-REQ named a person while krb5.personKeys is off. KRB-ERROR KDC_ERR_C_PRINCIPAL_UNKNOWN (6)
STS-KRB-0103 A product-mode AS-REQ named a person who is not in the default trust realm’s directory. KRB-ERROR KDC_ERR_C_PRINCIPAL_UNKNOWN (6)
STS-KRB-0104 A product-mode AS-REQ named a person who has no Kerberos keys, or whose keys were derived from a password they no longer have; they are told to sign in once with the password. KRB-ERROR KDC_ERR_C_PRINCIPAL_UNKNOWN (6) with an e-text saying so
STS-KRB-0105 A person’s stored Kerberos keys could not be opened (sealed under another key-encryption key, not this service’s shape, or bound to another name). KRB-ERROR KDC_ERR_C_PRINCIPAL_UNKNOWN (6)
STS-KRB-0106 Reading a stored service principal key threw; the configured account, if any, answered instead. —
STS-KRB-0107 Deriving a person’s Kerberos keys from a password that was just set or verified failed; the sign-in or password change was unaffected. —
STS-KRB-0108 Kerberos key material could not be sealed under the key-encryption key, so it was not stored. —
STS-KRB-0109 Kerberos key material could not be written to the directory entry it belongs on. —
STS-KRB-0110 The Kerberos key register was offered an incomplete directory slot and refused it whole. —
STS-KRB-0111 A restored or replicated row for a CONFIGURED principal carried configuration (password, salt, etypes, kvno, PAC identity, delegation, description or type) that differs from what the current settings build; the settings were kept and only the runtime state was taken. —
STS-KRB-0112 A restored or replicated principal row was neither configured by this process’s settings nor made at runtime (auto-created or directory-keyed), so it was not restored: the settings that made it no longer do. —
STS-KRB-0113 A replicated removal named a CONFIGURED principal and was refused; a configured account exists because the settings build it. —
STS-KRB-0114 A restored or replicated runtime-made principal carries a RID another principal in this database already holds; neither was renumbered, and a service authorizing on the PAC cannot tell them apart. —
STS-KRB-0115 A ticket presented in a TGS-REQ (the ticket-granting ticket or an S4U2Proxy evidence ticket) names a key version of a stored-key principal that is neither its current kvno nor a previous version still retained (krb5.retainedKeyVersions, krb5.retainedKeyTtlS), or one retained without that enctype. KRB-ERROR KRB_AP_ERR_BADKEYVER (44)
STS-KRB-0116 An Authenticator this process had not seen was already accepted by another process against the same store (the cluster claim, #46) — a replay delivered to a different node. KRB-ERROR KRB_AP_ERR_REPEAT (34)
STS-KRB-0117 The cluster claim store could not be asked whether an Authenticator was already accepted, so it was refused rather than accepted unproven. KRB-ERROR KRB_ERR_GENERIC (60)
STS-KRB-0118 A KDC request was answered before this node caught up with the other nodes’ committed changes, so a sign-out committed elsewhere in the last moment may not be honoured by it. none — logged; the request is answered
STS-KRB-0119 A SPNEGO request-mic continuation was refused because another process of this service had already completed that negotiation. RFC 4178 section 4.2.2, a reject NegTokenResp; HTTP 401
STS-KRB-0120 A SPNEGO request-mic continuation could not be proved unspent because the store that records completed negotiations could not be asked; it was refused (fail closed). RFC 4178 section 4.2.2, a reject NegTokenResp; HTTP 401
STS-KRB-0121 A TGS-REQ named a realm this KDC does not serve. Until 2026-09-15 such a request was answered as the default realm. KDC_ERR_WRONG_REALM (68)
STS-KRB-0122 A KDC request sent to a trust realm’s own /realm//KdcProxy named a Kerberos realm that realm does not serve (another realm's name, or one whose Kerberos is off). KDC_ERR_WRONG_REALM (68)
STS-KRB-0123 Kerberos was turned on for a trust realm that has no krb5.realm of its own. none (a refused administrative change)
STS-KRB-0124 A trust realm was given a krb5.realm another realm already answers to (another realm’s, the default realm’s, or krb5.trustedRealm), compared without regard to case. none (a refused administrative change)
STS-KRB-0125 A trust realm’s krb5.realm was changed or cleared while its Kerberos was on. none (a refused administrative change)
STS-KRB-0126 The acceptor was presented a ticket for a Kerberos realm the trust realm it was reached in does not serve. KRB_AP_ERR_NOT_US (35); over SPNEGO, HTTP 401
STS-KRB-0127 Two trust realms answer to one Kerberos realm name (a restored or replicated realm the registry did not re-judge), so the KDC routes that name to the first and not the second. none (logged when the router finds it)
STS-KRB-0128 A Kerberos key act — creating, rotating, deleting or clearing a stored key — was asked of a trust realm that has no KDC, so there is no principal for the key to belong to. HTTP 400 { ok: false, errors } / 303 with error=
STS-KRB-0129 An AS-REQ, or an S4U2Self naming a person, was refused because that person’s account is disabled. KDC_ERR_CLIENT_REVOKED (18)
STS-KRB-0130 A keytab was asked for a name that is not a person in this trust realm’s directory (no directory, no usable single-component name, or no entry). HTTP 400 { ok: false, errors } / a 400 portal page
STS-KRB-0131 A keytab was refused because the product KDC holds no current keys for the person — none derived yet, derived from an older password, unreadable, or krb5.personKeys off. HTTP 400 { ok: false, errors } / a 400 portal page
STS-KRB-0132 A keytab was refused because the password given does not derive the key the product KDC holds for the person, or none was given. HTTP 400 { ok: false, errors } / a 400 portal page
STS-KRB-0133 A development-mode keytab was refused because the development KDC has no principal for the person and will not make one (a name krb5.unknownUsers reserves), or it offers no enctype. HTTP 400 { ok: false, errors } / a 400 portal page
STS-KRB-0134 A keytab was refused because the person’s account is disabled, which the KDC refuses whatever key is presented. HTTP 400 { ok: false, errors } / a 400 portal page
STS-KRB-0135 An AS-REQ pre-authenticated with a password alone (PA-ENC-TIMESTAMP, or FAST’s PA-ENCRYPTED-CHALLENGE) was refused, in product mode, because the person holds or is required to hold a second factor. Refused only after the password verified. KDC_ERR_POLICY (12)
STS-KRB-0136 A FAST-armored AS-REQ (PA-FX-FAST) did not decode, carried no armor, named an armor type other than FX_FAST_ARMOR_AP_REQUEST, or its armor was not an AP-REQ. RFC 6113 section 5.4.1: KDC_ERR_PREAUTH_FAILED (24)
STS-KRB-0137 A FAST armor ticket was refused: not a TGT for the ticket-granting service of the realm asked, sealed under another key, expired or not yet valid. RFC 6113 section 5.4.1.1: KDC_ERR_PREAUTH_FAILED (24), KRB_AP_ERR_BAD_INTEGRITY (31), KRB_AP_ERR_TKT_EXPIRED (32), KRB_AP_ERR_TKT_NYV (33)
STS-KRB-0138 A FAST armor AP-REQ’s Authenticator was refused: it did not decrypt, named another client, was outside the clock tolerance, or carried no subkey. RFC 6113 section 5.4.1.1: KRB_AP_ERR_BAD_INTEGRITY (31), KRB_AP_ERR_BADMATCH (36), KRB_AP_ERR_SKEW (37), KDC_ERR_PREAUTH_FAILED (24)
STS-KRB-0139 A FAST req-checksum did not cover the outer request body under the armor key. RFC 6113 section 5.4.2: KRB_AP_ERR_MODIFIED (41)
STS-KRB-0140 A FAST enc-fast-req did not open under the armor key, or the KrbFastReq inside it did not decode. RFC 6113 section 5.4.2: KRB_AP_ERR_BAD_INTEGRITY (31)
STS-KRB-0141 A FAST request set a critical FAST option this KDC does not implement (hide-client-names). RFC 6113 section 5.4.2: KDC_ERR_UNKNOWN_CRITICAL_FAST_OPTIONS (93)
STS-KRB-0142 A PA-ENCRYPTED-CHALLENGE did not decode or did not decrypt under the challenge key: a wrong password inside FAST. RFC 6113 section 5.4.6: KDC_ERR_PREAUTH_FAILED (24)
STS-KRB-0143 A PA-ENCRYPTED-CHALLENGE’s timestamp was outside the clock tolerance. RFC 6113 section 5.4.6: KRB_AP_ERR_SKEW (37)
STS-KRB-0144 A PA-ENCRYPTED-CHALLENGE was presented a second time (the same ciphertext). RFC 6113 section 5.4.6: KRB_AP_ERR_REPEAT (34)
STS-KRB-0145 A PA-ENCRYPTED-CHALLENGE could not be proved unused because the claim store could not be asked. KRB_ERR_GENERIC (60)
STS-KRB-0146 A PA-OTP-REQUEST did not decode, its encData was not under the armor key or did not open, or it answered no PA-OTP-CHALLENGE this KDC issued (or its timestamp was outside the tolerance). RFC 6560 section 3.4: KDC_ERR_PREAUTH_FAILED (24), KDC_ERR_ETYPE_NOSUPP (14), KRB_AP_ERR_SKEW (37)
STS-KRB-0147 A PA-OTP-REQUEST carried no otp-pin, and this KDC requires the password as the PIN. RFC 6560 section 3.4: KDC_ERR_PIN_REQUIRED (97)
STS-KRB-0148 A PA-OTP-REQUEST’s otp-pin was not the person’s password (it does not derive the Kerberos key the KDC holds; an app password never does). RFC 6560 section 3.4: KDC_ERR_PREAUTH_FAILED (24)
STS-KRB-0149 A PA-OTP-REQUEST’s code was refused by the authenticator verifier: wrong, or no authenticator app enrolled. RFC 6560 section 3.4: KDC_ERR_PREAUTH_FAILED (24)
STS-KRB-0150 A PA-OTP-REQUEST’s code had already been used, at the KDC or at the sign-in screen (one step counter for both). RFC 6238 section 5.2: KDC_ERR_PREAUTH_FAILED (24)
STS-KRB-0151 A PA-OTP-REQUEST’s code could not be proved unspent because the step store could not be asked. KDC_ERR_PREAUTH_FAILED (24)
STS-KRB-0152 A PA-OTP-REQUEST carried no otp-value (a hashed OTP or one used as key material), which this KDC did not ask for. RFC 6560 section 3.6: KDC_ERR_PREAUTH_FAILED (24)
STS-KRB-0153 A ticket’s AD-CAMMAC did not verify under the key the ticket is sealed with, so its authentication indicators were ignored. RFC 7751 section 7, RFC 8129 section 5
STS-KRB-0154 Asking whether a person holds a second factor failed, so the KDC treated a password alone as not enough. —
STS-KRB-0155 An AS exchange waited (at most a second) for its client’s sign-out second to pass before taking authtime, so the new ticket is newer than the sign-out. Logged at debug; not a failure. —
STS-KRB-0156 An AS-REQ or TGS-REQ offered only encryption types this realm’s mode withholds — rc4-hmac, in product mode (#182). RFC 8429; KDC_ERR_ETYPE_NOSUPP (14)
STS-KRB-0157 A TGS-REQ’s ticket session key or Authenticator subkey is of an encryption type product mode withholds (rc4-hmac, #182). RFC 8429; KDC_ERR_ETYPE_NOSUPP (14)
STS-KRB-0158 The acceptor refused an AP-REQ whose ticket session key or Authenticator subkey is of an encryption type product mode withholds (rc4-hmac, #182). RFC 8429; KDC_ERR_ETYPE_NOSUPP (14)
STS-KRB-0159 A FAST armor AP-REQ’s subkey or ticket session key is of an encryption type product mode withholds (rc4-hmac, #182), so no armor key was made. RFC 6113 section 5.4.1.1, RFC 8429; KDC_ERR_ETYPE_NOSUPP (14)
STS-KRB-0160 A rotation of a trust realm’s krbtgt key failed — the new key could not be sealed or written to its directory entry — so nothing changed and the current key still seals every TGT. —
STS-KRB-0161 A trust realm’s stored krbtgt key record cannot be opened (sealed under another key-encryption key, stored in the clear in product mode, or bound to another realm). It is never rewritten: the KDC answers as though the realm had no krbtgt, and only “rotate and invalidate” replaces it. —
STS-KRB-0162 A node lost the race to create a trust realm’s first random krbtgt key and, re-reading the directory, did not find the winner’s key yet; the KDC refuses until it arrives. —
STS-KRB-0163 A trust realm’s first random krbtgt key was not made: this node could not ask the shared store whether another node was making it. —
STS-KRB-0164 A FAST armor ticket was sealed under a krbtgt key version the KDC no longer holds (a rotation retired it and its window ended, or “rotate and invalidate” dropped it). RFC 6113 section 5.4.1.1; KRB_AP_ERR_BADKEYVER (44)
STS-KRB-0165 A FAST-armored TGS-REQ (PA-FX-FAST) did not decode, named an armor type other than FX_FAST_ARMOR_AP_REQUEST, or was armored implicitly without a subkey in its PA-TGS-REQ Authenticator. RFC 6113 sections 5.4.1.1 and 5.4.2: KDC_ERR_PREAUTH_FAILED (24)
STS-KRB-0166 A TGS-REQ presented a ticket that is not a ticket-granting ticket and did not RENEW that ticket for its own server: a service ticket cannot buy other tickets. RFC 4120 section 3.3.3: KRB_AP_ERR_NOT_US (35)
STS-KRB-0167 A TGS-REQ’s ticket or Authenticator carried AD-fx-fast-armor (71), which marks FAST armor that may not be used to obtain a ticket. RFC 6113 section 5.4.1.1: KRB_ERR_GENERIC (60)
STS-KRB-0168 A TGS-REQ’s ticket or Authenticator carried AD-fx-fast-used (72) and the request was not armored with FAST. RFC 6113 section 5.4.2: KRB_AP_ERR_MODIFIED (41)
STS-KRB-0169 A user-to-user TGS-REQ (ENC-TKT-IN-SKEY) was refused: no additional ticket, not a TGT of this realm, it did not open or had expired, it was issued to another server than the one named, or its session key is an enctype the mode withholds. RFC 4120 section 3.3.3: KDC_ERR_BADOPTION (13), KRB_AP_ERR_BAD_INTEGRITY (31), KRB_AP_ERR_TKT_EXPIRED (32), KDC_ERR_SERVER_NOMATCH (26), KDC_ERR_ETYPE_NOSUPP (14)
STS-KRB-0170 An S4U2Self request’s PA-S4U-X509-USER did not decode (#186). [MS-SFU] 2.2.2: KDC_ERR_BADOPTION (13)
STS-KRB-0171 An S4U2Self request’s PA-S4U-X509-USER checksum did not verify under the TGT session key at key usage 26 (#186). [MS-SFU] 2.2.2: KRB_AP_ERR_MODIFIED (41)
STS-KRB-0172 An S4U2Self request’s PA-S4U-X509-USER carried a nonce that is not the request body’s (#186). [MS-SFU] 2.2.2: KDC_ERR_BADOPTION (13)
STS-KRB-0173 An S4U2Self request’s PA-S4U-X509-USER certificate names nobody in this realm: not issued to a person by its certificate authority, revoked, or without clientAuth (#186). [MS-SFU] 2.2.2: KDC_ERR_C_PRINCIPAL_UNKNOWN (6)
STS-KRB-0174 An S4U2Self request’s PA-S4U-X509-USER named one user and its certificate another (#186). [MS-SFU] 2.2.2: KDC_ERR_CLIENT_NAME_MISMATCH (75)
STS-KRB-0175 An S4U2Self request’s PA-S4U-X509-USER carried neither a cname nor a certificate (#186). [MS-SFU] 2.2.2: KDC_ERR_BADOPTION (13)
STS-KRB-0176 S4U2Proxy was refused because the evidence ticket’s PAC is missing, or its ticket or KDC signature does not verify with the krbtgt key: the ticket was altered after issue (CVE-2020-17049) or forged by the requester (#186). [MS-SFU] 3.2.5.2.2, [MS-PAC] 2.8.3: KRB_AP_ERR_MODIFIED (41)
STS-KRB-0177 S4U2Proxy was refused by the issuance policy’s delegation rules: a protected user, the front end’s subject groups or semantics, or the user’s authority for it (#186). Refused in both modes. KDC_ERR_BADOPTION (13) for the relationship, KDC_ERR_POLICY (12) otherwise

STS-LDAP

LDAP directory. The embedded directory on 389 and 636 and the console pages that show it.

Raised from: ldap/.

Code What failed Client sees
STS-LDAP-0001 An LDAP simple bind presented the reserved password this service refuses in every protocol. LDAP invalidCredentials (49)
STS-LDAP-0002 An LDAP simple bind was refused by the password verifier (product mode). The verifier’s own STS-AUTHN code is recorded instead where it gave one. LDAP invalidCredentials (49)
STS-LDAP-0003 An LDAP add, rename or search named a DN outside this directory’s naming context. LDAP noSuchObject (32)
STS-LDAP-0004 An entry could not be created because one already exists at that DN (LDAP add or rename, or a group create). LDAP entryAlreadyExists (68); a console/SCIM refusal elsewhere
STS-LDAP-0005 A person could not be created because another entry in ou=users already holds that username (one entry per person). LDAP entryAlreadyExists (68); a console/SCIM refusal elsewhere
STS-LDAP-0006 An entry could not be written because its parent container does not exist in this realm. LDAP noSuchObject (32); a console/SCIM refusal elsewhere
STS-LDAP-0007 The directory holds its maximum number of entries (ldap.maxEntries), so an entry was not created. LDAP adminLimitExceeded (11) on an add; a console/SCIM refusal, or nothing, elsewhere
STS-LDAP-0008 An LDAP add or modify carried an attribute value containing a NUL byte. LDAP invalidAttributeSyntax (21)
STS-LDAP-0009 An LDAP write tried to set pwdHistory or pwdChangedTime, which the password policy maintains (product mode). LDAP constraintViolation (19)
STS-LDAP-0010 An LDAP write would have left an entry holding more than one userPassword value. LDAP constraintViolation (19)
STS-LDAP-0011 An LDAP write supplied a pre-hashed userPassword in product mode, which cannot be checked against the password policy. LDAP constraintViolation (19)
STS-LDAP-0012 A userPassword written over LDAP was refused by the password policy. The policy’s own STS-AUTHN code is recorded instead where it gave one. LDAP constraintViolation (19)
STS-LDAP-0013 An operation named an entry that does not exist (LDAP delete, modify, rename, compare or search base; or a SCIM/console delete). LDAP noSuchObject (32); a SCIM 404 elsewhere
STS-LDAP-0014 An entry could not be deleted or renamed because other entries sit beneath it. LDAP notAllowedOnNonLeaf (66); a SCIM 400 elsewhere
STS-LDAP-0015 An LDAP modify carried no changes. LDAP protocolError (2)
STS-LDAP-0016 An LDAP modify named a change operation other than add, delete or replace. LDAP protocolError (2)
STS-LDAP-0017 An LDAP modify deleted an attribute the entry does not hold. LDAP noSuchAttribute (16)
STS-LDAP-0018 An LDAP modifyDN would have moved an entry into another trust realm’s directory. LDAP affectsMultipleDSAs (71)
STS-LDAP-0019 An LDAP compare named an attribute the entry does not hold. LDAP noSuchAttribute (16)
STS-LDAP-0020 A one-level or subtree search was based at the root DSE, which only a base search may read. LDAP noSuchObject (32)
STS-LDAP-0021 An LDAP search reached its size limit and the answer is incomplete. LDAP sizeLimitExceeded (4)
STS-LDAP-0022 A request worker failed an LDAP operation (it died or did not answer), so the operation was not retried in the front process. LDAP unavailable (52)
STS-LDAP-0023 A request worker refused an LDAP operation with an error name the front process could not rebuild into an LDAP result. LDAP operationsError (1)
STS-LDAP-0024 An LDAP handler run in a request worker finished without sending a result or failing, which would have hung the client. LDAP operationsError (1)
STS-LDAP-0025 The plain LDAP listener reported a socket error. —
STS-LDAP-0026 The LDAPS listener reported a socket error. —
STS-LDAP-0027 The plain LDAP listener could not bind its port at startup; the directory does not answer on it. —
STS-LDAP-0028 The LDAPS listener could not bind its port at startup; LDAPS is not offered. —
STS-LDAP-0029 No server certificate was available when the directory loaded, so LDAPS is not offered. —
STS-LDAP-0030 LDAPS could not be re-keyed with the certificate the service ended up with, so it serves the one built at require time. —
STS-LDAP-0031 A certificate authority’s CRL could not be published into the directory; its ldap:// distribution point fetches nothing. —
STS-LDAP-0032 The account-change observer threw after a directory write; the write stands and the observer’s event was lost. —
STS-LDAP-0033 The LDAP connection watcher failed, so request workers may hold a stale list of bound connections. —
STS-LDAP-0034 A search filter could not be evaluated against an entry (for example an extensible match), so the entry was treated as not matching. none; the entry is simply not returned
STS-LDAP-0035 ou=applications holds its maximum (applications.max), so an application sighting was not recorded. —
STS-LDAP-0036 ou=federations holds its maximum (federation.max), so a federation relationship was not created. —
STS-LDAP-0037 ou=policies holds its maximum (xacml.maxPolicies), so an XACML policy was not created. —
STS-LDAP-0038 ou=roles holds its maximum (roles.maxRoles), so a role was not created. —
STS-LDAP-0039 ou=peps holds its maximum (xacml.maxPeps), so a remote PEP registration was not created. —
STS-LDAP-0040 A credential or consent could not be written because the named identity has no entry in this realm. —
STS-LDAP-0041 roles.remotePepGroup or roles.xacmlUserGroup carries DN syntax, so its group was not seeded. —
STS-LDAP-0042 A user create, group create or membership change named no user or group. a console/API or SCIM refusal
STS-LDAP-0043 A user or group create was given a DN where a name was expected. a console/API or SCIM refusal
STS-LDAP-0044 A user create was given a decentralized identifier (DID) where a username was expected. a console/API or SCIM refusal
STS-LDAP-0045 A user create was given a SPIFFE ID where a username was expected. a console/API or SCIM refusal
STS-LDAP-0046 A user or group name carries a character RFC 4514 reserves in a DN, so it cannot name an entry. a console/API or SCIM refusal
STS-LDAP-0047 A user create named an attribute that is not in the person catalogue. a console/API refusal
STS-LDAP-0048 A write of a person or group named a DN that holds an entry of another kind. a SCIM or console/API refusal
STS-LDAP-0049 A group membership change named no member. a console/API refusal
STS-LDAP-0050 A group membership change named a group that does not exist, or an entry that is not a group. a console/API refusal
STS-LDAP-0051 A replicated change to ou=trustAnchors could not be applied to the TLS truststore; the next change or a restart reads it again. —
STS-LDAP-0052 In product mode, an anonymous LDAP connection asked to add, modify, rename or delete an entry. LDAP result code 50, insufficientAccessRights
STS-LDAP-0053 In product mode, a bound LDAP connection that does not hold Admin Write asked to add, rename or delete an entry, or to modify an entry other than its own. LDAP result code 50, insufficientAccessRights
STS-LDAP-0054 In product mode, a person asked to change an attribute on their own entry that ldap.selfWritableAttributes does not name. LDAP result code 50, insufficientAccessRights
STS-LDAP-0070 In product mode, an anonymous LDAP bind (no DN) was refused; a bind as somebody is required. LDAP result code 48, inappropriateAuthentication
STS-LDAP-0071 In product mode, a bind was made on the plain LDAP listener and refused before its password was read; binds require LDAPS. LDAP result code 13, confidentialityRequired
STS-LDAP-0072 In product mode, an unauthenticated bind (a DN with an empty password, RFC 4513 section 5.1.2) was refused. LDAP result code 53, unwillingToPerform
STS-LDAP-0073 In product mode, a bind was refused without checking its password because the bind DN or the address has had too many failed binds within the rate-limit window. LDAP result code 53, unwillingToPerform
STS-LDAP-0074 In product mode, a search or compare arrived on a connection that has not bound as anybody; the root DSE is the only read allowed before a bind. LDAP result code 50, insufficientAccessRights
STS-LDAP-0075 In product mode, a compare named a credential attribute (userPassword, a client secret, a private key, a TOTP or recovery code, an activation token or a Kerberos key), which no reader of the socket may test. LDAP result code 50, insufficientAccessRights
STS-LDAP-0076 In product mode, an add or modify named createTimestamp, modifyTimestamp or entryDN, which the directory maintains itself. LDAP result code 19, constraintViolation
STS-LDAP-0077 A delete or rename of the default realm’s bootstrap administrator (admin.bootstrapUsername) was refused — over LDAP or SCIM — because that account cannot be removed. LDAP result code 53, unwillingToPerform; SCIM 403
STS-LDAP-0078 A flag of the bootstrap administrator (pwdReset, stsBootstrapAdministrator or stsConsoleClaimedAt) could not be written because the account has no entry in this realm. none — logged
STS-LDAP-0090 A person was refused creation under a username that is a subject identifier (urn:uuid: or a bare UUID). action result ok:false (console, /admin-api HTTP 400, SCIM 400)
STS-LDAP-0091 No entry was created for an authentication whose identity is a urn:uuid: subject naming nobody in this realm’s directory. none — logged
STS-LDAP-0092 A create was refused because the same DN or username was still being created by another request, on this node or another one, when the create had waited for it as long as it waits. LDAP_ENTRY_ALREADY_EXISTS (68); HTTP 409 on SCIM and /admin-api
STS-LDAP-0093 A create was refused because the store that decides whether a DN or username is already being created elsewhere could not be asked (fail closed). LDAP_UNAVAILABLE (52); HTTP 503 on /admin-api, 500 on SCIM
STS-LDAP-0094 A bind could not be completed after the shared rate limiter was asked; the bind is answered operationsError. RFC 4511 section 4.1.9, operationsError (1)
STS-LDAP-0095 This node’s bound directory connections could not be read for, or committed to, the cluster connection table; other nodes list what it published last (a sign-out still reaches them by identity). none — logged
STS-LDAP-0096 Another node signed an identity out and this node could not close the directory connections bound as it; they may still be open. none — logged
STS-LDAP-0097 An account lock (pwdAccountLockedTime) changed through a directory write and handing the change to account_state.ts failed, so what the person held may not have been ended. none — logged; the write stands and every door refuses the person
STS-LDAP-0098 The node-ldapjs in use does not support the routeAnonymousBinds server option, so an anonymous bind is answered by the library and never reaches the bind handler; product mode cannot refuse it (reads on that connection are still refused). none — logged at startup
STS-LDAP-0099 In product mode, a compare named an attribute the bound identity may not read on that entry (ldap/directory_read_policy.ts); answered whether or not the entry holds it, so the refusal says nothing about the value. LDAP result code 50, insufficientAccessRights
STS-LDAP-0100 In product mode, a bind named a DN that is not a person’s — an application, a federation, a container — and was refused before its password was read; only people bind to the directory. LDAP result code 49, invalidCredentials (RFC 4513 section 5.1.3)
STS-LDAP-0101 A person’s attribute edit (#228) found no directory installed in this process, so there is no entry to change. HTTP 400 (API) or a 303 with error=
STS-LDAP-0102 A person’s attribute edit (#228) named nobody in this realm’s directory. HTTP 400 (API) or a 303 with error=
STS-LDAP-0103 A person’s attribute edit (#228) named an attribute the editor does not change: a credential, a binary value, the username or the address (which have doors of their own), or one outside the person schema. HTTP 400 (API) or a 303 with error=
STS-LDAP-0104 A person’s attribute edit (#228) named the attribute the entry’s own DN is built from, which would leave the DN and the entry disagreeing. HTTP 400 (API) or a 303 with error=
STS-LDAP-0105 A person’s attribute edit (#228) was not set, add or remove, or was an add to an attribute that holds one value. HTTP 400 (API) or a 303 with error=
STS-LDAP-0106 A person’s attribute edit (#228), or a create from the field grid, carried a value that is too long, holds a control character, does not have its attribute’s shape (a country code, a date, a language range, an http(s) URL, a DN), or was empty for an add or a remove. HTTP 400 (API) or a 303 with error=
STS-LDAP-0107 A person’s attribute edit (#228) added a value the attribute already holds. HTTP 400 (API) or a 303 with error=
STS-LDAP-0108 A person’s attribute edit (#228) removed a value the attribute does not hold. HTTP 400 (API) or a 303 with error=
STS-LDAP-0109 A person’s attribute edit (#228) would have left cn or sn, which RFC 4519 3.12 requires of every person, with no value. HTTP 400 (API) or a 303 with error=
STS-LDAP-0110 A person’s attribute edit (#228) was refused by the directory: the entry was gone or not a person’s when the write reached it. HTTP 400 (API) or a 303 with error=
STS-LDAP-0111 An LDAP add or modify named a credential attribute (a security key, an authenticator app, recovery codes, an app password, a signing key pair, a HOBA key, a self-issued subject, the emailed factor, Kerberos keys, a CIBA user code, an enrolment credential or a device secret). Credentials are written only through the doors that check them and send CAEP credential-change (#237), in every mode and for every bind, administrator included; the refusal names the door. RFC 4511 section 4.1.9 unwillingToPerform (53)
STS-LDAP-0112 The node-ldapjs in use does not support the encodeErrorMessage server option, so every LDAP result is sent with an empty diagnosticMessage and a client never sees the text of a refusal (#261). none — logged at startup
STS-LDAP-0120 A person was deleted from the directory (#241) and handing the delete to account_state.ts failed, so what they held may not have been ended at once. authn.sessionOf() still ends a session whose person has no entry the next time it is presented. none — logged; the delete stands
STS-LDAP-0130 A request or surface worker holding the directory as a window (ldap.workerDirectory=postgres-lru, #349) asked the store for an entry it did not hold and no answer came within ldap.workerDirectoryTimeoutMs — the database is down, unreachable or too slow. The request is refused rather than answered out of a window that cannot say what it is missing. HTTP 503 with Retry-After; an LDAP operation answers unavailable (52)
STS-LDAP-0131 A windowed worker’s question to the store (#349) was refused by the database: the connection failed or the statement errored. The request is refused as for STS-LDAP-0130. HTTP 503 with Retry-After; an LDAP operation answers unavailable (52)
STS-LDAP-0132 The directory bridge’s worker thread (#349) failed. The question it was answering timed out (STS-LDAP-0130); the next question starts a new thread. none — logged
STS-LDAP-0133 ldap.workerDirectory=postgres-lru (#349) was set where it cannot work: the store is not PostgreSQL (a memory or ldif store has nothing for a window to read), or the service is deployed as several cells (a person’s entry may be in another cell’s database). The service does not start. none — fatal at startup

STS-ATTR

Attribute sources. The operators’ SQL databases a realm reads people’s attributes from, onto their entries (#94): a source’s definition, its driver, its connection and password, the lookup, and the sign-in or scheduled refresh.

Raised from: attribute-sources/attribute_sources.ts, attribute-sources/attribute_source_drivers.ts, common/secrets.js (readSourceSecret), ldap/ldap_server.js (applySourcedAttributes).

Code What failed Client sees
STS-ATTR-0001 An attribute source’s driver (or Knex) is not installed: the dialect’s package is an optional one, installed into the image with STS_CLOUD_SDKS (#94). none (a console or API refusal, or a logged refresh failure)
STS-ATTR-0002 An attribute source could not be read: the connection, TLS, the password, the CA file or the query failed (#94). none (logged; per the source, the sign-in proceeds or is refused)
STS-ATTR-0003 An attribute source did not answer within its timeout (#94). none (logged; per the source, the sign-in proceeds or is refused)
STS-ATTR-0004 An attribute source has more than one row for a person’s key, so it names nobody (#94). none (logged; per the source, the sign-in proceeds or is refused)
STS-ATTR-0005 An attribute source’s definition was refused: its id, dialect, host, port, database, user, password provider, table, key or column names, refresh modes, interval, timeout or failure policy (#94). HTTP 400 (console and API)
STS-ATTR-0006 An attribute source’s password could not be read from where it names (#94). none (logged; per the source, the sign-in proceeds or is refused)
STS-ATTR-0007 An attribute source’s password was read and is empty (#94). none (logged; per the source, the sign-in proceeds or is refused)
STS-ATTR-0008 An attribute source may not write an attribute: one this service keeps, the entry’s identity, structure or authorization, or mail (#94). HTTP 400 (console and API), or logged at the write
STS-ATTR-0009 An attribute source named an attribute another source in the realm already writes; an attribute has one source (#94). HTTP 400 (console and API)
STS-ATTR-0010 An attribute source named a host attributeSources.hostPatterns does not allow in its realm (#94). HTTP 400 (console and API)
STS-ATTR-0011 An attribute source action named a source that is not there, or added one that already is, or named a person the realm does not have (#94). HTTP 400 (console and API)
STS-ATTR-0012 A sign-in was refused: an attribute source whose failure policy is refuse could not be read (#94). the calling protocol’s access_denied
STS-ATTR-0013 An attribute source’s refresh could not be queued on the scheduler (#94). HTTP 400 (console and API)
STS-ATTR-0014 The directory would not store or remove an attribute source (no directory, or it is full) (#94). HTTP 400 (console and API)
STS-ATTR-0015 An attribute source’s CA chain was refused: it is not PEM certificates, a block did not parse, a certificate is expired or not yet valid, or it is longer than 64 KiB (#94). HTTP 400 (console and API)

STS-SCIM

SCIM 2.0. Provisioning at /scim/v2 and its six authentication schemes.

Raised from: scim/.

Code What failed Client sees
STS-SCIM-0001 A SCIM endpoint (or HOBA key registration) was called while SCIM is turned off (scim.enabled). HTTP 501 (SCIM Error; plain JSON on /.well-known/hoba/register)
STS-SCIM-0002 A SCIM request body was not JSON. SCIM invalidSyntax (HTTP 400)
STS-SCIM-0003 A SCIM request body was refused by the document safety check (a polluting key, too deep or too many members) before scimmy coerced it. SCIM invalidSyntax (HTTP 400)
STS-SCIM-0004 A SCIM filter, attributes, excludedAttributes, sortBy or sortOrder parameter was longer than the limit. SCIM invalidFilter (HTTP 400)
STS-SCIM-0005 A SCIM startIndex or count was not an integer. SCIM invalidValue (HTTP 400)
STS-SCIM-0006 A SCIM filter could not be evaluated against the resources here. SCIM invalidFilter (HTTP 400)
STS-SCIM-0007 A SCIM User request named an id with no person entry under ou=users. HTTP 404 (SCIM Error)
STS-SCIM-0008 A SCIM User create or replace used the reserved userName this service refuses on purpose. SCIM invalidValue (HTTP 400)
STS-SCIM-0009 The directory refused a SCIM User create for a reason it did not name with a code of its own. SCIM uniqueness (HTTP 409) or invalidValue (HTTP 400)
STS-SCIM-0010 A SCIM User could not be mapped to a directory entry (userName is required). SCIM invalidValue (HTTP 400)
STS-SCIM-0011 The directory refused a SCIM User or Group write for a reason it did not name with a code of its own. HTTP 500, or SCIM invalidValue (HTTP 400)
STS-SCIM-0012 The directory refused a SCIM User or Group delete for a reason it did not name with a code of its own. HTTP 404, or SCIM invalidValue (HTTP 400)
STS-SCIM-0013 A SCIM Group request named an id that is not a group here. HTTP 404 (SCIM Error)
STS-SCIM-0014 A SCIM Group could not be mapped to a directory entry (displayName is required). SCIM invalidValue (HTTP 400)
STS-SCIM-0015 /Me was used by a request that authenticated as nobody, so there is no subject to alias. HTTP 501 (SCIM Error)
STS-SCIM-0016 /Me was used by a request whose authenticated subject has no entry under ou=users. HTTP 404 (SCIM Error)
STS-SCIM-0017 POST /Me was called; the authenticated subject already exists. HTTP 501 (SCIM Error)
STS-SCIM-0018 A SCIM .search body did not carry the SearchRequest schema URN. SCIM invalidSyntax (HTTP 400)
STS-SCIM-0019 A SCIM BulkRequest was larger than the advertised maximum payload size (scim.bulkMaxPayloadSize). HTTP 413 (SCIM Error)
STS-SCIM-0020 A SCIM handler threw something that is not a SCIM error — a defect in this service. HTTP 500 (SCIM Error)
STS-SCIM-0021 A SCIM request was refused inside the scimmy library itself (schema coercion, filter parsing, Bulk limits, or a handler error scimmy flattened to 404). SCIM Error (HTTP 4xx) as scimmy chose it
STS-SCIM-0022 A SCIM request failed inside the scimmy library itself with a server error. SCIM Error (HTTP 5xx)
STS-SCIM-0023 A HOBA key registration was refused for a reason scim_auth.js did not name with a code. HTTP 4xx/5xx JSON on /.well-known/hoba/register
STS-SCIM-0029 The SCIM authentication gate refused a request for a reason it did not name with a code. HTTP 401 or 403 (SCIM Error)
STS-SCIM-0030 A SCIM Bearer or DPoP access token was refused by the shared access-token check for a reason it did not name with a code. HTTP 401 (SCIM Error) with the check’s WWW-Authenticate/DPoP-Nonce headers
STS-SCIM-0031 A SCIM access token was not issued by this service, or its signature did not verify. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0032 A token presented to SCIM is not an access token (its typ is not Bearer). HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0033 A SCIM access token has been revoked. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0034 A SCIM HTTP Basic credential was not base64. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0035 A SCIM HTTP Basic credential carried no colon between user-id and password. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0036 A SCIM HTTP Basic credential named an empty username. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0037 A SCIM HTTP Basic password was refused by the verifier for a reason it did not name with a code of its own. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0038 A SCIM Digest credential set userhash=true, which this server does not support. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0039 A SCIM Digest credential named an algorithm this server does not offer (or MD5 while scim.digestMd5 is off). HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0040 A SCIM Digest credential asked for a qop other than auth. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0041 A SCIM Digest credential was missing username, nonce or response. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0042 A SCIM Digest credential named a nonce this server did not issue or has forgotten. HTTP 401 (SCIM Error, WWW-Authenticate stale=true)
STS-SCIM-0043 A SCIM Digest credential named a nonce older than scim.digestNonceSeconds. HTTP 401 (SCIM Error, WWW-Authenticate stale=true)
STS-SCIM-0044 A SCIM Digest credential with qop=auth carried no nc or no cnonce. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0045 A SCIM Digest nonce count was replayed. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0046 The uri in a SCIM Digest credential did not match the request-target. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0047 A SCIM Digest response hash did not match (wrong password). HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0048 A SCIM HOBA credential’s result was not four fields. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0049 A SCIM HOBA credential’s signature field was not base64url. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0050 A SCIM HOBA credential named a challenge this server did not issue or has forgotten. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0051 A SCIM HOBA credential named a challenge older than scim.hobaMaxAgeSeconds. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0052 A SCIM HOBA credential (key id, challenge and nonce) was replayed. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0053 A SCIM HOBA credential named a key id with no registered public key. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0054 The HOBA public key stored for a key id could not be read back — a broken registration in the directory. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0055 A SCIM HOBA signature did not verify against the registered key. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0056 A SCIM request presented HTTP Digest in product mode, where Digest is not offered. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0057 A SCIM request presented a credential in a scheme this service does not offer (or has turned off). HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0058 A SCIM request that requires authentication presented no credential. HTTP 401 (SCIM Error, WWW-Authenticate)
STS-SCIM-0059 A SCIM access token lacked the scim:read or scim:write scope the operation needs. HTTP 403 (SCIM Error), WWW-Authenticate error=insufficient_scope
STS-SCIM-0060 The access policy refused an authenticated SCIM request, for a reason it did not name with a code of its own. HTTP 403 (SCIM Error)
STS-SCIM-0061 A session could not be recorded for an accepted SCIM credential; the request went ahead. —
STS-SCIM-0062 An accepted SCIM credential could not be recorded at the authentication funnel; the request went ahead. —
STS-SCIM-0063 A HOBA key registration arrived while HOBA is turned off (scim.authHoba). HTTP 501 JSON
STS-SCIM-0064 A HOBA key registration carried no pub parameter. HTTP 400 JSON
STS-SCIM-0065 A HOBA key registration’s public key could not be read. HTTP 400 JSON
STS-SCIM-0066 A HOBA key registration offered a key that is not RSA. HTTP 400 JSON
STS-SCIM-0067 A HOBA key registration’s kid contained a full stop or whitespace. HTTP 400 JSON
STS-SCIM-0068 A HOBA key registration named nobody and came from no signed-in session. HTTP 400 JSON
STS-SCIM-0069 Outside development mode, a HOBA key registration for an existing account came from somebody not signed in as that account. HTTP 403 JSON
STS-SCIM-0070 Outside development mode, a HOBA key registration named an account that does not exist, and none is created. HTTP 404 JSON
STS-SCIM-0071 A HOBA key registration’s kid is already registered to another account. HTTP 409 JSON
STS-SCIM-0072 The directory refused to create the account a HOBA key registration named, for a reason it did not name with a code of its own. HTTP 409 or 400 JSON
STS-SCIM-0073 The account a HOBA key registration created could not be read back. HTTP 500 JSON
STS-SCIM-0074 A HOBA public key could not be written onto the account’s entry, for a reason the directory did not name with a code of its own. HTTP 507 or 400 JSON
STS-SCIM-0075 A SCIM error carried an HTTP status or scimType RFC 7644 section 3.12 does not allow, which is a defect in this service; it was sent as 500 rather than ending the process. HTTP 500 (SCIM Error)
STS-SCIM-0076 An HTTP Digest credential was refused because its nonce count had already been accepted with that nonce by another process of this service (a replay). RFC 7616 section 3.4; HTTP 401 with a fresh challenge
STS-SCIM-0077 A HOBA credential was refused because the same key id, challenge and nonce had already been accepted by another process of this service (a replay). RFC 7486 section 6; HTTP 401 with a fresh challenge
STS-SCIM-0078 A Digest or HOBA credential could not be proved unspent because the store that records spent credentials could not be asked; it was refused (fail closed). HTTP 500 (SCIM Error)
STS-SCIM-0079 An access token carried the SCIM scope an operation needs, and the client it was issued to no longer declares that scope in its oauthAllowedScope. HTTP 403 insufficient_scope (SCIM Error)
STS-SCIM-0080 A request named a path under /scim/v2 that is no SCIM endpoint; it is answered in the SCIM Error schema rather than by express as an HTML page (#206). HTTP 404 (SCIM Error, RFC 7644 section 3.12)
STS-SCIM-0081 A PUT, PATCH or DELETE carried an If-Match other than *, and this service keeps no entity-tags, so no version can match it (RFC 9110 section 13.1.1); nothing was changed (#206). HTTP 412 (SCIM Error, RFC 7644 sections 3.12 and 3.14)
STS-SCIM-0082 A filter ordered (gt, ge, lt, le) a boolean or binary attribute, which RFC 7644 section 3.4.2.2 refuses (#206). HTTP 400 invalidFilter (SCIM Error)

STS-SPIFFE

SPIFFE. The bundle endpoint, the Workload API and the SPIRE Server API.

Raised from: spiffe/.

Code What failed Client sees
STS-SPIFFE-0001 A SPIFFE gRPC handler failed with something that was not a gRPC status, which is a defect in this service (or the request worker running the method failed) rather than a problem with the call. gRPC UNKNOWN
STS-SPIFFE-0002 SPIFFE is turned off in this realm (spiffe.enabled), so the call or the bundle fetch was refused. gRPC UNAVAILABLE; HTTP 404 at the bundle endpoint
STS-SPIFFE-0003 A Workload API call did not carry the workload.spiffe.io: true metadata header the Workload Endpoint specification requires. gRPC INVALID_ARGUMENT
STS-SPIFFE-0004 spiffe_auth.js named a gRPC status grpc-js does not have; the call was refused with PERMISSION_DENIED instead. A defect in this service. gRPC PERMISSION_DENIED
STS-SPIFFE-0005 The XACML access policy refused a SPIRE Server API call that SPIRE’s own per-method table allowed. gRPC PERMISSION_DENIED
STS-SPIFFE-0006 A session for an authenticated SPIRE Server API caller could not be recorded; the call itself was unaffected. —
STS-SPIFFE-0007 The verified caller could not be attached to a gRPC call object, so its handler saw no caller detail. —
STS-SPIFFE-0008 Recording a gRPC call in the metrics counters threw and was ignored. —
STS-SPIFFE-0009 A configured SPIFFE socket path exists and is not a socket, so it was left alone and will not bind. —
STS-SPIFFE-0010 The SPIRE Server API Unix socket could not be made mode 0600, so other local users may reach the trusted local entity. —
STS-SPIFFE-0011 A SPIFFE gRPC listener could not bind its address or socket. —
STS-SPIFFE-0012 The SPIRE Server API TLS listener could not be set to request-but-not-require a client certificate, so a caller with no SVID cannot reach AttestAgent over TCP. —
STS-SPIFFE-0013 A SPIRE Server API method has no row in the authorization policy table, so it was refused. A defect in this service. gRPC PERMISSION_DENIED
STS-SPIFFE-0014 A SPIRE Server API method that requires an entity was called by a caller that presented no credential at all. gRPC UNAUTHENTICATED
STS-SPIFFE-0015 A SPIRE Server API caller does not hold any entity (local, agent, admin, downstream) the method is allowed to. gRPC PERMISSION_DENIED
STS-SPIFFE-0016 The client certificate presented to the SPIRE Server API carries no URI subjectAltName, so it is not an X509-SVID. gRPC PERMISSION_DENIED
STS-SPIFFE-0017 The client certificate presented to the SPIRE Server API carries more than one URI subjectAltName. gRPC PERMISSION_DENIED
STS-SPIFFE-0018 The URI subjectAltName on the presented client certificate is not a valid SPIFFE ID. gRPC PERMISSION_DENIED
STS-SPIFFE-0019 The client certificate presented to the SPIRE Server API would not parse. gRPC PERMISSION_DENIED
STS-SPIFFE-0020 The presented X509-SVID is not yet valid, allowing for the configured clock skew. gRPC PERMISSION_DENIED
STS-SPIFFE-0021 The presented X509-SVID has expired, allowing for the configured clock skew. gRPC PERMISSION_DENIED
STS-SPIFFE-0022 This service holds no X.509 authority to verify a presented X509-SVID against, which is a fault here. gRPC PERMISSION_DENIED
STS-SPIFFE-0023 A presented X509-SVID was signed by an authority belonging to a different trust domain from the one its SPIFFE ID names. gRPC PERMISSION_DENIED
STS-SPIFFE-0024 No X.509 authority this service holds, its own or federated, signed the presented X509-SVID. gRPC PERMISSION_DENIED
STS-SPIFFE-0025 One of this trust domain’s own X.509 authority certificates would not parse and cannot verify anything. —
STS-SPIFFE-0026 Recording an accepted SPIFFE credential as an authentication threw and was ignored. —
STS-SPIFFE-0027 A JWT-SVID was requested with no audience (FetchJWTSVID, MintJWTSVID or NewJWTSVID). gRPC INVALID_ARGUMENT
STS-SPIFFE-0028 FetchJWTSVID named a spiffe_id that is not a valid SPIFFE ID. gRPC INVALID_ARGUMENT
STS-SPIFFE-0029 A WIT-SVID method was called; this service issues no WIT-SVIDs and holds no WIT authority. gRPC UNIMPLEMENTED
STS-SPIFFE-0030 A held-open Workload API stream could not be re-sent its rotated SVIDs or bundles; the next rotation is still tried. —
STS-SPIFFE-0031 ValidateJWTSVID was given no JWT-SVID. gRPC INVALID_ARGUMENT
STS-SPIFFE-0032 ValidateJWTSVID was given no audience to validate against. gRPC INVALID_ARGUMENT
STS-SPIFFE-0033 The JWT-SVID given to ValidateJWTSVID is not a JWT. gRPC INVALID_ARGUMENT
STS-SPIFFE-0034 The sub claim of the JWT-SVID given to ValidateJWTSVID is not a valid SPIFFE ID. gRPC INVALID_ARGUMENT
STS-SPIFFE-0035 This service holds no JWT bundle for the trust domain a JWT-SVID names, so it cannot be validated. gRPC INVALID_ARGUMENT
STS-SPIFFE-0036 No key in the trust domain’s JWT bundle has the kid a JWT-SVID names. gRPC INVALID_ARGUMENT
STS-SPIFFE-0037 A JWT-SVID did not verify: its signature, expiry or audience was wrong. gRPC INVALID_ARGUMENT
STS-SPIFFE-0038 A verified JWT-SVID’s subject differs from the one presented; this should be unreachable. gRPC INVALID_ARGUMENT
STS-SPIFFE-0039 A federated bundle or federation relationship named a trust domain that is not a valid trust domain name. gRPC INVALID_ARGUMENT (per batch item)
STS-SPIFFE-0040 A federated bundle was submitted under a trust domain this service itself serves, in this realm or another. gRPC INVALID_ARGUMENT (per batch item)
STS-SPIFFE-0041 A submitted federated bundle is not a well-formed SPIFFE bundle document. gRPC INVALID_ARGUMENT (per batch item)
STS-SPIFFE-0042 The realm already holds its maximum number of federated bundles (spiffe.maxFederatedBundles). gRPC INVALID_ARGUMENT (per batch item)
STS-SPIFFE-0043 The SPIFFE issuing authority could not be built at startup, so nothing will issue an SVID. —
STS-SPIFFE-0044 An X509-SVID this service had just issued could not be read back for the directory; the SVID itself was unaffected. —
STS-SPIFFE-0045 A certificate in the SPIFFE authority’s own chain would not parse while its state was being reported. —
STS-SPIFFE-0046 No SPIFFE registration entry has the id the call named. gRPC NOT_FOUND (or per batch item)
STS-SPIFFE-0047 The registry refused to create a registration entry in a BatchCreateEntry call (invalid, duplicate, full, or not stored). gRPC INVALID_ARGUMENT (per batch item)
STS-SPIFFE-0048 An item of BatchUpdateEntry named no entry id. gRPC INVALID_ARGUMENT (per batch item)
STS-SPIFFE-0049 The registry refused a registration entry update in a BatchUpdateEntry call. gRPC INVALID_ARGUMENT (per batch item)
STS-SPIFFE-0050 No agent is recorded on this server under the id the call named or the connection carries. gRPC NOT_FOUND
STS-SPIFFE-0051 AttestAgent received a challenge_response with no attestation challenge outstanding on the stream. gRPC INVALID_ARGUMENT
STS-SPIFFE-0052 The agent attesting or renewing is banned on this server. gRPC PERMISSION_DENIED
STS-SPIFFE-0053 A call that signs a certificate signing request carried none (AttestAgent, RenewAgent, MintX509SVID, a BatchNewX509SVID item). gRPC INVALID_ARGUMENT (or per batch item)
STS-SPIFFE-0054 A join_token attestation carried an empty token. gRPC INVALID_ARGUMENT
STS-SPIFFE-0055 A join token presented at AttestAgent was never issued by this realm, or has already been spent. gRPC PERMISSION_DENIED
STS-SPIFFE-0056 A join token presented at AttestAgent has expired. gRPC PERMISSION_DENIED
STS-SPIFFE-0057 (retired) A join token created for a named agent was presented by an attestation producing a different agent. Retired 2026-09-21 (#40): the attesting agent is always the join token’s own, so the check refused every such token; agent_id now registers an alias entry, as SPIRE does (STS-SPIFFE-0084). gRPC PERMISSION_DENIED
STS-SPIFFE-0058 RenewAgent was called on a connection that carries no attested agent’s X509-SVID. gRPC UNIMPLEMENTED
STS-SPIFFE-0059 CreateJoinToken was refused because the realm holds spiffe.maxJoinTokens unexpired tokens. gRPC RESOURCE_EXHAUSTED
STS-SPIFFE-0060 AppendBundle or PublishJWTAuthority asked this service to add an authority to its own bundle, which it refuses. gRPC PERMISSION_DENIED
STS-SPIFFE-0061 No federated bundle or federation relationship is held for the trust domain named. gRPC NOT_FOUND (or per batch item); HTTP 404 at /spiffe/federated/{trustDomain}
STS-SPIFFE-0062 A federated bundle or federation relationship for that trust domain already exists. gRPC ALREADY_EXISTS (per batch item)
STS-SPIFFE-0063 A federated bundle delete in RESTRICT mode was refused because registration entries still federate with that trust domain. gRPC FAILED_PRECONDITION (per batch item)
STS-SPIFFE-0064 The certificate signing request given to MintX509SVID carries no SPIFFE ID in a URI subjectAltName. gRPC INVALID_ARGUMENT
STS-SPIFFE-0065 MintJWTSVID was not given the SPIFFE ID to mint for. gRPC INVALID_ARGUMENT
STS-SPIFFE-0066 Signing one item’s certificate signing request in BatchNewX509SVID failed. gRPC INVALID_ARGUMENT (per batch item)
STS-SPIFFE-0067 RefreshBundle asked this service to fetch a federated bundle from its recorded endpoint URL, which it never does. gRPC UNIMPLEMENTED
STS-SPIFFE-0068 A JWT authority could not be exported as DER for a Bundle message and was sent with empty key material. —
STS-SPIFFE-0069 The SPIFFE bundle endpoint has no trust bundle to serve because the authorities failed to build. HTTP 503
STS-SPIFFE-0070 The SPIRE Server API could not be given a TLS identity, so its TCP port bound plain and authenticates nobody. —
STS-SPIFFE-0071 A realm’s SPIFFE listener was not bound because another realm in this process already answers on that address. —
STS-SPIFFE-0072 A realm’s SPIFFE issuing authority failed while its listeners were starting; every call there will be refused with the reason. —
STS-SPIFFE-0073 A realm’s seed SPIFFE registration entries could not be created. —
STS-SPIFFE-0074 The SPIFFE listeners could not be reconciled after a trust realm changed. —
STS-SPIFFE-0075 A join token at AttestAgent could not be proved unspent because the cluster store could not be asked, so the attestation was refused. gRPC UNAVAILABLE
STS-SPIFFE-0076 A realm’s SPIFFE JWT authority or self-signed X.509 authority could not be established once for the cluster, so none was made. the SPIFFE call fails as when no authority could be built
STS-SPIFFE-0077 An agent asked for an SVID from a registration entry that is not beneath it (BatchNewX509SVID, NewJWTSVID). gRPC PERMISSION_DENIED (per batch item for BatchNewX509SVID)
STS-SPIFFE-0078 AttestAgent named a node attestor this realm does not accept: not in spiffe.nodeAttestors, or not one this server can verify. Nothing is taken on trust (#40). gRPC FAILED_PRECONDITION
STS-SPIFFE-0079 AttestAgent carried no attestation type in params.data.type. gRPC INVALID_ARGUMENT
STS-SPIFFE-0080 A node attestor challenged the agent and no challenge_response arrived within spiffe.attestationChallengeTimeout. gRPC DEADLINE_EXCEEDED
STS-SPIFFE-0081 The message after an attestation challenge carried no challenge_response. gRPC INVALID_ARGUMENT
STS-SPIFFE-0082 The AttestAgent stream closed or was cancelled while a node attestor’s challenge was outstanding. gRPC CANCELLED
STS-SPIFFE-0083 An agent already attested with evidence that is not re-attestable (a join token, a trust-on-first-use document) attested again; the agent must be deleted first, as in SPIRE. gRPC PERMISSION_DENIED
STS-SPIFFE-0084 CreateJoinToken’s agent_id could not be registered as the token’s alias entry (not in this trust domain, reserved, or the registry refused it), so no token was issued. gRPC INVALID_ARGUMENT
STS-SPIFFE-0085 A node attestor the realm accepts is not configured: x509pop in external_pki mode with no spiffe.x509popCaBundle, sshpop with no spiffe.sshpopCertAuthorities, tpm_devid with no DevID or endorsement anchors, or a template that does not parse. gRPC FAILED_PRECONDITION
STS-SPIFFE-0086 A node attestation payload or challenge response could not be read: not the attestor’s JSON, or a certificate, SSH certificate or TPM structure in it that does not parse. gRPC INVALID_ARGUMENT (INTERNAL for sshpop, as SPIRE answers)
STS-SPIFFE-0087 An x509pop attestation carried more intermediate certificates than spiffe.x509popMaxIntermediates. gRPC INVALID_ARGUMENT
STS-SPIFFE-0088 An x509pop attestation carried an RSA key larger than spiffe.x509popMaxRsaKeySize. gRPC INVALID_ARGUMENT
STS-SPIFFE-0089 A node attestor’s certificate did not chain to its configured trust anchors (x509pop, the tpm_devid DevID or endorsement certificate). gRPC PERMISSION_DENIED (x509pop), INVALID_ARGUMENT (tpm_devid)
STS-SPIFFE-0090 The agent’s address is not one its certificate allows (x509pop IP subjectAltNames, sshpop source-address), or the certificate carries no such restriction. gRPC PERMISSION_DENIED
STS-SPIFFE-0091 verify_client_ip is on and the agent has no address to verify (it came in on the Unix socket). gRPC INTERNAL
STS-SPIFFE-0092 No challenge could be issued for the attesting key: an x509pop certificate not for digitalSignature, or a key type the attestor does not sign with. gRPC INTERNAL
STS-SPIFFE-0093 A node attestor’s challenge response did not verify: the signature over the nonces, or the DevID signature. gRPC PERMISSION_DENIED (x509pop), INTERNAL (sshpop), INVALID_ARGUMENT (tpm_devid)
STS-SPIFFE-0094 An x509pop attestation in spiffe mode presented no SPIFFE ID, or one outside spiffe.x509popSpiffePrefix. gRPC PERMISSION_DENIED
STS-SPIFFE-0095 An agent path template could not produce a valid agent SPIFFE ID for this attestation. gRPC INTERNAL
STS-SPIFFE-0096 An sshpop host certificate was refused: not a host certificate, no principal, an authority not configured, outside its validity, an unsupported critical option, a signature that does not verify, or a first principal outside spiffe.sshpopCanonicalDomain. gRPC INTERNAL
STS-SPIFFE-0097 A tpm_devid attestation did not prove its DevID key resides in the TPM: incomplete, an endorsement certificate that does not match the EK, or a certification the attestation key did not sign. gRPC INVALID_ARGUMENT
STS-SPIFFE-0098 A tpm_devid credential activation returned the wrong secret: the TPM holding the EK did not decrypt it for this AK. gRPC INVALID_ARGUMENT
STS-SPIFFE-0099 A node attestor could not get an answer from a source it is configured to ask: a Kubernetes API server (TokenReview, a pod, a node), Google’s certificates, Microsoft’s tenant discovery or intermediate, or a cloud API. gRPC INTERNAL
STS-SPIFFE-0100 A k8s_psat token was not authenticated by the cluster’s TokenReview, or not for this server’s audience. gRPC PERMISSION_DENIED
STS-SPIFFE-0101 A k8s_psat agent’s service account is not in the cluster’s allow list, or the pod the token is bound to is not the pod that now has that name. gRPC PERMISSION_DENIED
STS-SPIFFE-0102 A k8s_psat agent named a cluster this realm is not configured for, or sent no cluster or token. gRPC INVALID_ARGUMENT
STS-SPIFFE-0103 An http_challenge agent’s port or agent name is not acceptable (required_port, allow_non_root_ports, the name’s form). gRPC INVALID_ARGUMENT
STS-SPIFFE-0104 An http_challenge agent’s host name matches none of spiffe.httpChallengeAllowedDnsPatterns (or is localhost), so it was neither resolved nor dialled. gRPC PERMISSION_DENIED
STS-SPIFFE-0105 An http_challenge fetch did not return the nonce: the host was unreachable, internal (product mode), redirected, or served something else. gRPC PERMISSION_DENIED
STS-SPIFFE-0106 A cloud node attestor is enabled and the SDK it calls its cloud with is not installed; the refusal names the package. gRPC FAILED_PRECONDITION
STS-SPIFFE-0107 A cloud identity document or token did not verify: an aws_iid signature against the region’s AWS certificate, an azure_imds PKCS#7 signature or its certificate chain, a gcp_iit token signature. gRPC INVALID_ARGUMENT
STS-SPIFFE-0108 A cloud node is not one this realm admits: a project, tenant or subscription not allowed, an account outside the organization, an instance outside the EKS clusters, a gcp_iit token for another audience or expired. gRPC PERMISSION_DENIED (INTERNAL for the aws_iid organization and EKS checks, as SPIRE answers)
STS-SPIFFE-0109 An aws_iid instance failed the block device check: its root volume and first network interface were not attached together. gRPC INTERNAL
STS-SPIFFE-0110 An azure_imds attested document did not carry this challenge’s nonce, or lacked a VM or subscription ID. gRPC INVALID_ARGUMENT
STS-SPIFFE-0111 A connection to the Workload API’s Unix socket could not be attested — the kernel would not name its peer, or a workload attestor (unix, docker, k8s) failed — and every call on it is refused. gRPC UNAVAILABLE
STS-SPIFFE-0112 A Workload API call arrived on a connection attested for a process that has since exited, whose pid was reused, or that executed a different program. gRPC PERMISSION_DENIED
STS-SPIFFE-0113 A realm’s Workload API Unix socket was not bound: this is a product and the native module workload attestation needs is not in the image. —
STS-SPIFFE-0114 A realm’s SPIRE Server API could not take a new certificate after the service Root was replaced, so it still presents a chain under the old Root and a client holding the new bundle cannot verify it until a restart. —
STS-SPIFFE-0115 After the service Root was replaced, a realm’s certificate authority branch did not arrive under the new Root within 30 seconds, so its SPIRE Server API was re-keyed anyway and the branch was repaired in this process — which may leave the realm with two Intermediate CAs if the process that replaced the Root rebuilds it too. —
STS-SPIFFE-0116 Product mode ignored spiffe.k8sSkipKubeletVerification: the k8s workload attestor verifies the kubelet’s certificate against its CA whatever it says. Logged once per process (#171). none — a warning in the log
STS-SPIFFE-0117 A caller on the SPIRE Server API’s Unix socket was not trusted as the local entity, in a product realm, because the socket was not verified private: it was not made 0600 (STS-SPIFFE-0010), the connection came before it was, or the socket or its directory has a group or other bit (#104). gRPC UNAUTHENTICATED (or PERMISSION_DENIED) from the method, which it may call only as another entity
STS-SPIFFE-0118 A caller on the SPIRE Server API’s Unix socket was not trusted as the local entity, in a product realm, because the kernel says it runs as a uid that is not this service’s own (#104). gRPC UNAUTHENTICATED (or PERMISSION_DENIED) from the method, which it may call only as another entity
STS-SPIFFE-0119 A caller on the SPIRE Server API’s Unix socket was not trusted as the local entity, in a product realm, because its kernel credentials could not be read — the native module is not built, or SO_PEERCRED failed (#104). gRPC UNAUTHENTICATED (or PERMISSION_DENIED) from the method, which it may call only as another entity
STS-SPIFFE-0120 The Workload API was not served over TCP in a product realm, because spiffe.workloadTcpSourceAuthenticated does not declare that the network authenticates source addresses (SPIFFE Workload Endpoint section 3) — the port was not bound, or a realm switched to product with it bound refused the call (#166). nothing listening on the port; gRPC UNAVAILABLE on a port already bound
STS-SPIFFE-0121 The Workload API was not served over TCP in a product realm: spiffe.workloadTcpSourceAuthenticated is on but spiffe.grpcHost is a wildcard address, and the declaration covers one named network (#166). nothing listening on the port; gRPC UNAVAILABLE on a port already bound
STS-SPIFFE-0122 A SPIFFE registration entry was refused in a product realm because it selects nothing that identifies a workload — no selector, or only transport: and endpoint: ones — at the console, /admin-api or the SPIRE Server API (#166). gRPC INVALID_ARGUMENT for the item in BatchCreateEntry and BatchUpdateEntry; a refused console or management API action
STS-SPIFFE-0123 A SPIFFE registration entry already in the registry that selects nothing identifying a workload answered no Workload API caller, because its realm is in product mode; said once per entry per process (#166). the entry is left out of the answer; the caller may get an empty SVID list
STS-SPIFFE-0124 The systemd workload attestor is named in spiffe.workloadAttestors and the optional D-Bus client (dbus-next) is not installed; every connection it would attest is refused, naming the package (#170). Logged once per process. gRPC UNAVAILABLE on every call of the connection
STS-SPIFFE-0125 The systemd workload attestor could not name a caller’s unit: D-Bus GetUnitByPID or a unit property failed, or the process the pid named changed while systemd was asked (#170). gRPC UNAVAILABLE on every call of the connection
STS-SPIFFE-0126 A docker workload’s image signature could not be verified because nothing to verify it with is configured: no cosign public key file, no verified TUF trust root and no pinned trusted_root.json, or a file that could not be read (#170). gRPC UNAVAILABLE on every call of the connection
STS-SPIFFE-0127 A docker workload’s cosign signature or attestation could not be fetched: its registry is not in spiffe.dockerSigstoreAllowedRegistries, the registry refused or failed, or a blob did not match its digest (#170). gRPC UNAVAILABLE on every call of the connection
STS-SPIFFE-0128 A docker workload’s image carried no cosign signature that verified: the signature under the key or certificate, the payload’s manifest digest, the keyless certificate’s chain to a Fulcio root, its SCT, or its signer identity (#170). gRPC UNAVAILABLE on every call of the connection
STS-SPIFFE-0129 A cosign signature’s Rekor transparency-log bundle was missing or did not verify: no bundle, a signed entry timestamp no trusted Rekor key verifies, or an entry that names another signature, key or payload (#170). gRPC UNAVAILABLE on every call of the connection
STS-SPIFFE-0130 A docker workload’s image had no in-toto attestation that verified, and spiffe.dockerSigstoreIgnoreAttestations is off (#170). gRPC UNAVAILABLE on every call of the connection
STS-SPIFFE-0131 The sigstore TUF refresh failed — a metadata file that did not verify under the trusted root’s keys and threshold, a version that went backwards, expired metadata, or a target whose length or hash did not match — and the last verified trust root was kept (#170). the scheduler job spiffe.sigstore-tuf-refresh fails; attestation goes on with the last verified set
STS-SPIFFE-0132 A SPIFFE Broker API call did not carry the broker.spiffe.io: true metadata header (SPIFFE Broker Endpoint section 3). gRPC INVALID_ARGUMENT
STS-SPIFFE-0133 A SPIFFE Broker API caller presented no X509-SVID, or one that did not verify against this trust domain’s or a federated bundle (SPIFFE Broker Endpoint section 5). gRPC UNAUTHENTICATED
STS-SPIFFE-0134 A SPIFFE Broker API caller’s X509-SVID verified and names no broker in spiffe.brokers (SPIFFE Broker API section 4.1). gRPC PERMISSION_DENIED
STS-SPIFFE-0135 A SPIFFE Broker API caller named a workload reference type its entry in spiffe.brokers does not allow (#170). gRPC PERMISSION_DENIED
STS-SPIFFE-0136 A SPIFFE Broker API request carried no workload reference, a malformed one, or a reference type this service does not understand (SPIFFE Broker API sections 3.1.1, 3.1.4 and 4.8, WORKLOAD_REFERENCE_INVALID). gRPC INVALID_ARGUMENT
STS-SPIFFE-0137 A SPIFFE Broker API reference named a process or pod that does not exist, or one that stopped while its stream was open (SPIFFE Broker API sections 4.8 and 4.9, WORKLOAD_NOT_FOUND). gRPC NOT_FOUND
STS-SPIFFE-0138 A SPIFFE Broker API reference named a workload no registration entry entitles to an SVID (SPIFFE Broker API section 4.8, WORKLOAD_NOT_ENTITLED). gRPC PERMISSION_DENIED
STS-SPIFFE-0139 A SPIFFE Broker API reference could not be attested: a workload attestor failed, or process references cannot be attested here without the native module (#170). gRPC UNAVAILABLE
STS-SPIFFE-0140 A realm’s SPIFFE Broker API listener was not bound, because it could not be given a mutual-TLS identity or its address is another realm’s; it is never bound plain (#170). nothing listening on the port
STS-SPIFFE-0141 An entry of spiffe.brokers was refused at the console or /admin-api: not a SPIFFE ID, or no reference type from pid, k8s and * (#170). a refused console or management API action
STS-SPIFFE-0142 A rootless Podman workload was not attested by the docker attestor because spiffe.dockerUseRootlessPodman is off, SPIRE’s rule; logged once per process (#170). no docker selectors for that workload
STS-SPIFFE-0143 A gRPC handler threw after the call waited for the cluster read barrier, so the exception could not reach grpc-js; a unary call is answered INTERNAL. INTERNAL for a unary call
STS-SPIFFE-0144 A certificate presented to the SPIRE Server or Broker API was signed by an authority this trust domain trusts and is refused: the two-certificate path breaks RFC 5280 (pki.verifyIssuedDirectly — a critical extension nothing here implements, a name constraint, a malformed certificate) or it is not a leaf X509-SVID (cA set, or a keyUsage without digitalSignature or with keyCertSign or cRLSign; X509-SVID section 4.3). #201. UNAUTHENTICATED / PERMISSION_DENIED, as for any unverified caller

STS-TLS

TLS and client certificates. The client-certificate truststore, the sign-in a verified one starts, and the server certificate the main port and LDAPS 636 share. The 8443 and 9443 listeners it was named for were deleted on 2026-09-16.

Raised from: tls/.

Code What failed Client sees
STS-TLS-0001 The service did not start: tls.minVersion, tls.ciphers, tls.groups or tls.signatureAlgorithms cannot build a TLS context. —
STS-TLS-0002 The service did not start: tls.certificateFile and tls.keyFile must be set together and only one was. —
STS-TLS-0003 The service did not start: the certificate or key named by tls.certificateFile / tls.keyFile could not be read. —
STS-TLS-0004 The service did not start: tls.certificateFile is not a PEM certificate. —
STS-TLS-0005 The service did not start: tls.keyFile is not a readable private key. —
STS-TLS-0006 The service did not start: the key in tls.keyFile does not match the certificate in tls.certificateFile. —
STS-TLS-0007 The trust anchor a request worker was handed does not sign the certificate handed in with it, so no anchor is published. —
STS-TLS-0008 This service’s Root CA does not sign the chain the TLS listener presents, so no anchor is published. —
STS-TLS-0009 The TLS listener certificate could not be re-issued under the certificate authority this service now holds. —
STS-TLS-0010 The client truststore could not be extended to a listener because it was given something that is not a TLS server. —
STS-TLS-0011 The client truststore could not be applied to a TLS listener, which keeps its previous context. —
STS-TLS-0012 A truststore add found no PEM certificate in what it was sent. HTTP 400 (POST /tls/trust)
STS-TLS-0013 A strict truststore add was refused whole because a certificate in it could not be read by OpenSSL. —
STS-TLS-0014 A truststore add stopped because the truststore holds its maximum number of anchors. HTTP 400 (POST /tls/trust) when nothing was added
STS-TLS-0015 A truststore remove named something that is not a SHA-256 fingerprint. —
STS-TLS-0016 A truststore remove named an anchor the truststore does not hold. —
STS-TLS-0017 Starting a sign-on session for a verified client certificate threw; the connection was unaffected. —
STS-TLS-0018 Recording a verified client certificate as an authentication threw; the connection was unaffected. —
STS-TLS-0019 The service did not start: tls.trustAnchorsFile could not be read. —
STS-TLS-0020 The service did not start: tls.trustAnchorsFile holds no PEM certificate. —
STS-TLS-0021 A TLS handshake failed on a listener this module watches — a version or cipher mismatch, or a non-TLS client; a client refusing this service’s certificate is STS-TLS-0034 since #225. It named the required-client-certificate listener until 2026-09-16, when that listener was deleted; it is now the main port, where a client certificate is asked for and never required TLS handshake failure
STS-TLS-0022 (retired) A TLS handshake failed on the optional-client-certificate listener. Retired 2026-09-16 with that listener; STS-TLS-0021 is the one code for a failed handshake now TLS handshake failure
STS-TLS-0023 A /tls or /tls/forwarded request carried a format parameter other than json or html. HTTP 400
STS-TLS-0024 POST /tls/trust or /tls/trust/clear was refused because product mode does not open the truststore to anybody who can reach the port. HTTP 403
STS-TLS-0025 (retired) A TLS listener could not bind its port. Retired 2026-09-16: this module owns no listener to bind —
STS-TLS-0026 The TLS listener certificate does not chain to this service’s Root and re-issuing it produced the same certificate. —
STS-TLS-0027 The runtime trust anchor store was installed without one of its list, write and remove functions, and was refused whole; runtime anchors are not persisted. —
STS-TLS-0028 A runtime trust anchor is in force but could not be written to ou=trustAnchors, so it will not survive a restart. —
STS-TLS-0029 A runtime trust anchor was removed from every listener but could not be removed from ou=trustAnchors, so it will come back on a restart. —
STS-TLS-0030 The stored trust anchors could not be read; the truststore was left as it was. —
STS-TLS-0031 (retired) The required-client-certificate listener refused a verified certificate this service issued that is not a TLS client identity. Retired 2026-09-16 with that listener: the same certificate is now refused where it is USED — no session at GET /tls/sign-in, no client authentication at the token endpoint — rather than at a socket HTTP 403 with the connection report
STS-TLS-0032 The file named by tls.certificateFile holds self-signed certificates, none of which signs the chain the listener presents, so no trust anchor is taken from it. —
STS-TLS-0033 A socket that presents the listener certificate (LDAPS, the SPIRE Server API) threw while being told the certificate was re-issued; the others were still told, and the main port serves the new one. —
STS-TLS-0034 A TLS client REFUSED this service’s certificate: it sent a certificate alert (bad_certificate, unsupported_certificate, certificate_revoked, certificate_expired, certificate_unknown or unknown_ca) during the handshake. From a browser it almost always means the client does not trust this service’s Root CA (#225). TLS handshake failure (the client closed the connection)
STS-TLS-0035 A connection was closed because its client certificate (or one in its chain) has an EC key on a curve outside the NIST set (P-256, P-384, P-521 and the other NIST-named curves); such certificates are refused before any certificate object is built (#212). the connection is closed after the handshake
STS-TLS-0036 The shared session-ticket key of an active-active cluster could not be applied to a TLS listener; that listener keeps its own keys, so a ticket it issues resumes only on this node. resumption falls back to a full handshake
STS-TLS-0037 The shared session-ticket key held in the store is not the 48 bytes node takes, so the listeners keep their own keys until the tls.ticket-key-rotate job replaces it. resumption falls back to a full handshake
STS-TLS-0038 A TLS session resumed on this node with a verified client certificate whose chain, replicated from the node that made the session, did not arrive within tls.resumedChainWaitMs; the request goes on with the leaf alone, and a revocation check that needs the chain answers as for a chain it cannot build. the request is answered; under hard-fail a certificate whose issuer this node does not hold is refused
STS-TLS-0039 A trust realm’s own listener (listener.port, #99) could not be bound on this node — the port in use, or not permitted — or failed after binding. The realm is still served on the main port under its prefix. the listener is absent on this node and shown as failed on the realm’s page and GET /admin-api/realms
STS-TLS-0040 A trust realm’s own listener has no certificate to present: its listener.certificateFile or privateKeyFile could not be read or do not match, it has no DNS name to issue one for, or the realm’s certificate authority did not issue one. the listener is not bound (or keeps the certificate it has, on a renewal)
STS-TLS-0041 A request on a trust realm’s own listener asked for a path outside that realm’s prefix — another realm’s, or the default realm’s; a realm’s listener serves that realm alone. 404
STS-TLS-0042 The listeners’ TLS settings this process started with leave a listener refusing every client, or are in the old shape: an empty tls.tls13CipherSuites, a TLS 1.3 suite in tls.ciphers (which is the TLS 1.2 list since #423), or tls.pqcOnly with no post-quantum suite or group to use. Set in the environment or an appconfig file, where no write could refuse it. the service does not start
STS-TLS-0043 A write to the listeners’ TLS settings was refused because it would leave a listener refusing every client: no TLS 1.3 suite, a TLS 1.3 suite in tls.ciphers, or post-quantum only (tls.pqcOnly, or a realm listener’s listener.pqcOnly) with no 256-bit suite or ML-KEM group to use. 400; nothing is written
STS-TLS-0044 The listeners’ TLS policy changed and could not be applied to one listener registered as re-keyed by its own module (a SPIFFE gRPC listener, the channel between cells); it keeps the policy it had. logged; Server configuration -> Listeners shows the policy in force
STS-TLS-0045 A TLS listener’s own trustAnchorsFile (listener.trustAnchorsFile, #429) could not be read or holds no certificate, so that listener's client truststore would be empty while configured to be filled. the service does not start

STS-VC

OpenID4VCI, OpenID4VP and DID. The credential issuer, the verifier, credential offers and DID documents.

Raised from: oid4vc/.

Code What failed Client sees
STS-VC-0001 An oid4vci encryption setting names no content encryption (enc) this issuer implements, so the implemented list is advertised and accepted instead. —
STS-VC-0002 A DID-named credential configuration names a sibling configuration the issuer metadata does not offer, so it is not advertised. —
STS-VC-0003 The Credential Issuer metadata could not be signed, so it was served without signed_metadata. —
STS-VC-0004 The identity JSON-LD context could not be read, so no configured claim is put in the ldp_vc credential being issued. —
STS-VC-0005 A configured claim maps to a JSON-LD term the vendored identity context does not define, so it was left out of an ldp_vc credential. —
STS-VC-0006 A Credential or Deferred Credential Request arrived unencrypted while the issuer requires request encryption. invalid_encryption_parameters (HTTP 400)
STS-VC-0007 A plain Credential or Deferred Credential Request body is not JSON. invalid_request (HTTP 400)
STS-VC-0008 An encrypted (application/jwt) Credential or Deferred Credential Request could not be decrypted or its plaintext is not JSON. invalid_encryption_parameters (HTTP 400)
STS-VC-0009 A Credential Request sent both credential_identifier and credential_configuration_id. invalid_credential_request (HTTP 400)
STS-VC-0010 A Credential Request used credential_identifier although the token response granted no credential_identifiers. unknown_credential_identifier (HTTP 400; invalid_credential_request until #187)
STS-VC-0011 A Credential Request named a credential_identifier the token response did not grant. unknown_credential_identifier (HTTP 400; invalid_credential_request until #187)
STS-VC-0012 A Credential Request used credential_configuration_id although the token response granted credential_identifiers. invalid_credential_request (HTTP 400)
STS-VC-0013 A Credential Request named a credential_configuration_id this issuer does not offer. unknown_credential_configuration (HTTP 400; unsupported_credential_type until #187)
STS-VC-0014 A Credential Request named no credential at all (neither credential_identifier nor credential_configuration_id). invalid_credential_request (HTTP 400)
STS-VC-0015 A Credential Request carried no credential_response_encryption while the issuer requires an encrypted response. invalid_encryption_parameters (HTTP 400)
STS-VC-0016 A Credential Request’s credential_response_encryption parameters are unusable (key, alg, enc or zip). invalid_encryption_parameters (HTTP 400)
STS-VC-0017 A Credential Request carried no JWT proof of possession. invalid_proof (HTTP 400)
STS-VC-0018 A Credential Request carried more proofs than the issuer’s batch size allows. invalid_credential_request (HTTP 400)
STS-VC-0019 A proof of possession in a Credential Request was refused (malformed, wrong typ, alg, audience, iat, nonce, or signature). invalid_proof, or invalid_nonce for a c_nonce this issuer does not hold (HTTP 400, #187)
STS-VC-0020 A Deferred Credential Request named a transaction_id this issuer never issued, has expired, or was already redeemed. invalid_transaction_id (HTTP 400)
STS-VC-0021 A Notification Request body is not JSON. invalid_notification_request (HTTP 400)
STS-VC-0022 A Notification Request named a notification_id this issuer never issued or that has expired. invalid_notification_id (HTTP 400)
STS-VC-0023 A Notification Request’s event is not one of credential_accepted, credential_failure or credential_deleted. invalid_notification_request (HTTP 400)
STS-VC-0024 The non-spec notification inspection endpoint was asked for a notification_id that does not exist. invalid_notification_id (HTTP 404)
STS-VC-0025 The Credential Offer page’s query parameters failed input validation. HTTP 400 plain text
STS-VC-0026 Where only registered addresses are accepted, the Credential Offer’s wallet parameter named a URL that is neither oid4vci.walletUrl nor listed in oid4vci.allowedWalletUrls. HTTP 400 plain text
STS-VC-0027 A pre-authorized (cross-device or deferred) Credential Offer was requested from a session that continued without signing in, where test controls are closed. HTTP 403 plain text
STS-VC-0028 The QR code for a cross-device Credential Offer could not be rendered. HTTP 500 plain text
STS-VC-0029 A Credential Offer fetched by reference (credential_offer_uri) does not exist or has expired. invalid_request (HTTP 404)
STS-VC-0030 Product mode: a pre-authorized code was spent after reaching oid4vci.txCodeMaxAttempts wrong Transaction Codes. —
STS-VC-0031 A certificate in oid4vp.trustedIssuerCertificates could not be read and is ignored by the Verifier. —
STS-VC-0032 The OID4VP Verifier page’s or presentation start endpoint’s query parameters failed input validation. HTTP 400 plain text
STS-VC-0033 Where only registered addresses are accepted, the presentation start’s wallet parameter named a URL that is neither oid4vp.walletUrl nor listed in oid4vp.allowedWalletUrls. HTTP 400 plain text
STS-VC-0034 The QR code for a cross-device OID4VP Authorization Request could not be rendered. HTTP 500 plain text
STS-VC-0035 An OID4VP Request Object fetched by request_uri does not exist. invalid_request (HTTP 404)
STS-VC-0036 An OID4VP Authorization Response was posted with a state for which no Authorization Request is outstanding. invalid_request (HTTP 400)
STS-VC-0037 The wallet answered an OID4VP Authorization Request with an error response (it declined or could not present). HTTP 200 with redirect_uri; the verdict records the wallet’s error
STS-VC-0038 An OID4VP Authorization Response’s vp_token is not a JSON object keyed by the DCQL credential query id, or holds no presentation. invalid_request (HTTP 400)
STS-VC-0039 A presented SD-JWT Disclosure is not base64url-encoded JSON. invalid_request (HTTP 400), as part of a refused presentation
STS-VC-0040 A presented SD-JWT Disclosure hashes to a digest the issuer never signed. invalid_request (HTTP 400), as part of a refused presentation
STS-VC-0041 A presentation failed one or more of the OID4VP Verifier’s checks (issuer signature, disclosures, key binding, nonce, audience, validity or requested claims). invalid_request (HTTP 400)
STS-VC-0042 The non-spec presentation result endpoint was asked for a state it has no record of. invalid_request (HTTP 404)
STS-VC-0043 The key credentials are signed with is not in this realm’s key set, so the DID document cannot publish it. —
STS-VC-0044 The BBS public key could not be published in the DID document. —
STS-VC-0045 The path-form /did.json was requested for a DID that has no path; did:web resolves it at the well-known location. not_found (HTTP 404)
STS-VC-0046 The DID generator was asked for a method other than jwk or web. invalid_request (HTTP 400)
STS-VC-0047 The embedded directory threw while being read for a person’s credential claims; the credential is built without directory values. —
STS-VC-0048 Populating the embedded directory for the current credential claim set threw. —
STS-VC-0049 A pre-authorized code this process still held was already redeemed by another process against the same store (the cluster claim, #46). invalid_grant (HTTP 400)
STS-VC-0050 A c_nonce every proof verified against was already spent by another process against the same store (the cluster claim, #46). invalid_nonce (HTTP 400, #187)
STS-VC-0051 The cluster claim store could not be asked about an OpenID4VCI single-use value — a pre-authorized code, a c_nonce or a Transaction Code attempt — so the request was refused rather than accepted unproven. invalid_grant or invalid_proof (HTTP 400)
STS-VC-0052 A wallet sign-in was refused because oid4vp.signIn is off. HTTP 403 page
STS-VC-0053 A wallet sign-in named no pending authentication — never started, expired, or already used — so there was nothing to sign in to. HTTP 400 page
STS-VC-0054 (retired) A wallet sign-in was refused for a request that demanded two factors (retired: it is now followed by a second factor). HTTP 403 page
STS-VC-0055 A wallet sign-in was asked about by a browser that did not start it (no binding cookie, or the wrong one), so it was not finished there. HTTP 403 page
STS-VC-0056 A wallet sign-in’s transaction is unknown, has expired, or belongs to a different pending authentication. HTTP 400 page
STS-VC-0057 A second OpenID4VP response arrived for a sign-in’s transaction, which is answered once. invalid_request (HTTP 400)
STS-VC-0058 A presentation verified and signed nobody in: the credential was signed by a certificate in oid4vp.trustedIssuerCertificates, not by this realm’s issuer. HTTP 403 page at /authn/wallet/wait
STS-VC-0059 A presentation verified and signed nobody in: this realm has no record of issuing the credential for a person on an access token it verified (another realm’s, a foreign token’s, or unknown). HTTP 403 page at /authn/wallet/wait
STS-VC-0060 A presentation verified and signed nobody in: the directory entry the credential was issued for no longer exists. HTTP 403 page at /authn/wallet/wait
STS-VC-0061 A presentation made to sign in did not verify (or was not a presentation at all), so nobody was signed in. HTTP 403 page at /authn/wallet/wait
STS-VC-0062 A wallet sign-in was already finished — here or on another node — and was not finished again. HTTP 400 page
STS-VC-0063 The cluster claim store could not be asked whether a wallet sign-in was already finished, so it was refused rather than finished unproven. HTTP 503 page
STS-VC-0064 A presentation verified and mapped to a person, and the issuance policy refused them a session. HTTP 403 page
STS-VC-0065 A wallet sign-in was returned to with a response_code that is not the one given to the wallet. HTTP 403 page
STS-VC-0066 A presentation verified and signed nobody in: its subject or holder key disagrees with what this realm recorded when it issued the credential. HTTP 403 page at /authn/wallet/wait
STS-VC-0067 An unexpected failure inside the wallet sign-in door. HTTP 500 page
STS-VC-0068 An issued credential could not be recorded as one that may sign its subject in; the credential was issued anyway. —
STS-VC-0069 A wallet sign-in request carried a malformed query parameter. HTTP 400 page
STS-VC-0070 A wallet sign-in was withdrawn by a sign-out after the wallet had presented and before the browser collected the session. HTTP 403 page at /authn/wallet/wait
STS-VC-0071 A presentation verified and signed nobody in: the credential was disowned — by a global sign-out, an administrator’s revocation, or its status-list entry. HTTP 403 page at /authn/wallet/wait
STS-VC-0072 A presented credential’s status list says it is revoked or suspended, or no statement about its status could be made (the list could not be fetched or verified, or the credential names none). invalid_request (HTTP 400); HTTP 403 page at a sign-in
STS-VC-0073 A Digital Credentials API answer was not a openid4vp-v1-signed DigitalCredential, was not in the response mode the request asked for, or its encrypted response could not be opened. HTTP 400 page at /authn/wallet/dc-api
STS-VC-0074 A Digital Credentials API answer was posted from a page on an origin other than the one the request named in expected_origins. HTTP 403 page at /authn/wallet/dc-api
STS-VC-0075 No status-list index could be allocated for a credential: the claim store could not be asked, or the list is full. server_error (HTTP 500) at the credential endpoint
STS-VC-0076 A status list (Token Status List or Bitstring Status List credential) could not be built or signed. HTTP 500
STS-VC-0077 A historical status list was asked for (the time parameter), which this issuer does not keep. HTTP 501
STS-VC-0078 A Bitstring Status List was asked for a purpose this issuer does not publish. HTTP 404
STS-VC-0079 A credential could not be built (its status index, its signature, or its proof). server_error (HTTP 500)
STS-VC-0080 An ldp_vc credential was asked for a holder key no Data Integrity cryptosuite here can prove (RSA, secp256k1, Ed448, a composite). invalid_proof (HTTP 400)
STS-VC-0081 The Digital Credentials API form was submitted with no answer — the page’s script did not run — and the same-device link was offered instead. HTTP 400 page at /authn/wallet/dc-api
STS-VC-0082 A status-list entry could not be changed from the console or the management API: no such index, an unknown status, or an INVALID entry asked to become valid again. HTTP 400 / HTTP 404
STS-VC-0083 A Digital Credentials API answer arrived for a sign-in that was not offered through the Digital Credentials API. HTTP 400 page at /authn/wallet/dc-api
STS-VC-0084 A wallet could not be the second factor: the step had expired, its first factor was already a wallet, or the credential was issued to somebody other than the person whose password was entered. HTTP 403 page at /authn/wallet/wait
STS-VC-0085 A certificate in oid4vci.keyAttestationTrustedCertificates could not be read and was ignored. —
STS-VC-0086 An access token this realm revoked was presented at an OpenID4VCI endpoint (credential, deferred credential or notification) in product mode. invalid_token (HTTP 401, WWW-Authenticate challenge)
STS-VC-0087 A BBS key was asked for at /bbs/keys/ that is not a live generation of this realm's BBS key (current, next, or retired within its grace). HTTP 404 not_found
STS-VC-0088 A credential presented to the OpenID4VP Verifier names no status (no Token Status List claim, no BitstringStatusListEntry) and oid4vp.requireStatusReference requires one: a foreign credential under all whose issuer certificate is not in oid4vp.statusOptionalIssuers, or one this realm signed under all or own-only. invalid_request (HTTP 400); HTTP 403 page at a sign-in
STS-VC-0089 An ldp_vc presented at the OpenID4VP Verifier (not a sign-in, whose register holds the status) disclosed no credentialStatus entry, though the request asked for it and oid4vp.requireStatusReference requires one. invalid_request (HTTP 400)
STS-VC-0090 A self-issued ID Token (SIOPv2, #129) was refused: it did not verify (iss not sub, a subject key that did not resolve or match, a bad signature, the wrong aud or nonce, expired or too old), or with vp_token id_token its subject was not the presentation’s holder. invalid_request (HTTP 400), or a 303 for form_post
STS-VC-0091 A self-issued ID Token verified and its subject is enrolled for nobody in the realm, so it signed nobody in — in both modes (#129). HTTP 403 page at /authn/wallet/wait
STS-VC-0092 oid4vp.verifierAttestation cannot be used — unreadable, not typ verifier-attestation+jwt, no sub, expired, or its cnf is not this realm’s request-signing key — so no signed request with the verifier_attestation prefix was built (#129). HTTP 500
STS-VC-0093 A SIOPv2 enrolment was started or collected by a browser holding no sign-on session, or for a person other than the one now signed in; or a self-issued ID was asked for as a second factor, which it is not offered as (#129). HTTP 403 / 400 page
STS-VC-0094 A key proved by a SIOPv2 enrolment was not enrolled: it is already enrolled for somebody, or the person holds the most they may (#129). HTTP 400 page
STS-VC-0095 A credential issuer’s well-known document was asked for at an inserted path no issuer here has (OpenID4VCI 1.0 section 12.2.2, #187). HTTP 404 {error: not_found}
STS-VC-0096 A presentation to the Verifier’s Response URI was not in the response mode its request asked for, or its direct_post.jwt response named no outstanding request’s key or could not be opened (OpenID4VP 1.0 section 8.3.1, #187). invalid_request (HTTP 400)
STS-VC-0100 A VC-API test endpoint (/vc-api/*, the Bitstring Status List publish hook) was called in a realm whose test controls are closed — a product realm — and answered as though it did not exist (#194). HTTP 404
STS-VC-0101 A VC-API test endpoint was presented an access token it refused: not issued by this realm, not an access token, revoked, without the vc-api:issue / vc-api:verify scope it needs, or issued to a client that no longer declares that scope (#194). HTTP 401 / 403 with WWW-Authenticate
STS-VC-0102 The VC-API issuer refused a credential that does not conform to the VC Data Model (a MUST of VCDM 2.0 or 1.1 broken), or that names an issuer other than the key it is asked to sign with (#194). HTTP 400 {errors}
STS-VC-0103 The VC-API issuer refused a credential JSON-LD safe mode rejects — a context this service does not hold (it fetches none), an undefined term, a redefined protected term, a relative IRI — or one its cryptosuite could not sign (#194-#196). HTTP 400 {errors}
STS-VC-0104 A VC-API issue request named an issuer (a securing mechanism and key) this service does not offer (#194). HTTP 404 {errors}
STS-VC-0105 A VC-API request failed inside this service rather than on its input (#194). HTTP 500 {errors}
STS-VC-0106 The VC-API verifier refused a credential or presentation: the data model, JSON-LD safe mode, a proof (the key, the purpose, the challenge or domain, the signature, the issuer), or a status list entry (#194-#198). HTTP 400 {verified: false, errors}
STS-VC-0107 A VC-API status change named a credential this realm issued no status for, a status type or purpose it does not publish, or tried to clear a revocation (#197). HTTP 404 / 400 {errors}
STS-VC-0108 A VC-API request body was not a JSON object, or carried a polluting key or more depth or members than any document this service accepts (validation.checkDocument, #194). HTTP 400 {errors}
STS-VC-0109 A DID the VC-API resolver was asked for could not be resolved, or a DID URL dereferenced: not a DID (invalidDid, invalidDidUrl), a method it does not support, a representation it does not produce, or a did:web other than this realm’s own, which it does not fetch (notFound) (#199). HTTP 400 / 404 / 501 with the resolution result’s error
STS-VC-0110 A Request Object with the x509_san_dns Client Identifier was asked for in product mode with no DNS name to certify: neither oid4vp.x509DnsName nor global.publicBaseUrl names one, and the Host a request arrived with is not certified there — whoever sent it would choose the host a signed, trusted request sends presentations to (#230). HTTP 500 text/plain at /oid4vp/start; the sign-in door’s 500 page; 409 JSON at /oid4vp/verifier-certificate
STS-VC-0111 The x509_san_dns name is not the host of the Response URI, or that host is an IP address: OpenID4VP 1.0 section 5.9.3 has a wallet that does not otherwise trust the Client Identifier require the response_uri’s FQDN to be it, so such a request would be refused by every such wallet (#230). HTTP 500 text/plain at /oid4vp/start; 409 JSON at /oid4vp/verifier-certificate
STS-VC-0112 The OpenID4VP Verifier’s certificate could not be issued, or was not in place over the key the Request Object is signed with when it was built, so no x509_san_dns or x509_hash request was made (#230). HTTP 500 text/plain at /oid4vp/start; 409 JSON at /oid4vp/verifier-certificate
STS-VC-0113 oid4vp.x509SigningAlgorithm names an algorithm this realm holds no signing key for, so no x509_san_dns or x509_hash request can be signed (#230). HTTP 500 text/plain at /oid4vp/start; 409 JSON at /oid4vp/verifier-certificate
STS-VC-0114 An application DID document was asked for and none is advertised: no such application in this realm, one not declared for the did family, or one with no key in didPublicKeyJwk. HTTP 404 JSON at /applications/{application}/did.json
STS-VC-0115 An application Domain Linkage Credential could not be signed: the application has no DID document, the origin is not one of its LinkedDomains services, or none of its published keys has a private half this service kept. none (a console or management API refusal, HTTP 400)

STS-SSF

Shared Signals, CAEP and RISC. Streams, subjects, delivery by push and poll, the receivers this service registers for itself, and the outbound push.

Raised from: ssf/.

Code What failed Client sees
STS-SSF-0001 A Shared Signals endpoint was called while the family is turned off (ssf.enabled). HTTP 501 {err: invalid_request}
STS-SSF-0002 An SSF endpoint was presented an access token that the shared access-token check refused (a DPoP proof, binding, audience or transport rule), and that check named no more specific condition. HTTP 401 {err: authentication_failed}, or the shared check’s own status and headers
STS-SSF-0003 An SSF endpoint was presented an access token this service did not issue, or whose signature does not verify. HTTP 401 {err: authentication_failed} with WWW-Authenticate
STS-SSF-0004 An SSF endpoint was presented a token that is not an access token (its typ claim names a refresh token, an ID Token or something else). HTTP 401 {err: authentication_failed} with WWW-Authenticate
STS-SSF-0005 An SSF access token lacked the scope the operation needs (ssf:read to read, ssf:write to change a stream). HTTP 403 {err: access_denied} with WWW-Authenticate
STS-SSF-0006 HTTP Basic was presented to an SSF endpoint while the scheme is turned off (ssf.authBasic). HTTP 401 {err: authentication_failed} with WWW-Authenticate
STS-SSF-0007 An SSF HTTP Basic credential did not decode to user:password. HTTP 401 {err: authentication_failed} with WWW-Authenticate
STS-SSF-0008 An SSF HTTP Basic credential carried the reserved password that is always refused, so that a wrong-credential path exists. HTTP 401 {err: authentication_failed} with WWW-Authenticate
STS-SSF-0009 An SSF HTTP Basic credential failed password verification (product mode: no such person, a wrong password, or a person with no password). HTTP 401 {err: authentication_failed} with WWW-Authenticate
STS-SSF-0010 A protected SSF endpoint was called with no credential at all. HTTP 401 {err: authentication_failed} with WWW-Authenticate
STS-SSF-0011 The body of an SSF management, subject, verification or poll request is not JSON. HTTP 400 {err: invalid_request}
STS-SSF-0012 A push stream was refused at creation because its delivery endpoint cannot be dialled by this transmitter (not a URL, wrong scheme, plain http with ssf.pushAllowHttp off, or a host outside ssf.pushAllowedHosts). HTTP 400 {err: invalid_request}
STS-SSF-0013 A Stream Configuration was refused at creation (a missing aud, an unsupported delivery method, a malformed member). HTTP 400 {err: invalid_request}
STS-SSF-0014 An SSF request named a stream_id this transmitter does not hold for the authenticated receiver — one that does not exist, or another receiver’s, which answers identically (#144). HTTP 404 {err: invalid_request}
STS-SSF-0015 A stream update (PUT or PATCH) was refused because the configuration it would produce is invalid. HTTP 400 {err: invalid_request}
STS-SSF-0016 A stream status change was refused (an unknown status value or a malformed request). HTTP 400 {err: invalid_request}
STS-SSF-0017 An Add Subject request was refused because the subject identifier is invalid (RFC 9493 format or member rules, or a missing critical member). HTTP 400 {err: invalid_request}
STS-SSF-0018 A Remove Subject request was refused because the subject identifier is invalid. HTTP 400 {err: invalid_request}
STS-SSF-0019 A verification request came sooner than the stream’s min_verification_interval while ssf.verificationRateLimit is on. HTTP 429 {err: invalid_request} with Retry-After
STS-SSF-0020 A verification request was refused because its stream is disabled. (Until #144 it also meant a push that failed; delivery is asynchronous now and a failed one is a dead letter.) HTTP 400 {err: invalid_request}
STS-SSF-0021 A poll request named a stream that delivers by push, so there is nothing to collect. HTTP 400 {err: invalid_request}
STS-SSF-0022 A Security Event Token was pushed at /ssf/receive while this service is not accepting pushed events (ssf.receiveEnabled). HTTP 501 {err: invalid_request}
STS-SSF-0023 A push at /ssf/receive carried an empty body. HTTP 400 {err: invalid_request}
STS-SSF-0024 A Security Event Token pushed at /ssf/receive did not verify, in product mode or while ssf.receiveRequireSignature is on (#117). HTTP 400 {err: invalid_key}
STS-SSF-0025 A Security Event Token pushed at /ssf/receive could not be read as a SET; it was recorded anyway. HTTP 400 {err: invalid_request}
STS-SSF-0026 An event was not transmitted on a stream because the stream does not deliver that event type. —
STS-SSF-0027 An event was not transmitted because its payload fails the event type’s member rules. —
STS-SSF-0028 An event whose type requires a subject was not transmitted because it carried none. —
STS-SSF-0029 An event was not transmitted on a stream because its subject is not one the stream covers. —
STS-SSF-0030 A built and signed Security Event Token was not queued on its stream (usually because the stream is disabled). —
STS-SSF-0031 A Security Event Token could not be signed, or its delivery failed with an exception, so the event was not transmitted. Check ssf.signingAlgorithm. —
STS-SSF-0032 An RFC 8935 push of a Security Event Token failed for a reason the push did not classify. —
STS-SSF-0033 A push was not made because push delivery is turned off (ssf.pushDelivery); the event stays on the queue. —
STS-SSF-0034 A push was not made because the stream’s delivery endpoint may not be dialled (not a URL, wrong scheme, plain http, or a host outside ssf.pushAllowedHosts). —
STS-SSF-0035 A push to one of this service’s own receivers was not made because this service’s TLS certificate could not be read to pin the connection. —
STS-SSF-0036 A receiver answered a push with a redirect, which is not followed. —
STS-SSF-0037 A receiver answered a push with a body larger than ssf.pushMaxResponseBytes. —
STS-SSF-0038 A receiver refused a pushed Security Event Token with an RFC 8935 error (400 with err and description). —
STS-SSF-0039 A receiver answered a push with a status that is neither success nor an RFC 8935 refusal (a 5xx, a 429, or another failure status). —
STS-SSF-0040 The response to a push failed while it was being read. —
STS-SSF-0041 A push request could not be built (a malformed request option). —
STS-SSF-0042 A receiver did not answer a push within ssf.pushTimeoutMs. —
STS-SSF-0043 A push could not connect to the receiver (DNS, connection refused, reset). —
STS-SSF-0044 A push was refused at TLS because nothing here trusts the receiver’s certificate. —
STS-SSF-0045 A Shared Signals console or management API action named a stream this transmitter does not hold. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0046 A stream status change from the console or management API was refused (an unknown status value). Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0047 An event emitted by hand from the SSF, CAEP or RISC console or management API carried a payload that is not JSON. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0048 An event transmitted by hand from the SSF console or management API carried a subject that is not JSON. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0049 The Shared Signals console or management API was asked for an action it does not have. Console error notice; HTTP 400 {ok: false, errors: [Unknown action …]} from /admin-api
STS-SSF-0050 A CAEP event emitted by hand named a type that is not one of CAEP’s eight. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0051 A CAEP event emitted by hand named a session the CAEP register does not track. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0052 A CAEP or RISC event emitted by hand has a payload that fails the event type’s member rules. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0053 A CAEP event emitted by hand was refused by the session register’s state machine (a session-presented about a revoked session). Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0054 A CAEP session reset named a session the register does not track. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0055 The CAEP console or management API was asked for an action it does not have. Console error notice; HTTP 400 {ok: false, errors: [Unknown action …]} from /admin-api
STS-SSF-0056 An automatic CAEP emission (a session starting, being presented or ending) failed with an exception. —
STS-SSF-0057 A RISC event emitted by hand named a type that is not one of RISC’s fourteen. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0058 A RISC event emitted by hand named no account. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0059 A RISC event emitted by hand was refused by the account register’s state machine (something other than account-purged about a purged account). Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0060 A RISC event emitted by hand was suppressed because the account has opted out (risc.honourOptOut). Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0061 A RISC account reset named an account the register does not track. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-SSF-0062 The RISC console or management API was asked for an action it does not have. Console error notice; HTTP 400 {ok: false, errors: [Unknown action …]} from /admin-api
STS-SSF-0063 An automatic RISC emission (a directory write this service observed) failed with an exception. —
STS-SSF-0064 An internal receive endpoint asked for a receiver surface this service does not have — a programming error in the surface’s route. HTTP 500 {err: invalid_request}
STS-SSF-0065 A push reached the admin console’s or user portal’s receive endpoint while this service is not running its own receivers (ssf.enabled or ssf.internalReceivers off). HTTP 501 {err: invalid_request}
STS-SSF-0066 A push reached an internal receive endpoint whose surface has no stream in this realm (it was deleted, or never seeded). HTTP 404 {err: invalid_request}
STS-SSF-0067 A push at an internal receive endpoint presented no authorization header, or not the one minted for that surface’s stream. HTTP 401 {err: access_denied}
STS-SSF-0068 A push at an internal receive endpoint carried an empty body. HTTP 400 {err: invalid_request}
STS-SSF-0069 A Security Event Token delivered to an internal receiver could not be read as a SET; it was recorded anyway. HTTP 400 {err: invalid_request}
STS-SSF-0070 A Security Event Token delivered to an internal receiver is not addressed to that receiver’s audience; it was recorded and refused. HTTP 400 {err: invalid_audience}
STS-SSF-0071 A Security Event Token delivered to an internal receiver did not verify, in product mode or while ssf.receiveRequireSignature is on (#117). HTTP 400 {err: invalid_key}
STS-SSF-0072 The admin console or the user portal could not be registered as a Shared Signals receiver in a realm, because its seeded stream configuration was refused; that surface’s inbox stays empty. —
STS-SSF-0073 A protocol family (GNAP) asked ssf.emitProtocolEvent() for an event type that is not one of CAEP’s; nothing was sent. —
STS-SSF-0074 A CAEP event a protocol family asked to emit failed ssf_events validation and was not sent. —
STS-SSF-0075 A CAEP event a protocol family asked to emit could not be built or delivered (the promise rejected). —
STS-SSF-0076 A family’s subject scope installed with ssf_streams.setSubjectScope() threw while a stream’s coverage was being decided; it was ignored (narrows nothing). —
STS-SSF-0077 A GNAP access token was presented to an SSF endpoint while GNAP is switched off in the realm (gnap.enabled), or the GNAP family is not loaded in this process. HTTP 401 authentication_failed
STS-SSF-0078 A GNAP access token presented to an SSF endpoint was refused and the GNAP resource-server check named no code of its own. HTTP 401 invalid_token
STS-SSF-0079 A GNAP access token presented to an SSF endpoint was issued for a named resource server, which this transmitter is not. HTTP 401 invalid_token
STS-SSF-0080 A GNAP access token presented to an SSF endpoint does not carry the ssf:read or ssf:write access the operation needs. HTTP 403 access_denied
STS-SSF-0081 A Security Event Token was not transmitted because the application that owns the stream is not allowed that event type (ssfAllowedEvents on its entry). —
STS-SSF-0090 A RISC event about an administrator’s act on an account (account-credential-change-required, recovery-information-changed) could not be built or delivered. —
STS-SSF-0091 A CAEP credential-change about a person could not be built, was not a valid event, or could not be delivered. —
STS-SSF-0092 A push was not made because ssf.pushBacklog pushes to the same receiver were already waiting for one of ssf.pushConcurrency slots; the SET was put on the stream’s dead-letter queue. —
STS-SSF-0093 A push stream was declared dead: its pushes all failed for ssf.deadStreamTimeoutS. Nothing more is pushed to it until a probe or an operator revives it. —
STS-SSF-0094 Security Event Tokens could not be delivered since the last dead-letter sweep and are on dead-letter queues (one summary line per realm per sweep, never one per SET). —
STS-SSF-0095 A stream was asked to be revived and is not dead. HTTP 400 on /admin-api/ssf/revive
STS-SSF-0096 A SET for a dead push stream was put on its dead-letter queue unsigned instead of being pushed. —
STS-SSF-0097 The dead-letter sweep failed in a realm; it is tried again at the next interval. —
STS-SSF-0098 Whether another process had already reported a stream as dead or revived could not be asked, so it was reported here and may be reported twice. none — logged
STS-SSF-0099 A GNAP key proof on a Shared Signals endpoint could not be confirmed unused across the cluster, so the token was refused. HTTP 401 {err: invalid_token}
STS-SSF-0100 The signing-key-rotated event (this service’s own) could not be transmitted after a rotation; the rotation itself stands. none — logged; nothing is sent to a receiver
STS-SSF-0101 A receiver asked to create a stream and already holds ssf.maxStreams streams — the limit is per receiver (SSF 1.0 section 8.1.1.1, “not allowed to create a stream”). HTTP 403 {err: access_denied}
STS-SSF-0102 A transmitter-initiated verification event (the console’s Verify, or POST /admin-api/ssf/verify) could not be sent on the stream. HTTP 400 on /admin-api/ssf/verify
STS-SSF-0103 The inserted-path form of the transmitter configuration document was asked for a path no transmitter’s issuer has (SSF 1.0 section 7.2). HTTP 404 {err: invalid_request}
STS-SSF-0104 A Security Event Token delivered to one of this service’s receivers is not explicitly typed secevent+jwt (SSF 1.0 section 4.1.1); it was recorded and refused. HTTP 400 {err: invalid_request}
STS-SSF-0105 A Security Event Token delivered to one of this service’s receivers carries an iss other than its stream’s, or one ssf.receiveIssuers does not list (SSF 1.0 section 4.1.6); it was recorded and refused. HTTP 400 {err: invalid_issuer}
STS-SSF-0106 A Security Event Token pushed at POST /ssf/receive is addressed to no audience ssf.receiveAudiences lists; it was recorded and refused. HTTP 400 {err: invalid_audience}
STS-SSF-0107 An access token (OAuth or GNAP) carried the Shared Signals scope an operation needs, and the client it was issued to no longer declares that scope in its oauthAllowedScope. HTTP 403 {err: access_denied}
STS-SSF-0108 A push delivery endpoint was refused because it is plain http and the realm is in product mode, where RFC 8935 push goes over TLS whatever ssf.pushAllowHttp says (#171). at stream creation HTTP 400 {err: invalid_request}; at push time none — a dead letter
STS-SSF-0109 Product mode ignored ssf.pushSkipTlsVerification: a push verifies the receiver’s certificate whatever it says. Logged once per process (#171). none — a warning in the log
STS-SSF-0110 No reaction to a signal this service’s own console or portal received could be decided: the signal-response policy is disabled, missing or does not load. The event is recorded and nothing is ended. —
STS-SSF-0111 A reaction the signal-response policy permitted to a received signal failed: the receiving surface’s sessions for the person could not be ended. —
STS-SSF-0112 The kerberos-tickets-invalidated event (this service’s own, #169) could not be transmitted after a krbtgt key was rotated with nothing kept; the rotation itself stands. none — logged; nothing is sent to a receiver
STS-SSF-0113 A Shared Signals act on a federation relationship was refused: an unknown signals-* action, no such service-provider-side relationship, no issuer or credential configured, an unsupported delivery, a stream already held, a bad status or subject, or no stream yet (#153, #373). console / /admin-api refusal (HTTP 400)
STS-SSF-0114 A federation partner’s Shared Signals configuration could not be discovered: the SSF issuer is not a URL, its /.well-known/ssf-configuration could not be read or does not name the issuer, a jwks_uri and a configuration_endpoint, or its jwks_uri could not be read (#153, #373). console / /admin-api refusal (HTTP 400)
STS-SSF-0115 A federation partner refused a stream act — create, read, update, delete, status, a subject or verification — or could not be reached (#153, #373). console / /admin-api refusal (HTTP 400)
STS-SSF-0116 Polling a federation partner’s Shared Signals stream (RFC 8936) failed (#153, #373). none (logged; the job tries again)
STS-SSF-0117 A push to /federation/signals/{id} named no relationship receiving by push here (none, disabled, its signals off, or no push stream), or its Authorization header is not the one this realm gave the partner (#153, #373). HTTP 404 or 401 {err}
STS-SSF-0118 A Security Event Token from a federation partner was malformed: not a compact JWS, typ not secevent+jwt, or no jti or events (#153, #373). HTTP 400 {err: invalid_request}, or a poll setErrs entry
STS-SSF-0119 A federation partner’s SET names an iss that is not the SSF issuer its configuration was discovered for (#153, #373). HTTP 400 {err: invalid_issuer}, or a poll setErrs entry
STS-SSF-0120 A federation partner’s SET’s aud does not name this realm’s stream audience (#153, #373). HTTP 400 {err: invalid_audience}, or a poll setErrs entry
STS-SSF-0121 A federation partner’s SET’s signature does not verify against the keys its SSF configuration names, and it was refused (product mode, or ssf.receiveRequireSignature) (#153, #373). HTTP 400 {err: invalid_key}, or a poll setErrs entry
STS-SSF-0122 Acting on a verified event from a federation partner — ending sessions, blocking or unblocking its sign-ins of a person, disabling or enabling their account — failed; the SET is recorded (#153, #373). none (logged)
STS-SSF-0123 A key event of this service’s own (federation-key-rotated, spiffe-authority-rotated or tls-certificate-changed, #245) could not be transmitted after the key moved; the change itself stands. none — logged; nothing is sent to a receiver
STS-SSF-0130 The RISC account register is over risc.maxAccountsTracked and every row left is an account holder’s opt-out (#260), which is never dropped to make room: RISC 1.0 section 2.8 makes the choice theirs. The register stays over its cap until the cap is raised. none — logged; the opt-outs are kept
STS-SSF-0131 An Add Subject request on a stream a person owns named somebody other than that person, and ssf.personStreamsSelfOnly is on. A person’s stream carries events only about them. HTTP 403 access_denied
STS-SSF-0132 A Shared Signals act on a federation relationship whose signals are off (fedSignalsEnabled), or an unblock of a person the relationship has not blocked (#373). console / /admin-api refusal (HTTP 400)

STS-RISK

Risk scoring. The external datasets a risk score reads — their import, verification, activation, rollback and retention — and the attributable failure history (#62).

Raised from: risk/, admin-ui/risk_admin.ts.

Code What failed Client sees
STS-RISK-0001 A dataset import was refused before anything was loaded: the dataset, the format or the realm is not one this service knows, or the format is not one that dataset takes, or the signature override was asked for a dataset other than fido.mds3. —
STS-RISK-0002 A dataset import was refused: the file’s SHA-256 is not the one its manifest or the caller named. Nothing was loaded and the active version stays. —
STS-RISK-0003 A dataset version was refused because it has fewer rows than risk.datasetShrinkLimitPercent allows against the active version — what a truncated download looks like. Its rows were deleted and the active version stays. —
STS-RISK-0004 A dataset version was refused because no line of the file was a row of its format. —
STS-RISK-0005 A dataset import failed in the store part-way through; the version is recorded as refused with the reason, its rows are deleted, and the active version stays. —
STS-RISK-0006 The store was asked to hold dataset rows of a kind it has no table for — a defect in the caller. —
STS-RISK-0007 A dataset version could not be activated or rolled back to: it is not one that loaded (it is loading, refused or deleted). —
STS-RISK-0008 The dataset directory could not be read, or a manifest in it is not JSON naming a dataset, a format and a file beside it; the manifest is skipped and the rest of the directory is imported. —
STS-RISK-0009 The risk retention job failed; superseded versions and old failures stay until its next run. —
STS-RISK-0010 An attributable failure could not be recorded in the store. The refusal it describes stands; only its record is lost. —
STS-RISK-0011 A Monitoring → Risk action or its /admin-api twin was refused: a read-only session, an unknown action, or a field it needs is missing. —
STS-RISK-0012 The install-time dataset loader (risk/risk_install.ts) could not import an entry: no database was named, the provider’s terms were not accepted with –accept-terms, or the download failed. The other entries are imported and the loader exits non-zero. —
STS-RISK-0013 A sign-in could not be assessed for risk (the store or a dataset lookup failed part-way). The sign-in stands; only its assessment is missing. —
STS-RISK-0014 A dataset import was refused because nobody has accepted its provider’s current terms (or the terms changed since they were accepted), or an acceptance was asked for a provider with none to accept. —
STS-RISK-0015 The install-time loader fetched a provider’s terms page (–check-terms) and it differs from the page seen at the last acceptance: read it before relying on the acceptance. —
STS-RISK-0016 An issuance was REFUSED on risk: the issuance policy denied it with the risk obligation’s refuse — by default, an authentication whose risk is HIGH. The client is told only that authentication failed. —
STS-RISK-0017 An issuance was refused UNTIL A STEP-UP: the issuance policy denied it with the risk obligation’s step-up (a second factor or a security key) and the door could not ask for it — a token endpoint, WS-Trust, the KDC, a federated or certificate sign-in, or a screen whose person holds no such factor. —
STS-RISK-0018 A step-up on risk was asked of a person who holds no factor that answers it. Refused rather than offered enrolment: enrolling a new factor under an elevated risk is how an attacker holding the password would get one. —
STS-RISK-0019 In development mode (observe only) the issuance policy would have refused on risk, and did not: the decision is recorded on the assessment and the issuance went ahead. risk.enforceInDevelopment turns enforcement on. —
STS-RISK-0020 A person’s risk level changed and no reaction could be decided: the risk-response policy is disabled or does not load. The change is recorded; nothing is announced, ended or disabled. —
STS-RISK-0021 A reaction the risk-response policy permitted (announce, end sessions, RISC credential-compromise, disable) failed part-way. The others were still taken; the change of risk is recorded. —
STS-RISK-0022 A FIDO MDS3 BLOB was refused: it is not a JWT carrying an x5c chain, the chain does not end at the FIDO root (or the configured risk.mdsTrustAnchors), or its signature does not verify. Nothing was loaded. FIDO Metadata Service v3.0, section 3.1.8
STS-RISK-0023 A FIDO MDS3 BLOB was refused because a certificate in its signing chain is revoked, or its status is unknown and the revocation policy refuses unknown. Nothing was loaded. FIDO Metadata Service v3.0, section 3.1.8
STS-RISK-0024 A FIDO MDS3 BLOB was refused because its serial number (no) is not greater than one already processed — a rollback. Nothing was loaded. FIDO Metadata Service v3.0, section 3.1.8
STS-RISK-0025 Monitoring → Risk Scoring, or GET /admin-api/risk/metrics, could not be answered: the risk store failed to count the window’s assessments. —
STS-RISK-0026 An entry of risk.signalFactors was ignored: it names no known signal, or its factor is not a positive number. The signal keeps its built-in factor; logged once for each value the setting is given. —
STS-RISK-0027 The risk.mds-refresh job could not download the FIDO MDS3 BLOB from risk.mdsUrl: outbound is off, the address is refused, the server did not answer 200, or the BLOB is larger than risk.mdsMaxBytes (#105). The active BLOB stays in force. FIDO Metadata Service section 3.2
STS-RISK-0028 A risk dataset upload was refused for its size: it declared, or sent, more than risk.uploadMaxBytes. Nothing of it is kept. —
STS-RISK-0029 A risk dataset upload was refused because risk.uploadDirectory has no room for it: its free space (statfs) could not hold the declared length — or, with none declared, risk.uploadMaxBytes — or the disk filled while it was written. —
STS-RISK-0030 risk.uploadDirectory could not be created or written, or an upload could not be written to it for a reason other than space. Nothing of the upload is kept. —
STS-RISK-0031 A risk dataset upload was malformed: not multipart/form-data (the console) or not one of the three body types (the API), no file, a second file, a field after the file, no dataset or format, an unknown or repeated query parameter, an empty file, a body that ended early — or a body a body parser had already read, which is a defect in common/app.js’s exemption. —
STS-RISK-0032 A compressed risk dataset file expanded past what it may: risk.expandedMaxBytes, or risk.expansionMaxRatio times its stored size above 16 MiB — a decompression bomb. The version is refused and nothing of it is kept. —
STS-RISK-0033 A zip risk dataset file holds no data entry or more than one (directories and __MACOSX/ aside), or its entry is encrypted or compressed with a method other than stored or deflate. Refused as ambiguous or unreadable. —
STS-RISK-0034 A compressed risk dataset file could not be expanded: a truncated or corrupt gzip stream, or a zip whose directory or entry does not read. The version is refused. —
STS-RISK-0035 A risk dataset version was left loading with no progress for risk.importStallMinutes — the process importing it stopped — and the risk.stalled-imports job refused it; or an import found its version already refused that way and stopped. —
STS-RISK-0036 The risk.upload-cleanup job removed a leftover upload file that no live process had touched for risk.importStallMinutes, or an upload file could not be deleted after its import. —
STS-RISK-0037 A risk dataset upload failed unexpectedly: its fields could not be checked, or its import threw rather than answering. The upload’s file is deleted. —
STS-RISK-0038 An authentication at HIGH or MEDIUM risk was PERMITTED for an application the issuance policy says risk may never lock out (the role-issuance template’s neverLockOut, the console by default), because the person holds no second factor to step up with (#226). The alarm: enrol a second factor for this person, and look at the assessment’s signals. permitted; recorded on the audit row and logged as a warning
STS-RISK-0039 An administrator with no second factor was sent to set one up (offered or required, #246) at a sign-in whose risk is HIGH or MEDIUM. The enrolment goes ahead so the console is never locked out (#226); whoever holds the password could be the one enrolling, so confirm it with the person. the set-up step; recorded on the audit row and logged as a warning
STS-RISK-0040 The install-time dataset loader (risk/risk_install.ts) could not make the database connection the way the service makes it (#213): persistence.databasePasswordProvider names a secret store whose password could not be read, or persistence.databaseUrl is not a URL it can be put into. The provider’s own reason follows. Nothing is imported and the loader exits non-zero. —
STS-RISK-0041 Monitoring → Geolocation (/admin/geolocation or GET /admin-api/geolocation, #255) could not be drawn or answered: the store’s count of the realm’s assessments by place failed, or the country outlines (admin-ui/natural_earth/countries.json) could not be read. The reason follows on the log line. HTTP 500
STS-RISK-0042 Monitoring → Geolocation was asked for something it does not draw (#255): a window other than live, 24h, 7d or 30d, a continent that is not one of the seven slugs, a country that is not an ISO 3166-1 alpha-2 code on the map, or a country together with a continent it is not in. HTTP 400
STS-RISK-0043 A FIDO MDS3 BLOB was LOADED although its signature or signing chain does not verify, because the administrator who uploaded it ticked the signature override. Its contents are unauthenticated and its chain’s revocation was not checked; the version is recorded with verification “overridden” and the reason. Replace it with a BLOB that verifies as soon as FIDO publishes one. loaded; recorded on the audit row and logged as a warning
STS-RISK-0044 A security key found cloned (its signature counter went backwards) could not be recorded on the person’s risk standing (#231). The assertion was refused and RISC credential-compromise was still sent; only the standing, and the risk-response policy’s reaction to it, are missing. WebAuthn Level 3 section 6.1.1

STS-MAIL

Mail. The one outbound mail channel (#63): the outbox and its delivery job, the five transports (capture, SMTP, Amazon SES, Azure Communication Services, the Gmail API), the templates, the rate ceilings, and the uses — self-service password reset, address verification, an administrator’s links mailed, and the security notices. No code here is ever sent to a recipient.

Raised from: common/mail.ts, common/mail_transports.ts, common/mail_uses.ts, common/mail_templates.ts, admin-ui/mail_admin.ts, portal/portal_mail.ts.

Code What failed Client sees
STS-MAIL-0001 A message was not queued because no mail transport is configured in the realm (mail.transport is off, or default in product mode). —
STS-MAIL-0002 Product mode: a configured mail transport cannot be built, and the service does not start. the service does not start
STS-MAIL-0003 The capture mail transport was asked for in product mode, where a captured message would put its body on the console; refused on write and at start. HTTP 400 on a settings write; the service does not start
STS-MAIL-0004 A mail transport could not be built (a missing host, an unreadable file, a half-configured option); the attempt is retried and then dead-lettered. —
STS-MAIL-0005 A cloud mail transport needs its SDK (an optional peer) and it is not installed. —
STS-MAIL-0006 A mail secret (the SMTP password, the DKIM key, the Azure connection string or the Gmail key) could not be read from its store. —
STS-MAIL-0007 A mail secret was read and is empty. —
STS-MAIL-0008 The relay or provider refused the message permanently (an SMTP 5xx, a rejected sender or recipient, a failed Azure operation); it is a dead letter. —
STS-MAIL-0009 A message could not be handed over this time (a timeout, a lost connection, an SMTP 4xx, throttling or a 5xx); it is retried with backoff. —
STS-MAIL-0010 A message was not queued because its recipient reached a rate ceiling (mail.ratePerRecipient or mail.ratePerCategory in mail.rateWindowS). —
STS-MAIL-0011 A message was not queued because the recipient’s entry has no mail address (or, for a self-service reset, no verified one). —
STS-MAIL-0012 A message was not queued because there is no entry for the recipient in the realm. —
STS-MAIL-0013 A message was not queued because the recipient declined its (optional) category. —
STS-MAIL-0014 TLS with the mail relay failed (its certificate did not verify, or the upgrade was refused) and nothing is sent in the clear. —
STS-MAIL-0015 A message carrying a link was not queued: global.publicBaseUrl is empty and product mode never builds a mailed link from a request. —
STS-MAIL-0016 A realm’s message template was refused when saved: an address of its own, remote content, script, an unknown placeholder or a missing link. HTTP 400
STS-MAIL-0017 A message template was named that does not exist, or a template to reset has no realm wording. HTTP 400
STS-MAIL-0018 A mail retry was refused: the message is unknown, not a dead letter, kept no body, or its recipient has no usable address now. HTTP 400
STS-MAIL-0019 A message still pending mail.retentionS after it was queued was dead-lettered. —
STS-MAIL-0020 A delivery attempt was deferred because the claim store could not be reached; the next sweep tries again. —
STS-MAIL-0021 The mail relay refused this service’s SMTP login. —
STS-MAIL-0022 DKIM signing is configured and cannot be done (no key, no selector, or a key that cannot sign). —
STS-MAIL-0023 A message was not queued because an address (the recipient’s mail attribute or mail.from) is not one plain mailbox. —
STS-MAIL-0024 An address verification link was refused: used, expired, or sent to an address the entry no longer has. HTTP 400 page on /portal/verify-email
STS-MAIL-0025 A console or management API mail action was unknown or malformed. HTTP 400
STS-MAIL-0026 A console session that may read but not write posted a mail action. HTTP 400
STS-MAIL-0027 A test message was asked for by an administrator whose own entry has no usable mail address. HTTP 400
STS-MAIL-0028 The periodic mail summary line counted dead letters or deferred attempts since the last one. —
STS-MAIL-0029 The mail outbox sweep failed in a realm. —
STS-MAIL-0030 A self-service password reset was asked for and no link was sent (not offered, the account disabled, or none could be issued); the form answers exactly as if one was. —
STS-MAIL-0031 A message or security notice could not be queued because of an unexpected error in the mail channel. —
STS-MAIL-0032 An address verification was asked for where no mail transport is available. HTTP 400
STS-MAIL-0033 A self-service password reset page was asked for where it is not offered (mail.selfServiceReset off, no transport, or passwords are not verified). HTTP 404
STS-MAIL-0034 A person tried to decline a mail category that cannot be declined (security notices, requested links). HTTP 400
STS-MAIL-0035 A self-service reset named the account and its address and gave a recovery code that is not one of the person’s; nothing was mailed but a notice of the attempt (#64, D4). the same sentence as a sent link
STS-MAIL-0036 A self-service reset gave an address that is not the account’s (#64, D4). the same sentence as a sent link
STS-MAIL-0037 A self-service reset was asked for an account that holds no unused recovery code, while one is required (#64, D4). the same sentence as a sent link
STS-MAIL-0038 A followed verification link for a NEW address could not write it to the entry (#64, D5). HTTP 400 page
STS-MAIL-0039 A person asked to change their address to something that is not an address this service can send to (#64, D5). HTTP 400 page
STS-MAIL-0180 The notice telling a person that a GNAP grant waits for their approval on the portal could not be queued; the request still waits there (#432 phase 6). log only

STS-GNAP

GNAP (RFC 9635 / RFC 9767). The grant request and continuation endpoints; interaction (redirect, app, user code); key proofing (HTTP message signatures, mutual TLS, detached and attached JWS); the five access token formats (jwt-signed, jwt-encrypted, macaroon, biscuit, zcap); token management; the RS-facing introspection, resource registration and token derivation of RFC 9767; the push finish outbound request; the console pages; and CAEP emission for grants.

Raised from: gnap/.

Code What failed Client sees
STS-GNAP-0001 A GNAP key names a proofing method this authorization server does not implement, in string or object form. HTTP 401 GNAP invalid_client
STS-GNAP-0002 A GNAP key’s “proof” member is neither a method name nor an object. HTTP 401 GNAP invalid_request
STS-GNAP-0003 A GNAP key uses the object form of “proof” for a method that is defined in string form only (every method but httpsig). HTTP 401 GNAP invalid_request
STS-GNAP-0004 An httpsig proof in object form lacks “alg” or “content-digest-alg” (RFC 9635 section 7.3.1). HTTP 401 GNAP invalid_request
STS-GNAP-0005 A GNAP key is neither a key object nor a non-empty reference string. HTTP 401 GNAP invalid_request
STS-GNAP-0006 A GNAP key reference names no key registered with this authorization server (no application entry carries it, or its shared key is unopenable or shorter than 32 bytes). HTTP 401 GNAP invalid_client
STS-GNAP-0007 A GNAP key by value is presented in no format, or in more than one of jwk, cert and cert#S256 (RFC 9635 section 11.35). HTTP 401 GNAP invalid_client
STS-GNAP-0008 A GNAP key’s “cert” member is not a PEM X.509 certificate. HTTP 401 GNAP invalid_client
STS-GNAP-0009 A GNAP key’s “cert#S256” member is not a base64url SHA-256 thumbprint. HTTP 401 GNAP invalid_client
STS-GNAP-0010 A GNAP key’s “jwk” member is not a JSON Web Key object. HTTP 401 GNAP invalid_client
STS-GNAP-0011 A GNAP key by value carries private or symmetric JWK material; only a public key may be sent. HTTP 401 GNAP invalid_client
STS-GNAP-0012 A JWK presented in GNAP lacks “alg” or “kid”, or names alg “none”. HTTP 401 GNAP invalid_client
STS-GNAP-0013 A JWK presented in GNAP names an alg that is not an asymmetric JWS algorithm for its key type. HTTP 401 GNAP invalid_client
STS-GNAP-0014 A JWK presented in GNAP does not import as a public key. HTTP 401 GNAP invalid_client
STS-GNAP-0020 A GNAP document’s “access” member is not an array of access rights. HTTP 400 GNAP invalid_request
STS-GNAP-0021 A GNAP access right is an empty reference string. HTTP 400 GNAP invalid_request
STS-GNAP-0022 A GNAP access right is neither a reference string nor an object with a string “type”. HTTP 400 GNAP invalid_request
STS-GNAP-0023 A GNAP access right’s actions, locations, datatypes, privileges or identifier is not of the type RFC 9635 section 8 requires. HTTP 400 GNAP invalid_request
STS-GNAP-0024 A requested GNAP access token (an access_token element) is not an object. HTTP 400 GNAP invalid_request
STS-GNAP-0025 A requested GNAP access token carries a label that is not a non-empty string. HTTP 400 GNAP invalid_request
STS-GNAP-0026 A request for multiple GNAP access tokens leaves one without a label (RFC 9635 section 2.1.2). HTTP 400 GNAP invalid_request
STS-GNAP-0027 A requested GNAP access token’s “flags” member is not an array of strings. HTTP 400 GNAP invalid_flag
STS-GNAP-0028 A requested GNAP access token names the same flag more than once. HTTP 400 GNAP invalid_flag
STS-GNAP-0029 A GNAP client requested a response-only flag (durable). HTTP 400 GNAP invalid_flag
STS-GNAP-0030 A GNAP client requested a flag this authorization server does not understand. HTTP 400 GNAP invalid_flag
STS-GNAP-0031 A GNAP grant request’s “access_token” member is an empty array. HTTP 400 GNAP invalid_request
STS-GNAP-0032 Two access tokens in one GNAP grant request share a label. HTTP 400 GNAP invalid_request
STS-GNAP-0033 A GNAP subject identifier is not an object with a “format”. HTTP 400 GNAP invalid_request
STS-GNAP-0034 A GNAP subject identifier uses a format that is not in RFC 9493. HTTP 400 GNAP invalid_request
STS-GNAP-0035 A GNAP “aliases” subject identifier contains another “aliases” identifier. HTTP 400 GNAP invalid_request
STS-GNAP-0036 A GNAP subject identifier lacks a member its format requires or carries a malformed one (aliases with no identifiers, an account URI without acct:, a phone number not in E.164). HTTP 400 GNAP invalid_request
STS-GNAP-0037 A GNAP “sub_ids” member is not an array of subject identifiers. HTTP 400 GNAP invalid_request
STS-GNAP-0038 A GNAP “subject” request member, or its sub_id_formats or assertion_formats, is malformed. HTTP 400 GNAP invalid_request
STS-GNAP-0039 A GNAP grant request’s “client” member is absent, empty, or neither an object nor an instance identifier. HTTP 401 GNAP invalid_client
STS-GNAP-0040 A GNAP grant request’s “client” object carries no key. HTTP 401 GNAP invalid_client
STS-GNAP-0041 A GNAP client’s class_id or display member (name, uri, logo_uri) is malformed, or a display URI is not absolute. HTTP 400 GNAP invalid_request
STS-GNAP-0042 A GNAP grant request’s “user” member is an empty reference, or neither a string nor an object. HTTP 403 GNAP unknown_user (400 invalid_request when it is neither a string nor an object)
STS-GNAP-0043 A GNAP “user.assertions” member is not an array of objects with string “format” and “value”. HTTP 400 GNAP invalid_request
STS-GNAP-0044 A GNAP “interact” member is not an object. HTTP 400 GNAP invalid_request
STS-GNAP-0045 A GNAP “interact.start” member is absent or not an array. HTTP 400 GNAP invalid_request
STS-GNAP-0046 A GNAP interaction start mode has no name. HTTP 400 GNAP invalid_request
STS-GNAP-0047 A GNAP “interact.finish” member has no method. HTTP 400 GNAP invalid_request
STS-GNAP-0048 A GNAP interaction finish nonce is absent or not printable ASCII. HTTP 400 GNAP invalid_request
STS-GNAP-0049 A GNAP interaction finish URI (redirect or push) is not an absolute URI without a fragment. HTTP 400 GNAP invalid_request
STS-GNAP-0050 A GNAP interaction finish names a hash_method this authorization server cannot compute. HTTP 400 GNAP invalid_request
STS-GNAP-0051 A GNAP “interact.hints” member is malformed. HTTP 400 GNAP invalid_request
STS-GNAP-0052 A GNAP request document (a grant, continuation, modification, rotation, introspection or registration request) is not a JSON object. HTTP 400 GNAP invalid_request (invalid_rotation for a rotation)
STS-GNAP-0053 A GNAP request document exceeds the shared bounds on nesting depth, key count or member names (validation.checkDocument()). HTTP 400 GNAP invalid_request (invalid_rotation for a rotation)
STS-GNAP-0054 A new GNAP grant request carries “interact_ref”, which is only ever sent to a continuation URI. HTTP 400 GNAP invalid_request
STS-GNAP-0055 A GNAP grant request asks for neither an access token nor subject information. HTTP 400 GNAP invalid_request
STS-GNAP-0056 A GNAP grant request’s “existing_access_token” (RFC 9767 token derivation) is not a non-empty string. HTTP 400 GNAP invalid_request
STS-GNAP-0057 A GNAP continuation POST carries members other than “interact_ref”, which belong to a PATCH. HTTP 400 GNAP invalid_request
STS-GNAP-0058 A GNAP continuation’s “interact_ref” is not a string of unreserved characters. HTTP 400 GNAP invalid_interaction
STS-GNAP-0059 A GNAP grant modification (PATCH) includes “client” or “interact_ref”. HTTP 400 GNAP invalid_request
STS-GNAP-0060 A GNAP token rotation request carries content other than a single “key” member. HTTP 400 GNAP invalid_rotation
STS-GNAP-0061 A GNAP request document does not match its JSON schema (gnap_schemas.js: types, lengths, caps, URI formats, control characters). HTTP 400 GNAP invalid_request (invalid_rotation for a rotation)
STS-GNAP-0070 A GNAP user reference is not one this authorization server issued. HTTP 403 GNAP unknown_user
STS-GNAP-0071 None of the user assertions in a GNAP grant request is one this authorization server issued and can verify. HTTP 403 GNAP unknown_user
STS-GNAP-0072 The user identifiers and assertions in a GNAP grant request name more than one person. HTTP 400 GNAP invalid_request
STS-GNAP-0080 A GNAP client instance or resource server presented an instance identifier this authorization server does not know. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0081 A GNAP instance identifier resolves to an application entry with no key registered to verify its requests. HTTP 401 GNAP invalid_client
STS-GNAP-0082 In product mode, a GNAP client instance or resource server proved a key no application entry registers (development mode would have created one). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0083 The application entry for a GNAP key seen for the first time (development mode) could not be created. HTTP 401 GNAP invalid_client
STS-GNAP-0090 The issuance policy refused one GNAP access token for a grant; the token was left out of the response (RFC 9635 section 3.2.2). —
STS-GNAP-0091 No enabled access token format satisfies every resource set a requested GNAP token names; the token was left out of the response. —
STS-GNAP-0092 A GNAP access token could not be minted in its chosen format; the token was left out of the response. —
STS-GNAP-0100 None of the interaction start modes a GNAP client offered is supported for it, and no push finish can reach the resource owner another way. HTTP 400 GNAP invalid_interaction
STS-GNAP-0101 In product mode, a GNAP interaction finish URI is not registered for the client instance (gnapFinishUri). HTTP 400 GNAP invalid_interaction
STS-GNAP-0102 A GNAP push finish URI is not one this service will dial (not an absolute http(s) URL, plain http with gnap.pushAllowHttp off, or a host outside gnap.pushAllowedHosts). HTTP 400 GNAP invalid_interaction
STS-GNAP-0103 In product mode, a GNAP finish URI uses plain http to a host other than localhost — refused at grant time, and a push finish refused at push time for the same reason (#171). HTTP 400 GNAP invalid_interaction
STS-GNAP-0110 A GNAP client proved its key with a proofing method this authorization server’s key_proofs_supported does not list. HTTP 401 GNAP invalid_client
STS-GNAP-0111 A GNAP client asked for a bearer token while bearer tokens are off (gnap.bearerTokens) or its entry forbids them (gnapBearerTokens). HTTP 400 GNAP invalid_flag
STS-GNAP-0112 A GNAP grant request or modification asks for an access right the client may not request (gnapAllowedAccess), or names an unregistered reference while gnap.unknownAccessReferences is refuse. HTTP 403 GNAP request_denied
STS-GNAP-0113 A GNAP grant needs the resource owner’s approval and the client offered no way to interact; the grant was finalized. HTTP 400 GNAP invalid_interaction
STS-GNAP-0120 A resource owner did not approve a GNAP grant — recorded when they answer, and again when the client continues and is told. HTTP 403 GNAP user_denied, at the next continuation
STS-GNAP-0121 The person who approved a GNAP grant is not the user the request named, and approval by an absent owner (gnap.ownerApproval) is off. HTTP 403 GNAP unknown_user, at the next continuation
STS-GNAP-0130 A GNAP continuation URI and access token do not together identify an active grant request. HTTP 401 GNAP invalid_continuation
STS-GNAP-0131 A GNAP continuation named a grant request that is finalized. HTTP 400 GNAP invalid_continuation
STS-GNAP-0132 A pending GNAP grant request expired before it was approved; the continuation finalized it. HTTP 400 GNAP invalid_continuation
STS-GNAP-0133 A GNAP client continued before the wait period ended. HTTP 400 GNAP too_fast, with a new continue member
STS-GNAP-0134 A GNAP interaction reference was presented for a grant request that is not pending; the grant was finalized (RFC 9635 section 5.1). HTTP 400 GNAP too_many_attempts
STS-GNAP-0135 A GNAP continuation presented an interaction reference that is not the one issued for the grant request. HTTP 400 GNAP invalid_interaction, with a new continue member
STS-GNAP-0136 A GNAP client polled more than gnap.maxPolls times before the resource owner decided; the grant was finalized. HTTP 400 GNAP too_many_attempts
STS-GNAP-0137 A GNAP client polled a grant whose finish method delivers an interaction reference, instead of presenting that reference (RFC 9635 section 3.3.5). HTTP 400 GNAP invalid_continuation, with a new continue member
STS-GNAP-0140 A GNAP grant modification (PATCH) named a grant request that is neither pending nor approved. HTTP 400 GNAP invalid_continuation
STS-GNAP-0141 A GNAP grant modification asks for more than was approved and offers no way to interact with the resource owner. HTTP 403 GNAP request_denied, with a new continue member
STS-GNAP-0150 A GNAP token management URI and access token do not identify a token. HTTP 401 GNAP invalid_rotation (invalid_request for a DELETE)
STS-GNAP-0151 A GNAP token rotation asked for a new key while key rotation is off (gnap.keyRotation, or the authorization server’s key_rotation_supported). HTTP 400 GNAP key_rotation_not_supported
STS-GNAP-0152 A GNAP key rotation was asked for a bearer token, which has no key to rotate. HTTP 400 GNAP invalid_rotation
STS-GNAP-0153 A revoked GNAP access token was presented for rotation. HTTP 400 GNAP invalid_rotation
STS-GNAP-0154 A GNAP access token whose grant is finalized was presented for rotation. HTTP 400 GNAP invalid_rotation
STS-GNAP-0155 A rotated GNAP access token could not be minted. HTTP 400 GNAP invalid_rotation
STS-GNAP-0160 A GNAP endpoint threw an unexpected error. HTTP 500 GNAP request_denied
STS-GNAP-0161 A GNAP endpoint was reached while GNAP is turned off in this trust realm (gnap.enabled). HTTP 404 GNAP request_denied
STS-GNAP-0162 The authorization server segment of a /:as/gnap path is not a valid identifier. HTTP 400 GNAP invalid_request
STS-GNAP-0163 The GNAP grant endpoint refused a request whose refusal carried no more specific code. HTTP 400 GNAP, with the refusal’s own error code
STS-GNAP-0164 A GNAP continuation URI does not name a grant request in the shape this authorization server issues. HTTP 401 GNAP invalid_continuation
STS-GNAP-0165 The GNAP continuation endpoint refused a request whose refusal carried no more specific code. HTTP 400 GNAP, with the refusal’s own error code
STS-GNAP-0166 A GNAP token management URI does not name a token in the shape this authorization server issues. HTTP 401 GNAP invalid_rotation (invalid_request for a DELETE)
STS-GNAP-0167 The GNAP token management endpoint refused a request whose refusal carried no more specific code. HTTP 400 GNAP, with the refusal’s own error code
STS-GNAP-0168 The GNAP introspection endpoint refused a request whose refusal carried no more specific code. HTTP 400 GNAP, with the refusal’s own error code
STS-GNAP-0169 The GNAP resource registration endpoint refused a request whose refusal carried no more specific code. HTTP 400 GNAP, with the refusal’s own error code
STS-GNAP-0200 A Content-Digest algorithm this service was asked to compute or accept is not sha-256 or sha-512 (for example a key’s content-digest-alg). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0201 A GNAP request with content carries no Content-Digest field. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0202 A Content-Digest field is not a Structured Field Dictionary. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0203 A Content-Digest member is not a Byte Sequence. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0204 A Content-Digest does not match the request content. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0205 A Content-Digest field carries no digest in an accepted algorithm. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0206 An HTTP message signature’s covered component identifier is malformed, or the covered components are not an Inner List. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0207 A covered component carries a parameter that is not understood or is of the wrong type. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0208 A covered component carries ;req, which a request verifier has no related request to resolve. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0209 An HTTP message signature covers a derived component this verifier does not understand. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0210 An HTTP message signature covers @status (or another response-only component) on a request, or a response status is malformed. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0211 A request has no method or no absolute target URI to derive a covered component from. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0212 A covered @query-param has no name parameter, or names a parameter the target URI does not have. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0213 A covered @query-param names a parameter that occurs more than once. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0214 A covered component carries ;tr, and trailers are not part of the message this verifier is given. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0215 A covered component combines ;bs with ;sf or ;key. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0216 A covered HTTP field is not present in the message. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0217 A covered component asks for ;sf or ;key on a field whose Structured Field type is unknown or is not a Dictionary. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0218 A covered ;key names a Dictionary member the field does not have. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0219 A covered field does not parse as its Structured Field type. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0220 An HTTP message signature lists @signature-params among its covered components. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0221 A covered component’s value contains a newline or a character outside ASCII. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0222 A signature parameter is of the wrong type or is a negative timestamp, or the signature parameters cannot be serialized. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0223 An HTTP message signature covers the same component more than once. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0224 The key for a signature algorithm is the wrong kind or too weak (a shared secret shorter than its hash, an asymmetric key of the wrong type, an RSA key under 2048 bits). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0225 A signature label handed to the HTTP message signer is not a valid Dictionary key. —
STS-GNAP-0226 No signature algorithm could be determined: neither the key nor an alg parameter names one. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0227 A signature algorithm, or a signature’s alg parameter, is not one this verifier supports. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0228 A JWS algorithm was signalled with the alg parameter, or an alg parameter disagrees with the key’s algorithm. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0229 Signing or verifying an HTTP message signature failed inside the cryptographic library. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0230 An HTTP message signature could not be appended to a message: it is not a successful sign() result, or its label is already used. —
STS-GNAP-0231 A Signature or Signature-Input field is not a Structured Field Dictionary. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0232 A Signature or Signature-Input field uses one label more than once. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0233 A GNAP request proved by httpsig carries no HTTP message signature (no Signature-Input and no Signature field). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0234 A signature label is present in only one of the Signature and Signature-Input fields. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0235 A Signature-Input member is not an Inner List of string component identifiers, or a Signature member is not a Byte Sequence. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0236 The message carries no HTTP message signature with the label the verifier asked for. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0237 No HTTP message signature carries the required tag (tag=”gnap”). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0238 An HTTP message signature carries the alg parameter, which RFC 9635 section 7.3.1 forbids. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0239 An HTTP message signature has no created parameter. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0240 An HTTP message signature is older than the allowed age (gnap.signatureMaxAgeS). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0241 An HTTP message signature claims a created time further in the future than the allowed clock skew. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0242 An HTTP message signature has passed its expires parameter. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0243 An HTTP message signature does not cover a required component (@method, @target-uri, content-digest, authorization). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0244 No verification key is known for an HTTP message signature (its tag or keyid does not name the presented key). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0245 An HTTP message signature uses an algorithm the verifier does not allow. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0246 An HTTP message signature does not verify over the signature base rebuilt from the message. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0260 A GNAP request’s content is a JWS whose payload is not a JSON object. HTTP 400 GNAP invalid_request
STS-GNAP-0261 A GNAP request’s content is not JSON. HTTP 400 GNAP invalid_request
STS-GNAP-0262 A GNAP JWS key proof is not a compact JWS, or its JOSE header is not JSON. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0263 A GNAP JWS key proof’s typ is not the one its proofing method requires. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0264 A GNAP JWS key proof’s alg is not the key’s own, or is “none”. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0265 A GNAP JWS key proof’s kid does not name the presented JWK. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0266 A GNAP JWS key proof’s htm is not the request method. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0267 A GNAP JWS key proof’s uri is not the URI the request was sent to. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0268 A GNAP JWS key proof’s created time is missing or outside the allowed age. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0269 A GNAP JWS key proof does not carry the hash of the presented access token in “ath”. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0270 A GNAP JWS key proof’s signature does not verify against the presented key. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0271 A GNAP JWS key proof has already been used. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0272 A GNAP detached JWS proof for a request with no content is not signed over an empty payload. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0273 A GNAP detached JWS proof does not carry the SHA-256 digest of the request content. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0274 A GNAP request’s Content-Digest was refused and the digest check named no more specific code. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0275 A GNAP HTTP message signature did not verify and the verifier named no more specific code. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0276 A GNAP HTTP message signature’s nonce has already been used. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0277 A GNAP key proved by mutual TLS was presented on a connection with no client certificate. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0278 The TLS client certificate is not the certificate the GNAP key names, or does not carry the presented key. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0279 A GNAP request had no usable key to verify it with. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0280 A cert#S256 GNAP key, which carries no public key, was used with a signature proofing method rather than mutual TLS. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0281 A GNAP key rotation changes the proofing method or its parameters. HTTP 401 GNAP invalid_rotation
STS-GNAP-0282 A GNAP key rotation was attempted for a key proved by mutual TLS, for which rotation is not defined. HTTP 400 GNAP key_rotation_not_supported
STS-GNAP-0283 A GNAP key names a proofing method that has no verifier implemented. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0284 A GNAP request that must carry a Detached-JWS header (a detached JWS proof, a content-less jws request, or a detached JWS key rotation) has none. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0285 A GNAP request proved by an attached JWS (or an attached-JWS key rotation) does not send a JWS as its content. HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0286 In a GNAP httpsig key rotation, the new key’s signature does not cover the old key’s Signature and Signature-Input. HTTP 401 GNAP invalid_rotation
STS-GNAP-0287 Under the PKI trust model (gnap.mtlsTrust or the entry’s gnapMtlsTrust is pki), the TLS client certificate proving a GNAP key did not verify: no chain to the client truststore, or a certificate this service issued that is not a TLS client identity in this realm (#107). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0288 Under the PKI trust model, a GNAP client’s TLS client certificate verified but was not issued to its application entry by this realm, and the entry registers no RFC 8705 certificate subject to bind it by (or no entry holds the key at all) (#107). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0289 Under the PKI trust model, a GNAP client’s application entry registers more than one RFC 8705 certificate subject parameter, so there is no single subject to bind the certificate by (#107). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0290 Under the PKI trust model, a GNAP client’s TLS client certificate does not carry the RFC 8705 certificate subject its application entry registers (#107). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0291 Under the PKI trust model, a GNAP client presented a TLS client certificate this realm issued to a different person or application (#107). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0292 Under the PKI trust model, a GNAP client presented a TLS client certificate this realm issued to its entry that the entry’s record no longer lists (#107). HTTP 401 GNAP invalid_client (400 invalid_resource_server at the RS-facing endpoints)
STS-GNAP-0300 A GNAP token model’s access is not a non-empty array of access rights. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0301 A GNAP token model’s access element is an empty reference, or neither a reference string nor a typed object. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0302 A GNAP token model’s access element has an array dimension or an identifier of the wrong type. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0303 A GNAP token model is not valid under RFC 9767 section 2.1 (a missing or malformed member, or a bearer flag and cnf that disagree), when minted or read back. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0304 A presented GNAP access token has expired. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0305 A presented GNAP access token is not yet valid (nbf). HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0306 A presented GNAP access token is not intended for the audience it was presented to. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0307 A key-bound GNAP access token was presented without that key. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0308 A presented GNAP access token does not grant the access the request needs, possibly because an attenuation narrowed it. HTTP 403 insufficient_scope at a resource server (WWW-Authenticate: GNAP)
STS-GNAP-0310 A GNAP macaroon could not be minted or checked: the model does not round-trip as caveats, the root key is too short, or the macaroon library refused. —
STS-GNAP-0311 A presented macaroon is not unpadded base64url, or not a libmacaroons v2 binary macaroon. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0312 A presented macaroon’s identifier is not this service’s GNAP prefix and a jti, so this service did not mint it. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0313 A presented macaroon carries a third-party caveat, which needs a discharge macaroon this format does not carry. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0314 A presented macaroon’s HMAC chain does not verify under the resource server’s root key. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0315 A presented macaroon carries a caveat outside this service’s caveat grammar. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0316 A presented macaroon’s authority section is malformed: a caveat out of place or repeated, a required one missing, or not a valid token model. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0317 A macaroon attenuation was refused: empty, outside the exp/nbf/aud/access grammar, or refused by the library. —
STS-GNAP-0320 A biscuit could not be minted or verified with the keys given (not Ed25519), or the biscuit library refused to mint or emitted a value that is not token68. —
STS-GNAP-0321 The biscuit WASM library could not be loaded. HTTP 401 invalid_token at a resource server; at issuance the token is left out
STS-GNAP-0322 A presented biscuit is not URL-safe base64, does not parse, or its signature chain does not verify under this authorization server’s public key. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0323 A presented biscuit’s authority block is not a GNAP token model (misnumbered or non-JSON access facts, a singular fact repeated, or not exactly one key binding). HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0324 A biscuit authorization check failed, or the authorizer could not be built for the presentation. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0325 Biscuit authorization exceeded its run limits (facts, iterations or time), which is a refusal and never a pass. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0326 A biscuit attenuation block was refused: empty, a parameter of an unsupported type, or rejected by the library. —
STS-GNAP-0330 ZCAP keys are unusable (no absolute controller URL, a keyId not under it, not a key of the kind gnap.zcapCryptosuite signs with, or a suite that is none of the four), or a capability’s invocationTarget is not an absolute URI. —
STS-GNAP-0331 The ZCAP libraries could not be loaded. HTTP 401 invalid_token at a resource server; at issuance the token is left out
STS-GNAP-0332 A presented ZCAP is not base64url JSON with exactly the members and @context this format writes. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0333 A presented ZCAP’s delegation proof does not verify under this authorization server’s key. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0334 A presented ZCAP’s GNAP terms are inconsistent, or it names no invocationTarget. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0335 The ZCAP libraries refused to sign a capability. —
STS-GNAP-0336 A presented ZCAP carries a proof of a suite other than the one this realm’s gnap.zcapCryptosuite names, or not exactly one proof. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0340 A presented jwt-encrypted GNAP access token is encrypted to a resource server’s key, which this authorization server does not hold. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0341 A presented jwt-encrypted GNAP access token does not decrypt. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0342 A presented JWT GNAP access token’s signature does not verify. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0343 A presented JWT is not a GNAP access token (its typ is wrong). HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0344 A GNAP token names an access token format that does not exist. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0400 A GNAP interaction start link (redirect or app) names no request still waiting for approval. HTTP 400 page
STS-GNAP-0401 A GNAP interaction start link had already been used. HTTP 400 page
STS-GNAP-0402 The GNAP user code page was opened while GNAP is turned off (gnap.enabled). HTTP 400 page
STS-GNAP-0403 A GNAP user code form post was malformed. HTTP 400 page
STS-GNAP-0404 Too many GNAP user codes were tried from one address. HTTP 429 page
STS-GNAP-0405 A GNAP user code is not recognised, or has expired. HTTP 400 page
STS-GNAP-0406 A GNAP approval page or answer names no request waiting for the person, or one whose interaction was never started. HTTP 400 page
STS-GNAP-0407 A GNAP approval answer failed its anti-forgery check. HTTP 400 page
STS-GNAP-0408 A GNAP approval answer was malformed. HTTP 400 page
STS-GNAP-0409 A GNAP approval could not be completed because of an unexpected error. HTTP 400 page
STS-GNAP-0500 A GNAP RS-facing request’s “resource_server” member is absent, or has neither a key nor an instance identifier. HTTP 400 GNAP invalid_resource_server
STS-GNAP-0501 A GNAP introspection request has no “access_token”, or its “proof” is not a method name. HTTP 400 GNAP invalid_request
STS-GNAP-0502 A GNAP resource registration request is malformed (no access rights, token_formats_supported not strings, token_introspection_required not a boolean). HTTP 400 GNAP invalid_request
STS-GNAP-0510 A resource server asked for a derived token while token derivation is off (gnap.tokenDerivation). HTTP 403 GNAP request_denied
STS-GNAP-0511 A GNAP token derivation names an existing access token that is not active. HTTP 400 GNAP invalid_request
STS-GNAP-0512 A GNAP token derivation names an existing access token that was not issued for the requesting resource server. HTTP 403 GNAP request_denied
STS-GNAP-0513 A GNAP derived token asks for more access than the token it is derived from: a derived token is a subset of the original (#432). HTTP 403 GNAP request_denied
STS-GNAP-0520 GNAP token introspection was asked for while it is off (gnap.introspection). HTTP 404 GNAP invalid_request
STS-GNAP-0530 GNAP resource registration was asked for while it is off (gnap.resourceRegistration). HTTP 404 GNAP invalid_request
STS-GNAP-0531 A GNAP resource registration names only token formats this authorization server does not issue. HTTP 400 GNAP invalid_request
STS-GNAP-0532 A GNAP resource registration requires introspection while introspection is off. HTTP 400 GNAP invalid_request
STS-GNAP-0533 A resource server tried to register access it may not (gnapAllowedAccess). HTTP 400 GNAP invalid_access
STS-GNAP-0540 No GNAP access token was presented to a resource server (no Authorization header in the GNAP or Bearer scheme). HTTP 401 invalid_token (WWW-Authenticate: GNAP)
STS-GNAP-0541 A GNAP access token presented to a resource server is unknown, revoked or expired, or its grant is finalized. HTTP 401 invalid_token (WWW-Authenticate: GNAP) at a resource server; HTTP 401 with WWW-Authenticate at the SSF transmitter
STS-GNAP-0542 A bearer GNAP access token was presented under the GNAP scheme rather than Bearer. HTTP 401 invalid_request (WWW-Authenticate: GNAP) at a resource server; HTTP 401 with WWW-Authenticate at the SSF transmitter
STS-GNAP-0543 A key-bound GNAP access token was presented under the Bearer scheme rather than GNAP with a key proof. HTTP 401 invalid_request (WWW-Authenticate: GNAP) at a resource server; HTTP 401 with WWW-Authenticate at the SSF transmitter
STS-GNAP-0544 The key of a presented key-bound GNAP access token, or the request content, could not be read. HTTP 401 invalid_request (WWW-Authenticate: GNAP) at a resource server; HTTP 401 with WWW-Authenticate at the SSF transmitter
STS-GNAP-0545 The key proof with a presented GNAP access token did not verify and the verifier named no more specific code. HTTP 401 invalid_token (WWW-Authenticate: GNAP) at a resource server; HTTP 401 with WWW-Authenticate at the SSF transmitter
STS-GNAP-0546 A presented GNAP access token failed its format’s verification and the format named no more specific code. HTTP 401 invalid_token or 403 insufficient_scope at the demonstration resource server (WWW-Authenticate: GNAP)
STS-GNAP-0550 The GNAP demonstration resource server was reached while it is turned off (gnap.demoResourceServer). HTTP 404 GNAP invalid_request
STS-GNAP-0551 The GNAP demonstration resource server was called with no access token; it answered with the RS-first challenge of RFC 9635 section 9.1. HTTP 401 invalid_token with WWW-Authenticate: GNAP as_uri, access, referrer
STS-GNAP-0552 The GNAP demonstration resource server refused a presented token whose refusal carried no more specific code. HTTP 401 invalid_token (WWW-Authenticate: GNAP)
STS-GNAP-0553 A GNAP access token presented at the demonstration resource server does not grant the action (read or write) on its resource type. HTTP 403 insufficient_scope (WWW-Authenticate: GNAP)
STS-GNAP-0600 A GNAP push interaction finish was not sent because gnap.pushFinish is off; the client learns the outcome when it continues. —
STS-GNAP-0601 A GNAP push interaction finish URI is not one this service will dial; nothing was sent. —
STS-GNAP-0602 A client answered a GNAP push interaction finish with a redirect, which is not followed. —
STS-GNAP-0603 A client answered a GNAP push interaction finish with a status other than 2xx. —
STS-GNAP-0604 A GNAP push interaction finish could not be started or delivered, or its response could not be read. —
STS-GNAP-0605 A GNAP push interaction finish timed out. —
STS-GNAP-0650 A GNAP monitor event is not in gnap_monitor.js’s vocabulary and was not counted — a programming error. —
STS-GNAP-0651 A GNAP monitor counter threw and was ignored; the grant itself was unaffected. —
STS-GNAP-0652 An application entry carries a gnapKey that is not a JSON key object; it identifies nobody. —
STS-GNAP-0653 A GNAP shared key on an application entry could not be opened with this process’s key-encryption key, so the key reference was not resolved. —
STS-GNAP-0654 A resource server’s entry carries a gnapJweKey that is not JSON; jwt-encrypted tokens for it are encrypted to this authorization server instead. —
STS-GNAP-0655 The macaroon root key could not be written onto a resource server’s application entry. —
STS-GNAP-0660 A GNAP console or management API revoke-grant names a grant that is not in this realm. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-GNAP-0661 A GNAP console or management API delete-resource-set names a resource set not registered in this realm. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-GNAP-0662 A GNAP console or management API action is not one of revoke-grant and delete-resource-set. Console error notice; HTTP 400 {ok: false, errors} from /admin-api
STS-GNAP-0663 The query string of a GNAP console page failed validation. HTTP 400 text/plain
STS-GNAP-0664 A GNAP console action form post failed validation. Console error notice
STS-GNAP-0665 A GNAP management API action was refused and the refusal carried no more specific code. HTTP 400 {ok: false, errors}
STS-GNAP-0700 The approver of a GNAP grant could not be recorded for the Shared Signals subject scope; the approval went ahead. —
STS-GNAP-0701 A CAEP event about a GNAP grant or token could not be delivered. —
STS-GNAP-0710 A continuation access token this process still held was already used by another process against the same store (the cluster claim, #46). invalid_continuation (HTTP 401)
STS-GNAP-0711 An interaction reference this process still held was already presented to another process against the same store (the cluster claim, #46). invalid_interaction (HTTP 400)
STS-GNAP-0712 An interaction start link (redirect or app) this process still held was already followed at another process against the same store (the cluster claim, #46). HTML page (HTTP 400)
STS-GNAP-0713 A user code this process still held was already entered at another process against the same store (the cluster claim, #46). HTML page (HTTP 400)
STS-GNAP-0714 A token management access token this process still held was already used by another process against the same store (the cluster claim, #46). invalid_rotation or invalid_request (HTTP 401)
STS-GNAP-0715 A key proof (an HTTP message signature nonce or a JWS) this process had not seen was already accepted by another process against the same store (the cluster claim, #46). invalid_client, invalid_resource_server or invalid_token (HTTP 401)
STS-GNAP-0716 The cluster claim store could not be asked about a GNAP single-use value, so the request was refused rather than accepted unproven. the refusal of the value it guarded
STS-GNAP-0717 A resource owner’s decision on a GNAP grant was refused because a decision on the same interaction had already been recorded, by another request or another node against the same store (the cluster claim, #46). RFC 9635 section 4 (an interaction is answered once)
STS-GNAP-0718 A signed GNAP request was refused because the realm’s signature replay history held gnap.replayCacheSize LIVE entries: forgetting one would let that signature be replayed, so the request is refused instead until entries age out. RFC 9635 section 7.3 (invalid_request)
STS-GNAP-0719 A GNAP client asked for an access right naming one of this service’s own protected scopes (ssf:read, ssf:write, as a reference string or an object of type ssf) that its application’s oauthAllowedScope does not list. RFC 9635 section 3.6 (request_denied)
STS-GNAP-0720 Product mode ignored gnap.pushSkipTlsVerification: a push finish verifies the client’s certificate whatever it says. Logged once per process (#171). none — a warning in the log
STS-GNAP-0730 A GNAP grant was refused at use — its continuation (other than the client revoking it), or introspected inactive — because its resource owner’s account is disabled. Covers a node the disable has not reached yet; the disable itself ends the grant (#432). RFC 9635 section 5 (invalid_continuation); RFC 9767 section 3.3 (active: false)
STS-GNAP-0731 A GNAP grant was refused at use — its continuation, or introspected inactive — because its client’s application entry no longer exists, or no longer names the key the grant is bound to (gnapKey, gnapKeyIdentity or gnapKeyReference removed or replaced, #432). RFC 9635 section 5 (invalid_continuation); RFC 9767 section 3.3 (active: false)
STS-GNAP-0732 A GNAP access token was not rotated because its resource owner’s account is disabled, or its client’s application entry is gone or no longer names the grant’s key (#432). Revoking it is still allowed. RFC 9635 section 6.1 (invalid_rotation)
STS-GNAP-0733 A resource server asked to derive from a GNAP access token whose resource owner’s account is disabled, or whose client’s application entry is gone or no longer names the grant’s key (#432). RFC 9767 section 4 (invalid_request)
STS-GNAP-0734 A GNAP access token was presented (the demonstration resource server, a Shared Signals endpoint) whose resource owner’s account is disabled (#432). RFC 9635 section 7.2 (invalid_token)
STS-GNAP-0735 A GNAP access token was presented whose client’s application entry no longer exists or no longer names the key the grant is bound to (#432). RFC 9635 section 7.2 (invalid_token)
STS-GNAP-0736 A GNAP grant could not be ended by an act from outside the protocol — a sign-out, a deleted client, a compromised device, a received signal (#432). The others it was asked to end were. none — a warning in the log
STS-GNAP-0737 An application entry was deleted, or its GNAP key removed or replaced, and its GNAP grants could not be ended with it (#432). Each is still refused at its next use (STS-GNAP-0731). none — a warning in the log
STS-GNAP-0750 The biscuit library gave no usable revocation identifiers for a token it had just minted, so the biscuit was not issued: one this authorization server could never publish as revoked would be accepted offline until it expired (#432). none — the token is not issued; the grant answers without it
STS-GNAP-0751 The revoked biscuits’ identifiers could not be listed at GET /gnap/biscuit/revocations (#432). HTTP 500
STS-GNAP-0752 The revoked-biscuit list reached oauth2.maxRevokedJtis with nothing expired in it, so its oldest unexpired revocations were forgotten: those biscuits are accepted again by a resource server that checks only the list, until they expire (#432). none — a warning in the log
STS-GNAP-0770 A GNAP client trusted to skip interaction (gnapSkipInteraction) presented a verified user assertion and the delegation policy refused it tokens for that person (#432, product mode): the relationship does not hold — the target is not the actor itself, not on the actor’s appAllowedToDelegateTo, and does not accept it (appAllowedToActOnBehalfOf), or no usable target was named. RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0771 A GNAP client trusted to skip interaction (gnapSkipInteraction) presented a verified user assertion and the delegation policy refused it tokens for that person (#432, product mode): the subject is protected (stsNotDelegated, appNotDelegated, delegation.protectedGroups, the console roster) or outside the actor’s appDelegationSubjectGroup. RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0772 A GNAP client trusted to skip interaction (gnapSkipInteraction) presented a verified user assertion and the delegation policy refused it tokens for that person (#432, product mode): the semantics are not allowed by the actor (appDelegationSemantics; empty is delegation only) or the subject (stsDelegationSemantics). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0773 A GNAP client trusted to skip interaction (gnapSkipInteraction) presented a verified user assertion and the delegation policy refused it tokens for that person (#432, product mode): the subject holds none of the roles the application the act stands on requires (appRequiredRole). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0774 A GNAP client trusted to skip interaction (gnapSkipInteraction) presented a verified user assertion and the delegation policy refused it tokens for that person (#432, every mode): the may_act the verified assertion carries names somebody other than the client. RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0775 A GNAP client trusted to skip interaction (gnapSkipInteraction) presented a verified user assertion and the delegation policy refused it tokens for that person (#432, product mode): a rule of the realm’s own issuance policy, or an actor this realm does not know. RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0776 A GNAP resource server asked to derive a token (RFC 9767 section 4) and the delegation policy refused it (#432, product mode): the relationship does not hold — the target is not the actor itself, not on the actor’s appAllowedToDelegateTo, and does not accept it (appAllowedToActOnBehalfOf), or no usable target was named. RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0777 A GNAP resource server asked to derive a token (RFC 9767 section 4) and the delegation policy refused it (#432, product mode): the subject is protected (stsNotDelegated, appNotDelegated, delegation.protectedGroups, the console roster) or outside the actor’s appDelegationSubjectGroup. RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0778 A GNAP resource server asked to derive a token (RFC 9767 section 4) and the delegation policy refused it (#432, product mode): the semantics are not allowed by the actor (appDelegationSemantics; empty is delegation only) or the subject (stsDelegationSemantics). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0779 A GNAP resource server asked to derive a token (RFC 9767 section 4) and the delegation policy refused it (#432, product mode): the subject holds none of the roles the application the act stands on requires (appRequiredRole). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0780 A GNAP derivation was refused because the original token’s may_act names somebody other than the deriving resource server (#432; refused in every mode). GNAP tokens carry no may_act today, so this is reached only through a realm’s own policy. RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0781 A GNAP resource server asked to derive a token (RFC 9767 section 4) and the delegation policy refused it (#432, product mode): a rule of the realm’s own issuance policy, or an actor this realm does not know. RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0782 A GNAP token derivation was refused because the derived token’s actor chain (act) would name more resource servers than gnap.maxDerivationDepth allows (#432, every mode). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0790 A GNAP continuation or modification arrived after the grant’s own lifetime (gnap.grantLifetimeS) ended; the grant was finalized as expired (#432). RFC 9635 section 5 (invalid_continuation)
STS-GNAP-0791 A GNAP access token rotation was refused because the grant the token was issued under has reached the end of its lifetime (gnap.grantLifetimeS) (#432). RFC 9635 section 6.1 (invalid_rotation)
STS-GNAP-0792 An administrator’s revoke-grant (console or /admin-api) named a person who is not the resource owner of the grant it named, so nothing was revoked (#432). HTTP 400 (API) or a 303 with error=
STS-GNAP-0793 A GNAP grant was to release subject information that neither an interaction nor a delegation decision authorized; none was released (#432). none — the subject member is omitted (RFC 9635 section 3.4)
STS-GNAP-0810 A GNAP access right was of a type the access-type catalogue does not declare (no resource application’s oauthAuthorizationDetailsType names it), and the issuance policy’s gnap-type-not-catalogued rule refuses one in product mode (#432). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0811 A GNAP bearer token was asked for carrying a right of a type the access-type catalogue declares bearer: false (#432). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0812 A GNAP access right did not meet its type’s catalogue definition: an action, datatype or privilege it does not allow, a required member missing, its JSON Schema, or a location its owning resource server does not answer to (#432). RFC 9635 section 3.6 (invalid_request, HTTP 400)
STS-GNAP-0813 A GNAP access right carried limits, and its type declares no limits schema in the access-type catalogue (#432). RFC 9635 section 3.6 (invalid_request, HTTP 400)
STS-GNAP-0814 A GNAP access right’s limits did not meet the limits schema its type declares (#432). RFC 9635 section 3.6 (invalid_request, HTTP 400)
STS-GNAP-0815 The issuance policy answered a GNAP access right with a verdict this service does not know; the right was refused (#432). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0816 No issuance policy, not even the built-in one, gave a verdict on a GNAP access right; it was refused (#432). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0817 The issuance policy narrowed a GNAP access right to nothing it could still grant: a reference string, an unrestricted dimension the catalogue lists no values for, every value taken off, or a narrowed right its type no longer accepts (#432). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0860 A GNAP access right’s limits are not ones this service can read: an amount, count, receiver, repeating interval or window that common/access_limits.ts gives no meaning (#432 phase 5). RFC 9635 section 3.6 (invalid_request, HTTP 400)
STS-GNAP-0861 A GNAP access right names an identifier whose owner (on a registered resource set, or by the resource server’s lookup) is not the person the grant is for, nor a group they are a member of; the issuance policy refused it (#432 phase 5). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0862 The person on the GNAP approval page does not own a resource a requested right names, and the issuance policy would not let them approve it; the page refused (#432 phase 5). RFC 9635 section 1.4 (the page answers 400)
STS-GNAP-0863 A GNAP access right names an identifier whose resource server declares an owner lookup that could not be answered; the issuance policy refused it (#432 phase 5). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0864 A resource registration’s resource_owners names an identifier no right in its access carries (#432 phase 5). RFC 9767 section 3.4 (invalid_request, HTTP 400)
STS-GNAP-0865 A resource registration’s resource_owners names a DN that is not a person or a group in the realm’s directory (#432 phase 5). RFC 9767 section 3.4 (invalid_request, HTTP 400)
STS-GNAP-0866 The GNAP approval page was sent limits that raise a right’s limits rather than lower them, or that cannot be read (#432 phase 5). RFC 9635 section 4 (the page answers 400)
STS-GNAP-0867 Limits lowered on the GNAP approval page no longer meet the limits schema of the right’s type (#432 phase 5). RFC 9635 section 4 (the page answers 400)
STS-GNAP-0868 A derived GNAP token would drop or raise a limit the original token’s right carries (#432 phase 5). RFC 9767 section 4 (request_denied, HTTP 403)
STS-GNAP-0869 A resource server’s owner lookup (gnapOwnerLookupUri) could not be answered: refused by the outbound policy, unreachable, or not {“owner”: “"} (#432 phase 5). —
STS-GNAP-0870 A demonstration spend would pass the limits of the token’s right for its grant and period (#432 phase 5). RFC 6750 section 3.1 (insufficient_scope, HTTP 403)
STS-GNAP-0871 A demonstration spend is outside the window or the repeating interval the token’s limits allow (#432 phase 5). RFC 6750 section 3.1 (insufficient_scope, HTTP 403)
STS-GNAP-0872 A demonstration spend names a receiver the token’s limits do not (#432 phase 5). RFC 6750 section 3.1 (insufficient_scope, HTTP 403)
STS-GNAP-0873 A demonstration spend states no amount, or one in another currency, where the token’s limits count an amount (#432 phase 5). RFC 6750 section 3.1 (insufficient_scope, HTTP 403)
STS-GNAP-0874 A demonstration spend’s body is not readable (#432 phase 5). RFC 6750 section 3.1 (invalid_request, HTTP 400)
STS-GNAP-0875 The running totals of a token’s limits could not be read from the store every node shares; the demonstration spend was refused (#432 phase 5). HTTP 503
STS-GNAP-0876 The demonstration operation failed after its spend was counted (asked to, with simulateFailure); the spend was refunded (#432 phase 5). HTTP 502
STS-GNAP-0877 A demonstration spend could not be refunded: a new period had begun, or the store could not be asked (#432 phase 5). —
STS-GNAP-0890 A GNAP access right whose type requires its resource owner on the approval page (interaction: always, or a consent action) was approved by skipping the page or by a remembered approval, and was left out of its token at issuance (#432 phase 6). audit only; the token is issued without the right
STS-GNAP-0891 A GNAP access right whose type requires an authentication level the approving session did not meet was left out of its token at issuance (#432 phase 6, RFC 9470). audit only; the token is issued without the right
STS-GNAP-0892 A client trusted to skip interaction (gnapSkipInteraction) asked for a right whose type requires its resource owner on the approval page, and offered no way to interact (#432 phase 6). RFC 9635 section 2.5 (invalid_interaction, HTTP 400)
STS-GNAP-0893 A GNAP request that could otherwise have been issued without interaction asked for a right needing an authentication level, which no session met, and offered no way to interact (#432 phase 6). RFC 9635 section 2.5 (invalid_interaction, HTTP 400)
STS-GNAP-0894 A GNAP grant waiting for its absent resource owner on the portal ran out (gnap.ownerApprovalLifetimeS) without an answer; it is finalized as rejected (#432 phase 6). RFC 9635 section 5 (invalid_continuation, HTTP 400)
STS-GNAP-0895 A derived GNAP token asked for a right beyond the original token of a type that requires its resource owner on the approval page (#432 phase 6). RFC 9767 section 4 (request_denied, HTTP 403)
STS-GNAP-0896 A derived GNAP token asked for a right needing an authentication level the session the original grant was approved on did not meet (#432 phase 6, RFC 9470). RFC 9767 section 4 (request_denied, HTTP 403)
STS-GNAP-0897 A GNAP grant could not wait for its resource owner: they already have gnap.ownerApprovalMaxPending requests waiting (#432 phase 6). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0898 A GNAP grant could not wait for its resource owner: they are homed in another cell than the one holding the client instance, whose portal could never list it (#432 phase 6, #98). RFC 9635 section 3.6 (request_denied, HTTP 403)
STS-GNAP-0899 The person at a GNAP approval page was sent to sign in again for the authentication level the rights need, and came back still short of it; the request is denied (#432 phase 6, RFC 9470). RFC 9635 section 3.6 (request_denied, HTTP 403), at the next continuation
STS-GNAP-0900 The mail notice for a GNAP grant waiting for its resource owner could not be queued; the grant waits on the portal regardless (#432 phase 6). log only
STS-GNAP-0901 A GNAP grant could not wait for its resource owner: the user the request names is not a person the directory holds (#432 phase 6). RFC 9635 section 2.4 (unknown_user, HTTP 400)

STS-DEVICE

Device register. The device register (#164, #218): a device’s owner, its keys, its attestation, compliance and status, the bounds on how many a person or an application holds, and the console’s and the management API’s doors to it.

Raised from: common/devices.ts, admin-ui/devices_admin.ts.

Code What failed Client sees
STS-DEVICE-0001 A device named an owner that is not a person or an application in the realm’s directory, named no owner, or an owner kind outside person and application (#164). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0002 A person already owns devices.maxPerPerson devices, so an administrator’s registration, or a move of a device to them, was refused (#164). A Native SSO sign-in replaces one instead. HTTP 400 (API) or a 303 with error=
STS-DEVICE-0003 An application already owns devices.maxPerApplication devices, so a registration or a move to it was refused (#164). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0004 A device key could not be accepted: an unknown kind, proof or attestation format, a certificate or JWK that could not be read, or a JWK carrying private material or a symmetric key (#164). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0005 A device key is already registered to another device in the realm, or one registration named the same key twice: a key identifies one device (#164). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0006 A device already holds devices.maxKeysPerDevice keys, or a registration named more (#164). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0007 A request named a device the realm does not hold, or — on /portal/devices and a person’s Remove — one that is not theirs (#164). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0008 A request named a key the device does not hold (#164). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0009 The directory did not store or remove a device entry — typically because it holds its maximum of entries (#164). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0010 A device’s label, model or operating system was too long or not one line, its platform was not one of the closed list, or an enrolment method was unknown (#164). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0011 A compliance status, its source or a device status was outside its closed list (#164). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0012 A device named an application that is not in the realm’s directory (#164). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0013 A POST to /admin/devices or /admin-api/devices named an action that does not exist (#218). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0014 A console session with Admin Read only posted to /admin/devices (#218). HTTP 303 with error=
STS-DEVICE-0015 A WebAuthn key named for a device is not a security key its owner enrolled, or the device’s owner is an application (#164). HTTP 400 (API) or a 303 with error=
STS-DEVICE-0016 A device enrolment challenge was refused: none was named, it is unknown or expired, it was issued to another session or person, or it was already answered (#164 phase 2). HTTP 400 (JSON) or the page with the sentence
STS-DEVICE-0017 A device key proof (a JWS over an enrolment challenge) is malformed, is signed with an algorithm not accepted, does not verify under the key in its own header, or carries the wrong typ, nonce, aud or iat (#164 phase 2). HTTP 400 (JSON) or the page with the sentence
STS-DEVICE-0018 An Android Key Attestation on a device key proof did not verify: the x5c chain, the leaf’s key, the key attestation extension, the attestationChallenge or the security level (#164 phase 2). HTTP 400 (JSON) or the page with the sentence
STS-DEVICE-0019 An Apple App Attest attestation object did not verify: its CBOR, the certificate chain to the App Attestation root, the nonce, the key id, the app id, the counter or the AAGUID (#164 phase 2). HTTP 400 (JSON) or the page with the sentence
STS-DEVICE-0020 A TPM key attestation in a certificate request (draft-ietf-lamps-csr-attestation, tcg-attest-tpm-certify) did not verify: the AK chain, the TPMS_ATTEST, its signature, or the certified key’s name and attributes (#164 phase 2). EST 400 / SCEP failInfo badRequest
STS-DEVICE-0021 A certificate request’s id-aa-attestation attribute is malformed, or there is more than one (draft-ietf-lamps-csr-attestation section 4.3) (#164 phase 2). EST 400 / SCEP failInfo badRequest
STS-DEVICE-0022 A WebAuthn credential could not be linked to a device: it is not one the signed-in person enrolled, or the fresh assertion with it did not verify (#164 phase 2). HTTP 400 (the page with the sentence)
STS-DEVICE-0023 A device certificate (the device profile over EST or SCEP) was refused by the identity rule: the device named is unknown, or it is not the requester’s and the requester holds no Admin Write (#164 phase 2, rule 3ag). EST 403 / SCEP failInfo badRequest
STS-DEVICE-0024 Product mode refused a device key presented without a verifiable attestation (common/mode.js acceptsUnattestedDeviceKeys()) (#164 decision 9). HTTP 400 (JSON or page) / EST 403 / SCEP failInfo badRequest
STS-DEVICE-0025 The device profile was asked for where it is not issued: over ACME, or as a re-enrollment of a certificate (a device is re-enrolled with simpleenroll naming its urn:sts:device: name) (#164 phase 2). HTTP 403 / EST 403 / SCEP failInfo badRequest
STS-DEVICE-0026 A POST to /portal/devices or /portal/devices/proof was malformed (#164 phase 2). HTTP 400
STS-DEVICE-0027 A shipped device attestation trust anchor (common/pki_device_anchors.json) did not match its pinned SHA-256 and was not used (#164 phase 2). none — logged; the anchor set is smaller
STS-DEVICE-0028 A device enrolment challenge could not be proved unspent because the claim store could not be asked, so it was refused (#164 phase 2). HTTP 503 (JSON) or the page with the sentence
STS-DEVICE-0029 Recognising the registered device behind a sign-in or a token request threw; nothing was recorded and nothing refused (#164 phase 2). none — logged
STS-DEVICE-0030 A Shared Signals event about a device (a compliance, risk or credential change, a compromise or a removal) threw on its way to ssf/account_signals.ts; the change stands and nothing was sent (#164 phase 4). none — logged
STS-DEVICE-0031 The sign-on sessions a compromised or removed device authenticated could not all be ended (#164 phase 4). none — logged; the device’s change stands
STS-DEVICE-0032 A certificate this service issued a compromised or removed device could not be revoked by its Issuing CA (#164 phase 4). none — logged and audited; the device’s change stands
STS-DEVICE-0033 A device risk level outside LOW, MEDIUM and HIGH (CAEP section 3.8.1), or a source outside risk, compromise and admin, was refused (#164 phase 4). none — the caller’s refusal
STS-DEVICE-0034 A device compliance feed request carried no report or more than devices.complianceFeedMaxReports, and was refused whole (#164 phase 3). HTTP 400
STS-DEVICE-0035 The compliance test control, POST /devices/test/compliance, was refused because the realm is in product mode, where test controls are closed (#164 phase 3). HTTP 403
STS-DEVICE-0036 Risk scoring could not set the risk level of the registered device that proved a sign-in: the device register refused or did not store it (#164 phase 5). The sign-in stands and the device keeps the level it had. none — logged as a warning
STS-DEVICE-0037 An issuance was refused by the issuance policy’s device-required rule: the realm requires a compliant registered device (devices.requireCompliantDevice) and this did not come from the subject’s own (or an application’s) compliant, uncompromised device — attested too where devices.compliantDeviceAttested says so (#164 phase 6). the issuance site’s own refusal — access_denied, a SOAP fault, a SAML status — whose description says a compliant registered device is required
STS-DEVICE-0038 An issuance was refused by the issuance policy’s device-compromised rule: it came from a registered device marked compromised, and the realm refuses one (devices.refuseCompromised, on by default) (#164 phase 6). the issuance site’s own refusal, saying only that authentication failed
STS-DEVICE-0039 A compliance status of compliant was refused for a device known only by a remembered browser’s cookie (attestation bearer): it holds no key an MDM could have inventoried, so nothing can say it is the device an MDM checked (#265). 400 on /admin-api/devices/set-compliance, a refused report in the MDM feed’s results
STS-DEVICE-0040 A remembered browser’s cookie could not be read: not a JWE this realm encrypted, a signature that does not verify against the realm’s browser device keys, expired, or claims that are not a device token. The cookie is cleared and the browser is treated as unrecognised (#265). none — the sign-in goes on without a remembered device
STS-DEVICE-0041 A remembered browser’s cookie carried an OLDER generation than the device holds, outside devices.browserReissueGraceSeconds: the cookie was copied. The device is marked compromised, which ends every session it holds, and risk scoring sees browser-token-replayed (#265). none — the sign-in goes on, at HIGH risk, without the device
STS-DEVICE-0042 A remembered browser’s cookie names a device that belongs to somebody other than the person signing in; it is not their device, and risk scoring sees browser-token-foreign (#265). none
STS-DEVICE-0043 A remembered browser’s token was not issued: once signed and encrypted it is larger than a cookie may be (about 4 KB) — devices.browserTokenCertificateHeader set to x5c or both is the usual cause (#265). none — the browser is not remembered, and the page says so
STS-DEVICE-0044 Remembering a browser was refused: devices.browserDevices is off in the realm, nobody is signed in, or the person holds their most devices (#265). 400 on /portal/devices; the sign-in itself goes on
STS-DEVICE-0045 A remembered browser’s generation and binding could not be written onto its device entry, so the token it holds was not issued again (#265). none — the browser keeps the token it has
STS-DEVICE-0046 A device was marked compromised and what its keys were trusted with beyond a session — the GNAP grants whose client key is the device’s, the OAuth tokens bound to its keys or certificates — could not all be ended (#432). The sessions, secret and certificates were. none — an error in the log

STS-XACML

XACML and access policy. The PDP, the policy repository, the embedded PEPs that decide this service’s own access and issuance, the PIP over HTTP, and the remote-PEP endpoints.

Raised from: xacml/, common/access_gate.ts, common/issuance_gate.js, common/roles.js.

Code What failed Client sees
STS-XACML-0001 A request reached an XACML endpoint while the family is switched off (xacml.enabled). HTTP 501 not_implemented
STS-XACML-0002 A request reached a remote-PEP endpoint or POST /xacml/pip while remote enforcement points are switched off (xacml.remotePeps). HTTP 501 not_implemented
STS-XACML-0003 The XACML surface (GET /xacml, /xacml/pdp, /xacml/policies, /xacml/protected) was refused to a caller that presented no client certificate. HTTP 403 access_denied
STS-XACML-0004 The XACML surface was refused to a caller whose client certificate did not verify against this service’s truststore. HTTP 403 access_denied
STS-XACML-0005 The XACML surface was refused to a verified certificate whose subject resolves to no directory entry holding XACML_USER (not in roles.xacmlUserGroup). HTTP 403 access_denied
STS-XACML-0006 The XACML surface was refused by the access policy to a verified caller that does hold XACML_USER — an operator-edited access-control document denied it. HTTP 403 access_denied
STS-XACML-0007 A remote-PEP endpoint (/xacml/pep/*, POST /xacml/pip) was refused to a caller that presented no client certificate. HTTP 403 access_denied (PIPError XML on /xacml/pip)
STS-XACML-0008 A remote-PEP endpoint was refused to a caller whose client certificate did not verify against this service’s truststore. HTTP 403 access_denied
STS-XACML-0009 A remote-PEP endpoint was refused to a verified certificate whose subject resolves to no directory entry holding REMOTE_PEPS (not in roles.remotePepGroup). HTTP 403 access_denied
STS-XACML-0010 A remote-PEP endpoint was refused by the access policy to a verified caller that does hold REMOTE_PEPS — an operator-edited access-control document denied it. HTTP 403 access_denied
STS-XACML-0011 A decision request to POST /xacml/pdp was not a well-formed JSON Profile request. HTTP 400 invalid_request
STS-XACML-0012 A decision could not be made because the repository’s root policy does not load; the PDP answered Indeterminate. HTTP 200 with decision Indeterminate (XACML status syntax-error); GET /xacml/protected may then refuse with 403
STS-XACML-0013 The engine reached Indeterminate through a processing or syntax error while evaluating a policy (not a missing attribute). HTTP 200 with decision Indeterminate (XACML status processing-error or syntax-error); GET /xacml/protected may then refuse with 403
STS-XACML-0014 The embedded demonstration PEP at GET /xacml/protected refused the subject because the decision was not one its bias allows. HTTP 403 with the PEP’s JSON enforcement answer
STS-XACML-0015 The embedded demonstration PEP refused a Permit because the decision carried an obligation it cannot discharge (XACML 3.0 section 7.2). HTTP 403 with the PEP’s JSON enforcement answer
STS-XACML-0016 GET /xacml was asked with a format or bias query parameter outside its allowed values. HTTP 400 text/plain
STS-XACML-0017 A remote PEP registration arrived on a plain HTTP listener, which cannot carry the client certificate xacml.pepRequireCertificate demands. HTTP 401 invalid_client
STS-XACML-0018 A remote PEP registration arrived over TLS with no client certificate while xacml.pepRequireCertificate is on. HTTP 401 invalid_client
STS-XACML-0019 A remote PEP registration produced no usable name from the certificate’s common name or the body’s name. HTTP 400 invalid_request
STS-XACML-0020 A remote PEP heartbeat named no PEP, neither by certificate nor by body. HTTP 400 invalid_request
STS-XACML-0021 A remote PEP heartbeat named a PEP that is not registered in ou=peps. HTTP 404 invalid_request
STS-XACML-0022 POST /xacml/pip was rate-limited (xacml.pipMaxPerWindow over security.rateLimitWindowS). HTTP 429 too_many_requests (PIPError XML) with Retry-After
STS-XACML-0023 A PIP query was not a well-formed carrying a and at least one . HTTP 400 invalid_request (PIPError XML)
STS-XACML-0024 A PIP query named more designators than xacml.pipMaxDesignators allows. HTTP 400 invalid_request (PIPError XML)
STS-XACML-0025 A PIP query carried a designator field or subject-id that is over its length cap or contains a control character. HTTP 400 invalid_request (PIPError XML)
STS-XACML-0026 A write to ou=policies, ou=peps or ou=roles was refused because no embedded directory is loaded in this process. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }; remote PEP register/heartbeat: HTTP 400/404 invalid_request
STS-XACML-0027 The embedded directory refused a write or removal in ou=policies, ou=peps or ou=roles — usually a container at its maximum. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }; remote PEP register/heartbeat: HTTP 400/404 invalid_request
STS-XACML-0028 A policy document was refused at write: it does not parse or fails XACML static type checking. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0029 A policy write named an entry that is not 1 to 128 letters, digits, dot, dash or underscore. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0030 A policy write asked to be the root while another policy already is. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0031 An XACML console action was refused because the console session holds Admin Read and not Admin Write. 303 back to the page with error=…, or HTTP 400 { ok: false, why } for a JSON post
STS-XACML-0032 An XACML console or management API action named an action that does not exist. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0033 An XACML repository or editor action named a policy that is not in the repository. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0034 The editor was asked to edit a stored policy that does not load. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0035 The guided policy editor refused an edit (a path, node kind or argument that the grammar does not allow). console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0036 A policy could not be created because the named template refused to build (unknown template or bad parameter). console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0037 An ALFA import did not parse. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0038 A remote PEP console action named no PEP, or one that is not registered. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0039 An issuance was refused because the issuance policy answered Deny. the issuance site’s own protocol refusal (for example OAuth access_denied)
STS-XACML-0040 An issuance was refused because the issuance policy answered NotApplicable. the issuance site’s own protocol refusal (for example OAuth access_denied)
STS-XACML-0041 An issuance was refused because the issuance policy could not be evaluated (Indeterminate). the issuance site’s own protocol refusal (for example OAuth access_denied)
STS-XACML-0042 An issuance for an application that requires a role was refused FAIL-CLOSED because no issuance policy is loaded (disabled, not loading, or the built-in template failed). the issuance site’s own protocol refusal (for example OAuth access_denied)
STS-XACML-0043 No issuance policy is loaded; issuance to applications requiring only EVERYBODY is not being gated (logged once per process). —
STS-XACML-0044 Access to a gated surface was refused because the access policy answered Deny. the gated surface’s own refusal (for example HTTP 403)
STS-XACML-0045 Access to a gated surface was refused because the access policy could not be evaluated (Indeterminate). the gated surface’s own refusal (for example HTTP 403)
STS-XACML-0046 Access to a gated surface was refused because the access policy answered NotApplicable under deny-unless-permit. the gated surface’s own refusal (for example HTTP 403)
STS-XACML-0047 The access policy named by xacml.accessPolicy is disabled, so access to every gated surface is ALLOWED without a policy decision. —
STS-XACML-0048 The access policy named by xacml.accessPolicy does not load, so access to every gated surface is ALLOWED without a policy decision. —
STS-XACML-0049 The built-in access-control policy could not be built from its template (a defect), so access to every gated surface is ALLOWED without a policy decision. —
STS-XACML-0050 common/access_gate.ts was given a decider that is not a function; every access decision is allowed. —
STS-XACML-0051 The access gate’s decider threw; access was ALLOWED because a throw is a defect rather than a decision. —
STS-XACML-0052 The issuance gate’s decider threw; issuance was ALLOWED because a throw is a defect rather than a decision. —
STS-XACML-0053 The role register threw while resolving a party’s roles; only the built-in roles were used. —
STS-XACML-0054 The role register threw while building the roles claim; the token or assertion was issued without it. —
STS-XACML-0055 A role write named an invalid role name, or the name of a built-in role. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0056 A role removal named a built-in role, which is computed and cannot be deleted. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0057 A role removal named a role that does not exist. console: 303 back to the page with error=…; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0058 A stored, enabled policy does not parse, so it was left out of the repository a decision resolves references against. —
STS-XACML-0059 The seeded policy was refused when ou=policies was created. —
STS-XACML-0060 The policy repository’s change observer threw after a successful write; the write stands. —
STS-XACML-0061 A directory value the PIP read does not parse at the datatype the policy designates, so it was dropped from the bag. —
STS-XACML-0062 A decision counter behind /admin/xacml/monitor threw; nothing was counted and the decision is unaffected. —
STS-XACML-0063 A decision was recorded against an asker the monitor’s catalogue does not know, so it was not counted. —
STS-XACML-0064 A realm’s remote PEP register could not be read (for the monitor or the other-realms hint); that part was reported as empty. —
STS-XACML-0065 The change-nudge dispatcher threw, which is a defect rather than an unreachable PEP; no policy change is lost. —
STS-XACML-0066 A change nudge was not sent because the PEP’s notify URL is outside the outbound bounds (not a URL, wrong scheme, plain http without xacml.pepNotifyAllowHttp, or a host not in xacml.pepNotifyAllowedHosts). —
STS-XACML-0067 A PEP’s notify endpoint answered a change nudge with a redirect, which is not followed. —
STS-XACML-0068 A PEP’s notify endpoint answered a change nudge with a non-2xx status. —
STS-XACML-0069 A PEP’s notify endpoint did not answer a change nudge within xacml.pepNotifyTimeoutMs. —
STS-XACML-0070 A change nudge could not be delivered because the connection to the PEP’s notify endpoint failed. —
STS-XACML-0071 An HTTPS listener certificate was asked for a PEP that is not registered in this realm, so there is no realm to issue it from. console: a page saying so; /admin-api: HTTP 400 { ok: false, errors }
STS-XACML-0072 A remote PEP’s HTTPS listener certificate could not be issued: the certificate authority refused it, or issuing threw. console: a page saying so; /admin-api: HTTP 400 { ok: false, errors }, or 500 when issuing threw
STS-XACML-0073 A change nudge was not sent because the PEP’s notify URL is plain http and the realm is in product mode, whatever xacml.pepNotifyAllowHttp says (#171). —
STS-XACML-0074 Product mode ignored xacml.pepNotifySkipTlsVerification: a nudge verifies the PEP’s certificate whatever it says. Logged once per process (#171). none — a warning in the log
STS-XACML-0075 A write put a person or a group on ADMIN_READ or ADMIN_WRITE; their people are the console roster’s, granted on /admin/rbac, and only an application is added on the role (#303). none (a console or management API refusal, HTTP 400)
STS-XACML-0076 A delete named a native role — ADMIN_READ, ADMIN_WRITE or DEVICE_COMPLIANCE — which every realm keeps (#303, #309). none (a console or management API refusal, HTTP 400)
STS-XACML-0077 A native role (ADMIN_READ, ADMIN_WRITE or DEVICE_COMPLIANCE) could not be seeded in a realm; no machine client can be issued its permission there until it exists (#303, #309). none — a warning in the log
STS-XACML-0078 Neither the issuance policy nor the built-in one it falls back to gave a verdict on a requested scope — a defect; a scope gated by role was dropped and an ungated one kept (#304). none — a warning in the log
STS-XACML-0079 The built-in issuance policy could not be evaluated for the per-scope question in a process with no issuance PEP — a defect; scopes gated by role were dropped and the rest kept (#304, #305). none — an error in the log
STS-XACML-0080 A write named an application’s role that is not @, or used a native or built-in role's name for one (#310). none (a console or management API refusal, HTTP 400)
STS-XACML-0081 A role write named a member type that is not user or application (#93). none (a console or management API refusal, HTTP 400)
STS-XACML-0082 A role write gave the role a member of a kind its member types exclude: a person or group on an applications-only role, or an application on a people-only one (#93). none (a console or management API refusal, HTTP 400)
STS-XACML-0083 A role write tried to restrict a console role (ADMIN_READ, ADMIN_WRITE) to one member type; it holds people and applications both (#93). none (a console or management API refusal, HTTP 400)
STS-XACML-0084 In product mode the issuance policy refused an issuance to an application through a protocol family it is not declared for (appAllowedProtocol): an ID Token to an application declared for OAuth 2.0 alone, a SAML assertion to one declared for OpenID Connect. each protocol’s own refusal (access_denied, a SAML Responder status, KDC_ERR_POLICY, a WS-Trust fault)
STS-XACML-0085 No issuance policy, not even the built-in one, gave a verdict on who may act for whom (#186); the exchange was refused. each protocol’s own refusal
STS-XACML-0086 The issuance gate’s decider threw on an exchange question (#186); the built-in policy decided instead. —
STS-XACML-0087 No issuance policy, not even the built-in one, answered the may_act question for a subject who named a delegate (#186); the subject’s own choice was put in the token. —
STS-XACML-0168 No issuance policy, not even the built-in one, could answer the per-right GNAP question (issue-gnap-right); the right was refused (#432). —

STS-XPEP

Remote XACML PEP (container). The second container: the remote Policy Enforcement Point that pulls the policy repository from this service, registers and heartbeats, asks the PIP over HTTP and decides in its own process. It has no audit log, so these codes appear at the front of its log lines rather than on an audit row.

Raised from: xacml-pep/.

Code What failed Client sees
STS-XPEP-0001 The error-code registry could not be loaded from ./error_codes or ../common/error_codes; the container starts anyway and tags its lines with a local fallback. In the image, the Dockerfile stopped copying common/error_codes.js. —
STS-XPEP-0002 The version module could not be loaded from ./version or ../common/version, so the PEP registers and reports its version as ‘unknown’. In the image, the Dockerfile stopped copying common/version.js and VERSION. —
STS-XPEP-0003 PEP_TLS_CERT, PEP_TLS_KEY or PEP_TLS_CA names a file that could not be read; the PEP carries on without it, so it registers unauthenticated or is refused. —
STS-XPEP-0004 The policy permitted the request but the decision carries an obligation this PEP cannot discharge, so section 7.2 turned the Permit into a refusal. HTTP 403 from GET /protected
STS-XPEP-0005 A decision was asked for while the PEP holds no root policy (it has never pulled one, or what it pulled had no root); the decision is NotApplicable and the bias settles it. HTTP 403 from GET /protected when deny-biased, 200 when permit-biased
STS-XPEP-0006 The engine answered Indeterminate for a request against the policy this PEP holds (a processing or missing-attribute error); the bias settles it. HTTP 403 from GET /protected when deny-biased, 200 when permit-biased
STS-XPEP-0007 A request arrived whose URL would not parse, so it could name none of the PEP’s endpoints. HTTP 400
STS-XPEP-0008 Deciding a GET /protected request threw inside the PEP (the PIP, the engine or enforcement), so no decision was reached. A defect in the PEP, not a Deny. HTTP 500 decision_failed
STS-XPEP-0009 A request named a method and path the PEP does not answer (it answers GET /, GET /protected, POST /notify and GET /healthcheck). HTTP 404 not_found
STS-XPEP-0010 A policy pull threw unexpectedly, from the nudge or from the poll timer. The policy already held is kept and the next poll tries again. —
STS-XPEP-0011 Retrying the registration on the poll timer threw unexpectedly; the pull still runs and the registration is tried again next interval. —
STS-XPEP-0012 The heartbeat, or the pull it triggers when the PDP says this copy is behind, threw unexpectedly. Reporting only; enforcement is unaffected. —
STS-XPEP-0013 The PEP could not start (registration, first pull, timers or listener setup threw) and the process exits. —
STS-XPEP-0014 The seven XACML engine modules were found neither beside engine.js nor one directory up, so the PEP cannot load and the process dies at require. —
STS-XPEP-0015 The PEP could not reach the PDP to register (network, TLS, timeout or a PEP_PDP_URL that is not a URL). It still enforces and retries on every poll. —
STS-XPEP-0016 The PDP refused the PEP’s registration (a missing or unrecognised client certificate, a full register, a taken name, or remote PEPs turned off). It still enforces with what it can pull and retries on every poll. —
STS-XPEP-0017 A policy pull could not reach the PDP. The last good policy set is kept and enforced, and the PEP reports itself stale. —
STS-XPEP-0018 The PDP refused a policy pull or answered it with an unexpected status (commonly 403: no verified certificate holding REMOTE_PEPS; 501: remote PEPs off in that realm). The last good policy set is kept. —
STS-XPEP-0019 The PDP answered a policy pull with 200 and a body that is not a policy set. The last good policy set is kept. —
STS-XPEP-0020 One or more pulled policies would not parse or validate in this PEP and were left out, so its policy count disagrees with the PDP’s. —
STS-XPEP-0021 A policy pull succeeded but no pulled policy is the root, so there is nothing to evaluate and every decision is NotApplicable until one is. —
STS-XPEP-0022 The heartbeat could not reach the PDP. Reporting only; enforcement is unaffected. —
STS-XPEP-0023 The PDP refused the heartbeat or answered it with a status other than 200 (for example an unregistered PEP). Reporting only; enforcement is unaffected. —
STS-XPEP-0024 The policy designates more access-subject attributes than one PIP query may carry, so none was fetched and every designator resolves to an empty bag. —
STS-XPEP-0025 The PIP query to POST /xacml/pip could not be made (network, TLS, timeout or an unparsable PDP URL); the PEP decides on the request’s own attributes alone. —
STS-XPEP-0026 The PDP refused the PIP query or answered it with a status other than 200 (403 when the client certificate does not hold REMOTE_PEPS); the PEP decides on the request’s own attributes alone. —
STS-XPEP-0027 The PDP’s answer to the PIP query would not parse as a PIPResponse, so every designator resolves to an empty bag. —
STS-XPEP-0028 The PIP returned a value that is not valid at the datatype the policy’s designator declares; the value is dropped rather than making the decision Indeterminate. —
STS-XPEP-0029 Only one of PEP_HTTPS_CERT and PEP_HTTPS_KEY is set, so the PEP has no HTTPS listener. Plain HTTP is unaffected. —
STS-XPEP-0030 The HTTPS certificate and key files could not be read, are not PEM, or do not belong together. A listener already serving keeps the pair it has; one not yet started waits for a usable pair. —
STS-XPEP-0031 The HTTPS listener could not bind its port (commonly the port is taken). Plain HTTP and enforcement are unaffected. —
STS-XPEP-0032 The certificate the HTTPS listener is serving is expired or not yet valid, so clients that check will refuse the handshake. —
STS-XPEP-0033 The remote XACML PEP met an uncaught exception after it had started, and contained it rather than exiting (#355): it carries on enforcing the policy it last pulled. The line carries the stack; a distinct fault is logged at occurrences 1, 2, 3 and each power of ten. none — logged; the PEP carries on
STS-XPEP-0034 The remote XACML PEP met a promise rejection nobody handled after it had started, and contained it rather than exiting (#355), throttled as STS-XPEP-0033 is. none — logged; the PEP carries on

STS-ADMIN

Admin console. The console at /admin, its gate, and the actions behind its controls.

Raised from: admin-ui/ (except pki_admin.js), admin-core/.

Code What failed Client sees
STS-ADMIN-0001 The admin console could not start a sign-in: its OIDC client entry (sts-admin-console) is missing, or declares a client secret method and has no secret. HTTP 503 temporarily_unavailable (JSON) or a 503 page
STS-ADMIN-0002 The admin console could not start a sign-in in product mode because the address it was reached at is not a registered redirect URI of sts-admin-console. HTTP 503 temporarily_unavailable (JSON) or a 503 page
STS-ADMIN-0003 A console request that cannot be redirected to sign in (a JSON caller, or a form POST) carried no console session. HTTP 401 login_required
STS-ADMIN-0004 A console sign-out was refused because the form did not carry this session’s CSRF token. HTTP 403 csrf
STS-ADMIN-0005 A console write (a non-GET request) was refused because it did not carry this session’s CSRF token. HTTP 403 csrf
STS-ADMIN-0006 The access policy (the XACML access-control document) refused a console request for a person who holds the console role it needs. HTTP 403 policy_denied
STS-ADMIN-0007 A signed-in person without the Admin Read role tried to read a console page. HTTP 403 insufficient_role
STS-ADMIN-0008 A signed-in person without the Admin Write role tried to post a console form. HTTP 403 insufficient_role
STS-ADMIN-0009 A console request’s query string failed validation (an over-long, repeated or malformed parameter). HTTP 400 page
STS-ADMIN-0010 The admin console’s OIDC callback refused the authorization response (state, code redemption, ID Token verification or session establishment failed). HTTP 400 page
STS-ADMIN-0011 The admin console’s OIDC callback threw rather than resolving; this is a defect in the relying-party code, not something a request can cause. HTTP 500 page
STS-ADMIN-0012 A console action was refused (its result was not ok) and the action named no more specific code. HTTP 303 back to the page with error=, or HTTP 400 JSON
STS-ADMIN-0013 An asynchronous console action (Shared Signals, CAEP, RISC or SPIFFE) rejected instead of resolving a refusal; it is answered as a refused action. HTTP 303 back to the page with error=, or HTTP 400 JSON
STS-ADMIN-0014 A console inverted-hook slot was offered an incomplete filler at startup and refused it whole; the pages and operations behind it report the reader as not installed. —
STS-ADMIN-0015 The startup check of SETTING_HOMES found a settings group drawn on no page, drawn twice, unknown to config.js, or sent to a path that is not a console page. —
STS-ADMIN-0016 The new-user form’s Fill with example data was refused because the service is running in product mode. HTTP 200 form page with a warning, or HTTP 400 JSON
STS-ADMIN-0017 The new-user form’s Fill with example data was pressed with no username to seed the example person from. HTTP 200 form page with a warning
STS-ADMIN-0018 The new-user form was posted with an action other than create or fill. HTTP 200 form page with a warning, or HTTP 400 JSON
STS-ADMIN-0019 The admin console’s Shared Signals receive endpoint refused a pushed Security Event Token and the receiver named no more specific code. HTTP 4xx/5xx per RFC 8935, as the receiver decided
STS-ADMIN-0020 The realm switcher named a trust realm that is not defined; the browser was sent back to the current realm. HTTP 303 to the current realm
STS-ADMIN-0021 A console drill-down named a record that does not exist: an application, an authorization server profile, a trust realm, a federation relationship or a cache. HTTP 200 page saying there is no such record
STS-ADMIN-0022 The realm switcher was given a return path that is not a single-slash-rooted path (a possible open redirect); /admin was used instead. HTTP 303 to /admin in the chosen realm
STS-ADMIN-0500 An admin console control or management API action named an operation its resource does not have. HTTP 400 (API JSON errors) or a 303 back to the console page with error=
STS-ADMIN-0501 An admin action needs a module that is not loaded in this process (the logout reader, the directory or group writer, the Shared Signals reporters, the XACML pages, or the client-certificate truststore), so there is nothing to act on. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0502 A token revoke or restore named no jti and no token to read one from. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0503 An artifact revoke or restore named no credential handle. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0504 An artifact revoke or restore named a handle this service no longer holds (never issued, or forgotten to the cap). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0505 A token-set revoke or restore named no set. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0506 A token-set revoke or restore named a set this service no longer holds. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0507 A token-set revoke was refused because nothing in the set carries an identifier to revoke. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0508 A revoke-by-kind named a credential kind that cannot be revoked. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0509 A bulk token revocation by subject or by user named nobody. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0510 A session revoke on /admin/sessions did not carry both the identity key and the session id. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0511 A session revoke ended nothing: the session had already ended, or the logout module skipped it. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0512 An /admin/logout action named no identity to act on. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0513 An /admin/logout end action was posted with nothing selected. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0514 A delegated-permission action that edits the exposing application named no resource application. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0515 A delegated-permission grant or revoke named no client application. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0516 The delegated-permission register refused a change made from the console or the management API. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0517 The XACML administration pages refused an action reached through the management API. HTTP 400 (API)
STS-ADMIN-0518 A users action that acts on one person (activation link, password, second-factor clear, attribute edit) named nobody. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0519 An activation link could not be issued for the named person. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0520 An operator’s clear of a person’s authenticator app was refused. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0521 An operator’s clear of a person’s recovery codes was refused. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0522 An operator’s removal of a person’s security key was refused (no such key, or it is their last way in). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0523 A set-password action sent neither a password nor a request to generate one. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0524 A set-password action’s password and confirmation did not match. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0525 A password set by an operator was refused by the password policy or could not be written. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0526 Creating a person from the console or the management API was refused by the directory (a bad or taken username, or a refused attribute). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0527 Creating a group from the console or the management API was refused by the directory. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0528 Adding a member to a group from the console or the management API was refused by the directory. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0529 An applications action that edits one entry named no application. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0530 The application registry refused to create an entry (including a SAML 2.0 service provider or SAML 1.1 relying party registered by hand). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0531 The application registry refused to change an attribute on an entry (including the SAML 2.0 logout service and signing certificate). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0532 Refreshing a service provider’s SAML metadata from its configured URL failed. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0533 A revoke-registration named an application the registry does not hold. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0534 A revoke-registration named an application that has no RFC 7591 registration to revoke. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0535 The application registry refused to forget an entry. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0536 The authorization server profile register refused a create, member change, reset or delete. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0537 A SAML 2.0 service provider action named no entityID. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0538 A SAML 1.1 relying party action named no identifier. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0539 A console role grant or revoke was refused and carried no more specific code. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0540 The consent register refused a global consent change, a revocation or a forget. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0541 Creating a role was refused because a role of that name already exists. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0542 The role register refused a role write or delete (the name grammar, a built-in name, or the cap). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0543 A role action named a role that does not exist. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0544 A role membership action named a member kind that is not user, group or application. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0545 A role membership action named no member. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0546 A role membership action named a built-in role, which is computed and has no membership to edit. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0547 Adding a role member was refused because they already hold the role. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0548 Removing a role member was refused because they do not hold the role. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0549 Saving a password policy profile was refused (a missing or invalid field, or fields that contradict each other). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0550 Resetting a password policy profile to the built-in defaults was refused. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0551 A claims action named a claim set this page or resource does not carry. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0552 A claim set or its directory-attribute selection refused a change (a reserved or duplicate claim name, or an unknown attribute). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0553 Removing a claim was refused because the claim set has no claim of that name. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0554 Replacing a claim set was refused because the claims posted are not valid JSON. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0555 Replacing a claim set was refused because the claims posted are not a JSON array. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0556 The verifiable credential claim selection refused a change. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0557 A verifiable credential claim add or remove named no attribute. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0558 Adding a verifiable credential claim was refused because it is already selected. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0559 Removing a verifiable credential claim was refused because it is not selected. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0560 Populating the directory for the verifiable credential claim set failed. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0561 The OpenID4VP verifier configuration refused a change to the requested claims or the default format. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0562 The trust realm registry refused a create, update, override change or removal. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0563 A request tried to remove the trust realm it arrived in. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0564 The settings table refused a change: an unknown or restart-only key, or a value that failed the setting’s check. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0565 A settings action was posted with no setting it recognises. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0566 A token lifetime or SAML assertion settings action was given a field that page does not own. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0567 A Shared Signals, CAEP or RISC console action was refused and carried no more specific code. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0568 Adding client-certificate trust anchors was refused (nothing readable as a certificate, all already held, or the truststore full). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0569 Removing a client-certificate trust anchor was refused (no anchor with that fingerprint). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0570 The SPIFFE registry refused a registration entry create, update or delete. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0571 A SPIFFE registration entry update or delete named no entry. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0572 A SPIFFE registration entry update named a field that may not be changed. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0573 A SPIFFE agent action named no agent. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0574 The SPIFFE registry refused an agent ban, unban or delete. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0575 The federation register refused a relationship create, change, enable, disable or delete. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0576 A federation action named no relationship. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0577 Rotating a SPIFFE X.509 or JWT authority from the console failed. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0578 A SPIFFE authority rotation named neither x509, jwt nor both. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0579 Setting a federated SPIFFE bundle named no trust domain. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0580 A federated SPIFFE bundle was refused (not a readable bundle for that trust domain). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0581 Removing a federated SPIFFE bundle was refused because none is held for that trust domain. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0582 A console role grant or revoke named a role that is neither Admin Read nor Admin Write. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0583 A console role grant named somebody whose name cannot be a directory entry under ou=users. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0584 A console role revoke named nobody. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0585 The directory refused the group write behind a console role grant or revoke. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0586 A console role revoke was refused because the person holds the role through a memberOf value on their own entry, which this console does not write. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0587 The console roles’ directory slot was offered a filler missing required functions and was not installed; the roles read as having no directory. —
STS-ADMIN-0588 A key pair export was refused because the caller does not hold Admin Write. HTTP 403
STS-ADMIN-0589 A key pair export named a key this realm does not hold. HTTP 400 (JSON or API) or a 303 with error=
STS-ADMIN-0590 A key pair export was refused because the key has not been generated yet, or has no exportable encoding. HTTP 400 (JSON or API) or a 303 with error=
STS-ADMIN-0591 A key pair export asked for a format that key does not offer. HTTP 400 (JSON or API) or a 303 with error=
STS-ADMIN-0592 A key pair export found no PEM key pair for the key in this realm. HTTP 400 (JSON or API) or a 303 with error=
STS-ADMIN-0593 The key exporter refused an export (for example a PKCS#12 with no password, or a key it cannot read). HTTP 400 (JSON or API) or a 303 with error=
STS-ADMIN-0594 A key pair export threw unexpectedly. HTTP 400 (JSON) or a 303 with error=
STS-ADMIN-0595 The crypto report was handed a malformed protocol family list and ignored it; its drift check does not run. —
STS-ADMIN-0596 This build of the admin console offers no crypto reporter slot, so the management API cannot mirror the crypto and key pages. —
STS-ADMIN-0597 The API explorer could not mint an access token for the reader; the page draws and Try it will be refused. —
STS-ADMIN-0598 The /admin/database page threw while being drawn. HTTP 200 page saying it could not be drawn
STS-ADMIN-0599 The /admin/secrets page threw while being drawn. HTTP 200 page saying it could not be drawn
STS-ADMIN-0600 The delegation map picture could not be laid out; the page drew without it. —
STS-ADMIN-0601 The federation map picture could not be laid out; the page drew without it. —
STS-ADMIN-0602 A Kerberos principals action named an action the page does not have. HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0603 A Kerberos service principal action named something that is not a usable service principal name (fewer than two components, a foreign realm, krbtgt, or characters a principal may not carry). HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0604 A service principal was created for an SPN that already holds a stored key; rotate it instead. HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0605 A service principal was rotated or deleted and holds no stored key. HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0606 The application entry a service principal’s key is stored on could not be found or created. HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0607 A Kerberos key could not be sealed or written, so nothing was stored and no keytab was handed out. HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0608 A clear-person-keys action named nobody, or somebody not in the default trust realm’s directory. HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0609 The Kerberos key register has no directory in this process, so a principal could be neither listed nor changed. HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0610 “Rotate and invalidate” of the krbtgt key was asked for without the typed confirmation “invalidate”; nothing was queued. HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0611 A rotation of the krbtgt key could not be queued on the scheduler (the scheduler is off, or refused the run). HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0620 Regenerating an application’s client secret was refused: the application is not in the registry. HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0640 A certificate details view was asked for with a value that is not a SHA-256 certificate fingerprint (64 hexadecimal digits). the page with a dialog saying so / HTTP 400 { ok: false, errors }
STS-ADMIN-0641 A certificate details view named a fingerprint this service does not hold in the trust realm the request was reached in. the page with a dialog saying so / HTTP 404 { ok: false, errors }
STS-ADMIN-0642 A certificate this service holds could not be described or its chain could not be built. the page with a dialog saying so / HTTP 500 { ok: false, errors }
STS-ADMIN-0643 The used-assertion history page could not be drawn, because the store holding the history could not be read. the page with a warning saying so
STS-ADMIN-0644 An RFC 9728 protected resource metadata import was refused (load-resource-metadata), where the library named no code of its own. HTTP 400 (API), or /admin/applications/new redrawn with the reason
STS-ADMIN-0645 A create from an imported RFC 9728 document was refused on /admin/applications/new, where the create named no code of its own, and the page was redrawn with the reason. /admin/applications/new redrawn with the reason
STS-ADMIN-0646 A software statement was asked to be issued for an application that is not in the registry. the caller’s refusal (errors on a console or /admin-api reply)
STS-ADMIN-0647 The client metadata given for a software statement to issue is not a JSON object, or the input validator refused it. the caller’s refusal (errors on a console or /admin-api reply)
STS-ADMIN-0648 The client metadata given for a software statement to issue names a JWT claim or a member only registration assigns. the caller’s refusal (errors on a console or /admin-api reply)
STS-ADMIN-0649 A software statement for an application could not be signed or written onto its entry. the caller’s refusal (errors on a console or /admin-api reply)
STS-ADMIN-0650 A software statement could not be issued because there was no issuer to name: no request address reached the action and oauth2.issuer is not set. the caller’s refusal (errors on a console or /admin-api reply)
STS-ADMIN-0700 The query string of /admin/oauth2/monitor did not match the shape the page accepts (state, client_id, page, per, clientsPage, offset, limit, format) and was refused before anything was read. HTTP 400 text/plain
STS-ADMIN-0701 An OAuth 2.0 monitoring action named an action the page does not have; the refusal names the one it does. the caller’s refusal (a 303 with error= on the console, HTTP 400 { ok: false, errors } on /admin-api)
STS-ADMIN-0702 A withdrawal of a pushed authorization request carried no request_uri, or one longer than the store could ever hold. the caller’s refusal (a 303 with error= on the console, HTTP 400 { ok: false, errors } on /admin-api)
STS-ADMIN-0703 A withdrawal of a pushed authorization request named a value that is not in the urn:ietf:params:oauth:request_uri: namespace this service issues pushed request_uris from (RFC 9126 section 2.2). the caller’s refusal (a 303 with error= on the console, HTTP 400 { ok: false, errors } on /admin-api)
STS-ADMIN-0704 A withdrawal named a request_uri this realm does not hold: it was never pushed here, it expired and was swept, or it was already withdrawn. the caller’s refusal (a 303 with error= on the console, HTTP 400 { ok: false, errors } on /admin-api)
STS-ADMIN-0705 An OAuth 2.0 monitoring console action threw; nothing is known to have changed and the log line carries the stack. a 303 back to /admin/oauth2/monitor with error=
STS-ADMIN-0706 The bootstrap administrator could not be created in the default realm, or could not be given both console roles, at startup. none — logged
STS-ADMIN-0720 Issuing an application a TLS client certificate was refused with no more specific code (the key algorithm, the label or the realm’s certificate authority). the caller’s refusal (errors on a console or /admin-api reply)
STS-ADMIN-0721 An application TLS client certificate’s file password was too short, too long, or not the same twice. the caller’s refusal (errors on a console or /admin-api reply)
STS-ADMIN-0722 An application TLS client certificate action named an application the registry does not hold. the caller’s refusal (errors on a console or /admin-api reply)
STS-ADMIN-0723 Revoking an application’s TLS client certificate was refused with no more specific code. the caller’s refusal (errors on a console or /admin-api reply)
STS-ADMIN-0724 An asynchronous applications action on the console threw; nothing is known to have changed and the log line carries the stack. the console’s refusal (a redirect with the error)
STS-ADMIN-0780 Resetting somebody’s password was refused by the password policy or the store. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0781 Issuing somebody a password reset link was refused (nobody by that name, or no store). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0782 A password reset link was issued and the person’s password could not be removed, so the link was withdrawn. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0783 Disabling somebody’s primary security keys was refused. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0784 Disabling somebody’s second factors was refused. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0785 Requiring, or no longer requiring, a second factor of somebody was refused. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0786 A realm administrator reached the console in a realm other than the one they signed in through, where they hold no role. HTTP 403 on /admin
STS-ADMIN-0787 A realm administrator was refused a service-wide console page or action (the store, the listeners, the service Root, the realm registry, another realm). HTTP 403 on /admin
STS-ADMIN-0788 A realm administrator posted a setting that names the whole service rather than their realm. HTTP 403 on /admin
STS-ADMIN-0789 A new trust realm’s bootstrap administrator could not be given its generated password in product mode. none — logged
STS-ADMIN-0790 The realm chooser in front of /admin was asked for a realm that is not defined. HTTP 400 on /admin
STS-ADMIN-0791 Uploading a SAML 2.0 service provider’s metadata document failed — none was sent, or consuming it was refused. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0792 Disabling or enabling an account named nobody, or named the anonymous principal, which is not an account. HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0793 Disabling or enabling an account was refused and the refusal carried no code of its own. HTTP 400 { ok: false, errors } / 303 with error=
STS-ADMIN-0794 A disable named a riscReason that is not one of RISC account-disabled’s two (hijacking, bulk-account; RISC 1.0 section 2.2). HTTP 400
STS-ADMIN-0795 A named authorization server’s fapi member was set to a value that is not a FAPI profile this service enforces, nor off (#138). HTTP 400
STS-ADMIN-0796 Product mode: the bootstrap administrator reached the console before claiming it, signed in by something other than a password verified in its own realm (a federation partner, a certificate, a wallet, a Kerberos ticket). Its roles are not honoured and the window stays unclaimed. HTTP 403 bootstrap_password_required
STS-ADMIN-0797 Product mode: a signed-in person holding no console role reached the console while its bootstrap administrator had not yet claimed it. Development would have opened the console to them; product does not. Logged once per console session. HTTP 403 insufficient_role
STS-ADMIN-0798 Product mode, at startup or at a realm’s creation: a realm has no bootstrap administrator and nobody on its console roster, so its console is closed to everybody. POST /admin-api/rbac/grant with an admin:write access token is the way in. none (a log line)
STS-ADMIN-0799 An authorization server profile’s access_token_signing_alg was set to an algorithm this service does not sign access tokens with (#139). HTTP 400
STS-ADMIN-0800 Making an app password for somebody was refused; the credential store’s own code is on the audit row. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0801 Revoking somebody’s app password was refused; the credential store’s own code is on the audit row. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0802 A password reset for a Kerberos keytab gave neither or both of a password and random, or the new password was refused (the password policy’s own code wins where it gave one). Nothing was changed. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0803 A password reset for a Kerberos keytab SET the password and then no keytab could be made, or a Kerberos principals action threw inside the console. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0804 restore-kerberos (clearing a Kerberos sign-out instant) was refused because it is a development-only test control. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0805 set-not-delegated (marking a person as one who cannot be delegated, or clearing it) was refused (#108). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0806 set-may-act (naming the one party who may act for a person, or clearing it) was refused (#108). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0807 record-verification (an identity verification for OpenID Connect for Identity Assurance, #127) was refused: the verification did not check, a claim is not verifiable or has no value on the entry, or the entry does not exist. HTTP 400 (API) or a 303 with error=
STS-ADMIN-0808 remove-verification named a verification not recorded for the person, or the directory did not store the change (#127). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0809 enrol-self-issued-subject was refused: not a DID, thumbprint or public JWK, already enrolled for somebody, the person’s limit reached, or no entry (#129). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0810 remove-self-issued-subject named a subject not enrolled for the person, or the directory did not store the change (#129). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0811 remove-device named a device that is not the person’s, or the directory did not remove it (#130). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0812 answer-ciba-request, a development test control, was refused in product mode (#131). HTTP 400 (API)
STS-ADMIN-0813 answer-ciba-request named no CIBA request waiting for the person (#131). HTTP 400 (API)
STS-ADMIN-0814 clear-email-factor could not write the person’s entry (#64). HTTP 400 (API)
STS-ADMIN-0815 set-mail was given something that is not an address this service can send to (#64). HTTP 400 (API)
STS-ADMIN-0816 set-mail named nobody in this realm, or the directory would not write the address (#64). HTTP 400 (API)
STS-ADMIN-0817 A set-aud-sub act named no person or no client, a client_id with spaces, or an aud_sub over 255 characters or with control characters (#148). none (a console or management API refusal, HTTP 400)
STS-ADMIN-0818 A set-aud-sub act named a person with no entry in this realm, or the directory would not write it (#148). none (a console or management API refusal, HTTP 400)
STS-ADMIN-0819 set-attribute, add-attribute or remove-attribute was refused and ldap/person_editor.ts named no more specific reason (#228). HTTP 400 (API) or a 303 with error=
STS-ADMIN-0820 A console form POST held a value outside the closed set the mirroring /admin-api operation’s enum declares (#86). HTTP 400 page
STS-ADMIN-0821 A permission gated by role — admin:read, admin:write, or an application permission its resource lists in oauthRoleGatedPermission — was asked for on behalf of a person or an application no held role authorizes it for (for a person’s console roles: no Admin Read or Admin Write, not signed in, or the bootstrap administrator before its claim), and was left off the tokens (#302, #303). none — the token is issued without that scope (RFC 6749 section 3.3)
STS-ADMIN-0822 Every scope a request asked for was a permission gated by role that the subject’s roles do not authorize, so nothing was left to issue (#302, #303). invalid_scope (RFC 6749 sections 4.1.2.1 and 5.2)
STS-ADMIN-0823 add-permission or remove-permission named a native role — ADMIN_READ, ADMIN_WRITE or DEVICE_COMPLIANCE — whose permission is fixed (#303, #309). none (a console or management API refusal, HTTP 400)
STS-ADMIN-0824 add-permission or remove-permission named no permission (#303). none (a console or management API refusal, HTTP 400)
STS-ADMIN-0825 add-permission named a native permission (admin:read, admin:write, device:compliance), which only its native role authorizes (#303, #309). none (a console or management API refusal, HTTP 400)
STS-ADMIN-0826 add-permission named a permission no application in the realm defines; a permission must be defined before a role can authorize it (#303). none (a console or management API refusal, HTTP 400)
STS-ADMIN-0827 add-permission named a permission the role already authorizes (#303). none (a console or management API refusal, HTTP 400)
STS-ADMIN-0828 remove-permission named a permission the role does not authorize (#303). none (a console or management API refusal, HTTP 400)
STS-ADMIN-0829 create-role named a realm-wide role with the application separator “@” in it; that is how an application’s role is named (#310). none (a console or management API refusal, HTTP 400)
STS-ADMIN-0830 create-role named an application that is not in the realm’s registry (#310). none (a console or management API refusal, HTTP 400)
STS-ADMIN-0831 add-permission put another application’s permission on an application’s role, which may authorize only its own application’s permissions (#310). none (a console or management API refusal, HTTP 400)
STS-ADMIN-0832 add-attribute-claim named no directory attribute for the claim to carry (#94). HTTP 400 (console and API)
STS-ADMIN-0833 common/applications.js names an attribute as a boolean or a document field of the console’s field grid and the schema has no single-valued editable attribute of that name; the grid draws it as an ordinary field. none (startup log)
STS-ADMIN-0834 A create or update-fields from the field grid carried a box for a value of a multi-valued attribute with nothing in it; every box present for a list must hold a value, and an empty list is no boxes. HTTP 400 (console and API)
STS-ADMIN-0835 update-fields named no attribute to change: neither fields nor protocols was given. HTTP 400 (console and API)
STS-ADMIN-0836 update-fields changed some attributes of an application and was refused one or more others; the reply names each refusal. HTTP 400 (console and API)
STS-ADMIN-0837 generate-did-key was refused: no such application, one not declared for the did family, an algorithm other than ES256, ES384 or EdDSA, or the public key could not be written. none (a console or management API refusal, HTTP 400)
STS-ADMIN-0838 A person’s update-fields named no attribute to change: fields was absent or empty and the form named no field. HTTP 400 (console and API)
STS-ADMIN-0839 A person’s update-fields was refused one or more attributes, possibly after saving others; the reply names what was saved and each refusal. HTTP 400 (console and API)
STS-ADMIN-0840 A settings save ticked none of an ordered choice’s values (webauthn.algorithms on /admin/webauthn): an empty list is refused rather than saved, because the setting would fall back to a default nobody chose. none (a console refusal, drawn on the page)
STS-ADMIN-0841 set-delegation-semantics was refused: a value is neither delegation nor impersonation, nobody has that name, or the entry could not be written (#186). none (a console or management API refusal, HTTP 400)

STS-API

Management API. /admin-api, its access token, its request validation and the explorer.

Raised from: mgmt-api/.

Code What failed Client sees
STS-API-0001 A management API request carried no Bearer access token while adminApi.authRequired is on. HTTP 401 unauthorized, WWW-Authenticate: Bearer
STS-API-0002 A management API access token was not signed by this service (the default realm’s key), or its signature did not verify. HTTP 401 invalid_token, WWW-Authenticate: Bearer error=”invalid_token”
STS-API-0003 A management API access token had expired. HTTP 401 invalid_token, WWW-Authenticate: Bearer error=”invalid_token”
STS-API-0004 A management API access token was audienced to a different resource server than /admin-api. HTTP 403 forbidden
STS-API-0005 The XACML access policy refused a management API request made with a valid token, usually because the token lacks the admin:read or admin:write scope the method needs. HTTP 403 forbidden
STS-API-0006 In product mode with the token gate off, the XACML access policy refused a management API caller who does hold a console role. HTTP 403 forbidden
STS-API-0007 In product mode with the token gate off, a management API request arrived with nobody signed in. HTTP 401 JSON (HTTP 403 page for a browser)
STS-API-0008 In product mode with the token gate off, a signed-in management API caller did not hold the console role the method needs. HTTP 403 forbidden (HTTP 403 page for a browser)
STS-API-0009 A management API request body did not match the operation’s JSON Schema (an unknown member, a wrong type, or a value outside a closed set its enum declares — #86). HTTP 400 { ok: false, errors }
STS-API-0010 A management API request schema would not compile at startup, so that operation runs unvalidated. —
STS-API-0011 The crypto reporter slot that admin-ui/crypto_metadata.ts fills was not installed, so the crypto report, the key list or a key export could not be answered. HTTP 503 { ok: false, errors }
STS-API-0012 The database report could not be built (the probe run rejected). HTTP 500 { ok: false, errors }
STS-API-0013 The secret-store report could not be built (the probe run rejected). HTTP 500 { ok: false, errors }
STS-API-0014 A key export request named an action other than export. HTTP 400 { ok: false, errors }
STS-API-0015 A key export was refused (an unknown key, an unsupported format, or a missing PKCS#12 password) and the refusal carried no more specific code. HTTP 400 { ok: false, errors }
STS-API-0016 A key export threw while the keystore file was being built. HTTP 400 { ok: false, errors }
STS-API-0017 The TLS truststore reader is not installed in this process, so the truststore could not be reported. HTTP 503
STS-API-0018 The Shared Signals action rejected instead of resolving a refusal, which is a defect in ssf/ssf.ts. HTTP 500 { ok: false, errors }
STS-API-0019 The CAEP action rejected instead of resolving a refusal. HTTP 500 { ok: false, errors }
STS-API-0020 The RISC action rejected instead of resolving a refusal. HTTP 500 { ok: false, errors }
STS-API-0021 The PKI action rejected (certificate authority or key generation threw). HTTP 500 { ok: false, errors }
STS-API-0022 The SPIFFE action rejected (an authority rotation or key generation threw). HTTP 500 { ok: false, errors }
STS-API-0030 A management API users action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0031 A management API sessions action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0032 A management API sign-out (logout) action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0033 A management API groups action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0034 A management API admin roles (rbac) action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0035 A management API multi-factor (mfa) action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0036 A management API tokens action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0037 A management API trust realms action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0038 A management API configuration action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0039 A management API token lifetimes action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0040 A management API SAML assertions action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0041 A management API claims action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0042 A management API UserInfo claims action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0043 A management API custom SAML attributes action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0044 A management API credential claims action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0045 A management API verifier request action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0046 A management API federation action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0047 A management API SAML 2.0 action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0048 A management API SAML 1.1 action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0049 A management API authorization servers action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0050 A management API applications action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0051 A management API XACML action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0052 A management API Shared Signals (ssf) action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0053 A management API CAEP action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0054 A management API RISC action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0055 A management API PKI action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0056 A management API signals receiver action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0057 A management API TLS truststore action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0058 A management API delegated permissions action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0059 A management API roles action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0060 A management API policies action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0061 A management API consent action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0062 A management API SPIFFE action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0063 A management API SPIFFE registration entries action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0064 A management API SPIFFE agents action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0065 A management API Kerberos principals action was refused (including an unknown action) and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0080 A management API certificate details request was refused and the view attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0081 The used-assertion history could not be read for GET /admin-api/used-assertions, because the store holding it could not be queried. HTTP 500 { ok: false, errors }
STS-API-0082 A management API access token verified and its JOSE typ header is not at+jwt (RFC 9068 section 4): an ID Token, another JWT, or an access token minted before at+jwt. HTTP 401 invalid_token, WWW-Authenticate: Bearer error=”invalid_token”
STS-API-0083 A management API access token names an iss that is not an issuer this service publishes at any address this API answers under (RFC 9068 section 4). HTTP 401 invalid_token, WWW-Authenticate: Bearer error=”invalid_token”
STS-API-0100 The query string of GET /admin-api/oauth2/monitor did not match the shape the operation accepts (offset, limit, state, client_id, page, per, clientsPage) and was refused before anything was read. HTTP 400 { ok: false, errors }
STS-API-0101 An /admin-api/oauth2/monitor action was refused and the action layer attached no more specific code. HTTP 400 { ok: false, errors }
STS-API-0102 An /admin-api/oauth2/monitor action threw; nothing is known to have changed and the log line carries the stack. HTTP 500 { ok: false, errors }
STS-API-0110 An /admin-api access token bound to a client certificate (RFC 8705 cnf x5t#S256) was presented on a connection without that certificate. invalid_token (HTTP 401)
STS-API-0111 (retired) A trust realm’s own access token was presented at /admin-api by a client other than that realm’s sts-management-api. HTTP 403 forbidden
STS-API-0112 A trust realm’s own token or administrator reached a service-wide /admin-api operation, or another realm’s. HTTP 403 forbidden
STS-API-0113 A users or groups create that had claimed its name across nodes threw before it could answer; the claim was given back. HTTP 500
STS-API-0120 A DPoP-bound access token (cnf.jkt) was presented at /admin-api as a Bearer token. invalid_token (HTTP 401)
STS-API-0121 A DPoP proof presented at /admin-api did not verify, and the proof check reported no code of its own. invalid_dpop_proof (HTTP 401)
STS-API-0122 A management API access token was refused because this service has revoked or disowned it, or the person it was issued to has a disabled account. invalid_token (HTTP 401)
STS-API-0123 A management API access token carried the admin scope an operation needs, and the client it was issued to does not declare that scope in its oauthAllowedScope (in the realm that issued it). HTTP 403 forbidden
STS-API-0124 A management API query parameter held a value outside the closed set its operation’s enum declares (#86). HTTP 400 { ok: false, errors }
STS-API-0125 A management API access token carried the admin scope an operation needs, and its subject — a person, or the application on a client_credentials token — no longer holds a role authorizing it in the realm that issued it (#302, #303). HTTP 403 forbidden

STS-PORTAL

User portal. The pages that belong to the person looking at them, and account activation.

Raised from: portal/.

Code What failed Client sees
STS-PORTAL-0001 A user portal request’s query string or form body did not match the shape its route accepts, and was refused before anything was read or changed. HTTP 400 page (Bad request)
STS-PORTAL-0002 An activation link was tried too often from one address or for one account, and the rate limiter refused the attempt. HTTP 429 page
STS-PORTAL-0003 An activation link was refused: the token is wrong, expired, already spent, or was never issued for that person. The four causes deliberately answer the same sentence. HTTP 400 page
STS-PORTAL-0004 The authenticator app setup started during an activation expired before its code was confirmed. HTTP 400 page
STS-PORTAL-0005 The one-time code typed to confirm an authenticator app during an activation did not verify. HTTP 400 page
STS-PORTAL-0006 An activation set a password whose confirmation did not match. HTTP 400 page
STS-PORTAL-0007 An activation chose no way to sign in: no password, and no security key used instead of one. HTTP 400 page
STS-PORTAL-0008 A new password set from the portal (at activation or on the password page) was refused by the password policy or could not be written. HTTP 400 page
STS-PORTAL-0009 An authenticator app was asked for during an activation and its enrolment could not be started; the activation finished without it. —
STS-PORTAL-0010 The access policy refused a signed-in person a portal page or action. HTTP 403 page
STS-PORTAL-0011 The portal could not start its OpenID Connect sign-in: the sts-user-portal client entry is missing or has no secret, or in product mode the portal was reached at an address not registered as a redirect URI. HTTP 503 page
STS-PORTAL-0012 The portal’s OpenID Connect callback could not complete a sign-in (a state, code, token or ID Token step failed). HTTP 400 page
STS-PORTAL-0013 The portal’s OpenID Connect callback threw unexpectedly. HTTP 500 page
STS-PORTAL-0014 The portal’s directory slot was offered a filler without personEntry() and was not installed; the Overview falls back to what the session carries. —
STS-PORTAL-0015 Reading the signed-in person’s directory entry for the Overview threw; the page fell back to what the session carries. —
STS-PORTAL-0016 The QR code for an authenticator app enrolment could not be rendered; the secret is offered for typing only. —
STS-PORTAL-0017 A portal form post was refused because its CSRF token was missing or did not match the session. HTTP 403 page
STS-PORTAL-0018 Confirming an authenticator app code was tried too often and the rate limiter refused the attempt. HTTP 429 page
STS-PORTAL-0019 A password change was tried too often and the rate limiter refused the attempt. HTTP 429 page
STS-PORTAL-0020 Self-service signing key generation was tried too often and the rate limiter refused it. HTTP 429 page
STS-PORTAL-0021 Removing the person’s own authenticator app was refused (there was none, or the store refused the write). HTTP 400 page
STS-PORTAL-0022 An authenticator app enrolment could not be started (the mechanism is off, or product mode will not enrol this person). HTTP 400 page
STS-PORTAL-0023 The code typed to confirm an authenticator app enrolment on /portal/mfa did not verify. HTTP 400 page
STS-PORTAL-0024 A set of recovery codes could not be generated for the signed-in person. HTTP 400 page
STS-PORTAL-0025 A confirmed set of recovery codes could not be stored (the pending set was gone or the write failed). HTTP 400 page
STS-PORTAL-0026 A portal form post named no action, or one its handler does not have. HTTP 400 page
STS-PORTAL-0027 Taking a signing key off was refused because the person holds none. HTTP 400 page
STS-PORTAL-0028 A person tried to issue themselves a signing key while pki.personSelfService is off. HTTP 403 page
STS-PORTAL-0029 The certificate authority could not issue a self-service signing key pair. HTTP 400 page
STS-PORTAL-0030 A self-service signing key pair was issued but could not be written to the person’s entry; the key pair is discarded. HTTP 500 page
STS-PORTAL-0031 A password change was refused because the current password did not verify. HTTP 400 page
STS-PORTAL-0032 A password change gave no new password, or a confirmation that did not match. HTTP 400 page
STS-PORTAL-0033 A security key enrolment could not be started (policy refused the role, the key limit was reached, or the mechanism is off). HTTP 400 page
STS-PORTAL-0034 A security key enrolment was finished with no WebAuthn ceremony result, usually because the browser ran no script. HTTP 400 page
STS-PORTAL-0035 A security key enrolment was refused because the configured WebAuthn RP ID does not fit the host the portal was reached at. HTTP 400 page
STS-PORTAL-0036 A security key enrolment’s registration response did not verify, or the key was refused on the write. HTTP 400 page
STS-PORTAL-0037 Removing one of the person’s own security keys was refused (no such key on their entry, or removing it would leave no way in). HTTP 400 page
STS-PORTAL-0038 The portal’s Shared Signals receive endpoint refused a push that carried no more specific code of its own (receivers off, no stream, wrong bearer token, empty or malformed token, wrong audience, or an unverified signature). SSF error JSON (HTTP 400, 401, 404, 500 or 501)
STS-PORTAL-0039 A person’s revocation of their own TLS client certificate was refused (a serial they hold no certificate under, or the revocation register refused it). HTTP 400 page
STS-PORTAL-0040 A TLS client certificate was asked for with a file password that is too short, too long, or not the same twice. HTTP 400 page
STS-PORTAL-0041 A self-service TLS client certificate could not be issued (no certificate authority, a refused key algorithm or label, or the cap reached). HTTP 400 page
STS-PORTAL-0042 A TLS client certificate was issued and its PKCS#12 and PEM files could not be built; the certificate was revoked at once. HTTP 500 page
STS-PORTAL-0047 A person’s own ACME account binding key or SCEP challenge password was not made on /portal/certificates (the enrollment core refused it; its own code is on the monitor row). HTTP 4xx page
STS-PORTAL-0048 A person asked /portal/certificates to delete an account binding key or challenge password they do not hold. HTTP 404 page
STS-PORTAL-0049 A person asked /portal/certificates to revoke a certificate they do not hold, or the revocation was refused. HTTP 404 or 400 page
STS-PORTAL-0050 A person asked /portal/certificates for an ACME or SCEP credential while that protocol is turned off in the realm. HTTP 403 page
STS-PORTAL-0051 A POST to /portal/certificates named no action the page performs. HTTP 400 page
STS-PORTAL-0070 A password reset link was refused by the rate limit. HTTP 429 page
STS-PORTAL-0071 A password reset link did not verify; the page answers one sentence for every reason. HTTP 400 page
STS-PORTAL-0072 A new password from a reset link was refused before it was tried: missing, not typed twice alike, or the reserved password. the reset form again, HTTP 400
STS-PORTAL-0073 A new password from a reset link was refused by the password policy or the store. the reset form again, HTTP 400
STS-PORTAL-0074 The realm chooser in front of /portal was asked for a realm that is not defined. HTTP 400 on /portal
STS-PORTAL-0075 An account holder asked for a RISC opt-out move the section 2.8 state diagram does not allow from where their account is, or RISC is off. HTTP 409, the page redrawn saying so
STS-PORTAL-0076 An account holder’s RISC opt-out move was not recorded: Shared Signals is not running in this process, so there was no register to move. HTTP 503, the page redrawn saying so
STS-PORTAL-0077 A person’s own app password was not made on /portal/app-passwords; the credential store’s code is on the audit row. HTTP 400 page
STS-PORTAL-0078 A person asked /portal/app-passwords to revoke an app password they do not hold. HTTP 404 page
STS-PORTAL-0079 A POST to /portal/app-passwords named an action the page does not have. HTTP 400 page
STS-PORTAL-0080 A keytab download on /portal/kerberos was refused because the password typed is not the person’s current one. HTTP 400 page
STS-PORTAL-0081 A keytab download on /portal/kerberos was refused by the Kerberos register after the password verified; its own STS-KRB code is on the audit row. HTTP 400 page
STS-PORTAL-0082 A POST to /portal/kerberos named an action the page does not have. HTTP 400 page
STS-PORTAL-0083 A POST to /portal/sign-ins was refused: its CSRF token did not match the session. HTTP 403 page
STS-PORTAL-0084 A POST to /portal/sign-ins named a sign-in that is not the person’s own, is too old, or has already been answered (#62 P6). HTTP 400 page
STS-PORTAL-0085 A POST to /portal/consents named no consent of the signed-in person’s own to withdraw — none held for that application and scope, or no scope named (#172). HTTP 400 page
STS-PORTAL-0086 A POST to /portal/delegate could not set or clear the signed-in person’s delegate (stsMayAct) (#108). HTTP 400 page
STS-PORTAL-0087 A POST to /portal/self-issued named a self-issued subject the signed-in person has not enrolled, or the directory did not store the removal (#129). HTTP 400 page
STS-PORTAL-0088 A POST to /portal/devices named a device the signed-in person does not own, or the directory did not remove it (#130). HTTP 400 page
STS-PORTAL-0089 A POST to /portal/ciba answered a CIBA request that is not waiting for the signed-in person (#131). HTTP 400 page
STS-PORTAL-0090 A CIBA user code set on /portal/ciba was refused — the wrong length, or not stored (#131). HTTP 400 page
STS-PORTAL-0091 An approval on /portal/ciba asked for more (acr_values) than the sign-on session proved; the person is offered a stronger sign-in (#131). HTTP 403 page
STS-PORTAL-0092 Turning an emailed second factor on or off on /portal/mfa was refused; the page names why (#64). HTTP 400 page
STS-PORTAL-0093 Linking a Claims Provider on /portal/claim-sources failed at its callback in a way no STS-OAUTH-0678 to 0685 code names (#147). none (a portal page, HTTP 500)
STS-PORTAL-0094 An unlink on /portal/claim-sources named a Claims Provider the person has no link to (#147). none (a portal page, HTTP 400)
STS-PORTAL-0095 A user code typed or approved on /portal/device matched no waiting device (#150). none (a portal page, HTTP 404 or 400)
STS-PORTAL-0096 A sign-on session typed too many user codes that matched nothing on /portal/device and is refused for ten minutes (RFC 8628 section 5.1, #150). none (a portal page, HTTP 429)
STS-PORTAL-0097 Answering a device sign-in on /portal/device failed unexpectedly (#150). none (a portal page, HTTP 500)
STS-PORTAL-0098 A live admin console session in the same browser was not adopted by /portal — it names nobody, the realm it was signed in through is no longer defined, its tokens ran out beyond renewal, or its person is homed in another cell — so the portal signs in the ordinary way. none (the portal runs its own sign-in)
STS-PORTAL-0099 Adopting a live admin console session on /portal threw; the portal signs in the ordinary way. none (the portal runs its own sign-in)
STS-PORTAL-0100 A security key was chosen during an activation beside a password and its enrolment could not be started; the activation went on without it. —
STS-PORTAL-0101 A security key was chosen during an activation instead of a password and its enrolment could not be started (the mechanism or role is off, or the authentication policy refuses it), so the activation was refused rather than finished with no way in. HTTP 400 page
STS-PORTAL-0102 An activation’s security key step did not register a key — the enrolment had expired, the browser ran no ceremony, the RP ID did not fit, or the registration did not verify — and the step was drawn again. HTTP 400 page
STS-PORTAL-0163 A POST to /portal/gnap named a GNAP grant that is not one the signed-in person approved, or one with nothing live left to revoke (#432). HTTP 400 page
STS-PORTAL-0243 A POST to /portal/ciba answered a GNAP access request that is not waiting for the signed-in person: answered already, run out, or somebody else’s (#432 phase 6). HTTP 400 page
STS-PORTAL-0244 A resource owner approved a GNAP access request on /portal/ciba with a session that does not meet the authentication level the rights need; the page offers to sign in again with it (#432 phase 6, RFC 9470). HTTP 403 page

STS-LOGOUT

Sign-out. The protocol-independent sign-out and the session inventory.

Raised from: logout/.

Code What failed Client sees
STS-LOGOUT-0001 A sign-out named somebody other than the caller while naming another person is closed (logout.anyUser off, or product mode). HTTP 403 {error: forbidden} or a 403 page
STS-LOGOUT-0002 A sign-out request carried no session cookie and named nobody, so there is nobody to act on. (A browser GET is sent to sign in instead, which is not a failure.) HTTP 401 {error: no_subject} or a 401 page
STS-LOGOUT-0003 A sign-out form failed validation (an unrecognised scope value, or an over-long selection). HTTP 400 page
STS-LOGOUT-0004 One family’s live items could not be read for a sign-out inventory; the page reports that family as unreadable. —
STS-LOGOUT-0005 One family’s live items could not be read while a sign-out was ending them, so nothing in that family was ended. —
STS-LOGOUT-0006 Ending one live item during a sign-out failed with an exception; it is reported as not ended. —
STS-LOGOUT-0007 A sign-out ended nothing: nothing live was found for the identity, or nothing that was selected could be ended. —

STS-REG

Registries. The application registry, consent, delegated permissions, the delegation register, the statistics and the claim configuration.

Raised from: common/applications.js, common/consent.ts, common/app_permissions.ts, common/delegation.js, common/admin_stats.js, common/audit.js, common/claim_attributes.ts, common/group_claims.ts, common/user_graph.ts, common/credential_graph.ts, common/inetorgperson.ts.

Code What failed Client sees
STS-REG-0001 An application identifier was empty, longer than 512 characters, or contained a line break or NUL. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0002 The application registry has no store: no directory is loaded in this process, so nothing can be created, deleted, registered or seeded. the caller’s refusal (errors on a console or /admin-api reply), where there is a caller
STS-REG-0003 An application was created with an identifier that is already in the registry. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0004 An application was created with a kind the registry does not know. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0005 An application was declared for a protocol family the registry does not know. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0006 An attribute not in the published application schema was written. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0007 A DERIVED application attribute (a counter or a sighting) was written by hand. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0008 An application attribute was written against its cardinality: several values for a single-valued one, or set where add/remove applies (or the reverse). the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0009 An add or remove on an application attribute carried no value. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0010 An attribute scoped to certain protocol families was written onto an application not declared for any of them. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0011 An application home page was not an absolute http or https URL. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0012 A permission base URI was not absolute. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0013 A delegated permission name was not usable. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0014 A delegated permission was defined that the application already defines. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0015 A delegated permission was defined on an application with no permission base URI. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0016 A delegated permission was granted that no application defines. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0017 An application was granted a delegated permission it defines itself. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0018 A global consent value was not an RFC 6749 scope token. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0019 An application’s private key could not be sealed under the key-encryption key, so it was not stored. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0020 The directory would not take an application entry: ou=applications is full (applications.max) or the directory refused the write. the caller’s refusal where there is one; a protocol exchange carries on
STS-REG-0021 An application was named that is not in the registry. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0022 The directory would not delete an application entry. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0023 An application’s sealed private key will not open under this process’s key-encryption key; it was written under a different one. —
STS-REG-0024 An application’s stored RFC 7591 registration document is not valid JSON; the registration is rebuilt from its attributes. —
STS-REG-0025 An application carries a per-application setting override that does not parse; the service-wide setting is used instead. —
STS-REG-0026 Two or more applications claim one identifier (an audience, a client_id, a permission base URI or an AppliesTo); the first found is used. —
STS-REG-0027 A delegated permission was removed that the application does not define. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0028 The consent register was offered a directory missing one of its four functions, so no consent can be recorded. —
STS-REG-0029 A consent could not be recorded, revoked or forgotten because no directory is installed. the caller’s refusal (errors on a console or /admin-api reply); the consent screen asks again
STS-REG-0030 A consent was agreed and the directory did not write it down (no entry for the person, most often); the person is asked again next time. —
STS-REG-0031 A consent revoke or forget did not name the person, application and scope it needs. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0032 A consent was revoked or forgotten that is not on the person’s entry. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0033 A delegation act could not be recorded; the protocol exchange carried on and the act is missing from /admin/delegation. —
STS-REG-0034 A claim set was named that does not exist. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0035 A claim-attribute selection named an attribute that is not in the catalogue. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0036 A typed custom claim was given with no name. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0037 A typed custom claim was given a name this service sets itself. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0038 A typed custom claim name was configured twice in one set. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0039 The directory’s user observer threw while being told about an authentication, an enrolment, an issuance or a credential status change; the event stands and the directory entry may not reflect it. —
STS-REG-0040 A SCIM request could not be counted; /admin/scim/monitor under-reports it. —
STS-REG-0041 The application registry threw while recording an authentication; the authentication stands and the application entry does not show it. —
STS-REG-0042 The claim-attribute resolver threw during issuance; the token or assertion is issued without its configured attribute claims. —
STS-REG-0043 The group-claim resolver threw during issuance; the token or assertion is issued without its groups claim. —
STS-REG-0044 The role register threw during issuance; the token or assertion is issued without its roles claim. —
STS-REG-0045 The directory could not be read for the groups claim; the token or assertion is issued without it. —
STS-REG-0046 groups.claimName is empty or names a claim this service sets itself, so tokens and assertions are issued without the groups claim that is switched on. —
STS-REG-0047 The audit log’s actor resolver threw while naming the signed-in user for an HTTP row; the row is recorded with no actor. —
STS-REG-0048 An audit event could not be recorded and was dropped; the operation it describes went ahead regardless. —
STS-REG-0049 In product mode, a return address (a SAML ACS URL or shire, a WS-Federation wreply, or the console’s or portal’s own callback) is on the application’s entry but still marked as OBSERVED — a development-mode request put it there and nobody confirmed it — so it was refused as unregistered. the family’s own refusal for an unregistered address: an HTTP 400 page for SAML 2.0, SAML 1.1 and WS-Federation; the console’s or portal’s sign-in refusal page
STS-REG-0050 A confirm-address or discard-address named an address that is not marked as observed on that attribute of the entry. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0051 A confirm-address or discard-address named an attribute that is not a return-address attribute. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0052 A confirm-address or discard-address carried no address. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0053 An ssfAllowedEvents value was neither caep, risc nor an event type URI this transmitter knows. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0060 A write of oauthAssertionKeySource or oauthSamlAssertionKeySource named a value outside issued, uploaded-realm-ca and uploaded-external-ca. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0061 Regenerating the client secret of sts-management-api was refused because adminApi.clientSecret pins it. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0070 A client registration (RFC 7591 or 7592) named a redirect_uri, post_logout_redirect_uri, frontchannel_logout_uri or backchannel_logout_uri that is not a usable address — not http(s) with a host, not a private-use scheme named for a domain, or (for the two logout URIs) not http(s). invalid_redirect_uri or invalid_client_metadata (HTTP 400)
STS-REG-0071 A console or /admin-api write put an unusable address on oauthRedirectUri, oauthPostLogoutRedirectUri, oauthFrontchannelLogoutUri or oauthBackchannelLogoutUri. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0072 An RFC 7591 registration or RFC 7592 update named an RFC 9701 introspection_signed_response_alg, introspection_encrypted_response_alg or introspection_encrypted_response_enc this service cannot honour, or an enc with no alg. invalid_client_metadata (HTTP 400)
STS-REG-0073 A console or /admin-api write put an unusable RFC 9701 algorithm on oauthIntrospectionSignedResponseAlg, oauthIntrospectionEncryptedResponseAlg or oauthIntrospectionEncryptedResponseEnc, or an enc on an entry with no alg. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0074 An RFC 9728 protected resource metadata import named no document: nothing pasted, nothing uploaded and no URL. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0075 An RFC 9728 import gave the document more than one way (pasted, uploaded and a URL are exclusive). the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0076 An RFC 9728 document was empty, too large (federation.maxResponseBytes), not JSON, not a JSON object, or refused by the JSON document walk. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0077 An RFC 9728 document is malformed: resource missing, not a URL or carrying a fragment, or a member of the wrong JSON type. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0078 An RFC 9728 document was to be fetched by URL and federation.outbound is off. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0079 The URL an RFC 9728 document was to be fetched from is not a URL, or not https while plain http is refused (federation.outboundAllowHttp off, or product mode). the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0080 In product mode, the host of an RFC 9728 document URL resolves to a loopback, private, link-local or reserved address. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0081 The host of an RFC 9728 document URL could not be resolved. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0082 The RFC 9728 document URL answered with a redirect, which is not followed. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0083 The RFC 9728 document URL answered a status other than 200. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0084 The RFC 9728 document fetched by URL was larger than federation.maxResponseBytes. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0085 The RFC 9728 document URL did not answer within federation.outboundTimeoutMs. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0086 The request for an RFC 9728 document failed at the connection (refused, reset, a certificate this service does not trust). the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0087 In product mode, a fetched RFC 9728 document’s resource is not the identifier its well-known URL was built from (section 3.3). the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0088 In product mode, an RFC 9728 document’s resource is not an https URL (section 2). the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0089 A console or /admin-api write put an unusable value on oauthResourceMetadata (not a JSON object with a resource) or oauthResourceMetadataUrl (not an http or https URL). the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0090 oauthRoleGatedPermission named a permission the application does not define in oauthPermission; only its own permissions can be gated by role (#303). none (a console or management API refusal, HTTP 400)
STS-REG-0100 An RFC 7591 registration or RFC 7592 update named request_uris, request_object_signing_alg, request_object_encryption_alg, request_object_encryption_enc or require_signed_request_object this service cannot honour. invalid_client_metadata (HTTP 400)
STS-REG-0101 A console or /admin-api write put an unusable value on oauthRequestUri, oauthRequestObjectSigningAlg, oauthRequestObjectEncryptionAlg, oauthRequestObjectEncryptionEnc or oauthRequireSignedRequestObject. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0110 An RFC 7591 registration or RFC 7592 update gave authorization_details_types a value that is not an array of type names (RFC 9396 section 10). invalid_client_metadata (HTTP 400)
STS-REG-0111 A console or /admin-api write put a value on oauthAuthorizationDetailsTypes that is not a type name. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0112 A console or /admin-api write put an unusable authorization_details type definition on oauthAuthorizationDetailsType: not a name or a JSON object, a stray member, a location that is not an absolute URI, a schema that does not compile, or the built-in openid_credential. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0120 An RFC 7591 registration or RFC 7592 update gave require_pushed_authorization_requests a value that is not a boolean. invalid_client_metadata (HTTP 400)
STS-REG-0121 A console or /admin-api write put a value other than TRUE or FALSE on oauthRequirePushedAuthorizationRequests. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0130 A registration gave an RFC 8705 certificate subject parameter a value that is not what it names (a DN, host name, URI, IP address or mailbox). invalid_client_metadata (HTTP 400)
STS-REG-0131 A registration gave more than one of RFC 8705 section 2.1.2’s five certificate subject parameters. invalid_client_metadata (HTTP 400)
STS-REG-0132 A registration gave tls_client_certificate_bound_access_tokens a value that is not a boolean. invalid_client_metadata (HTTP 400)
STS-REG-0133 A registration asked for certificate-bound access tokens while the main port is not TLS, so no token could be bound. invalid_client_metadata (HTTP 400)
STS-REG-0134 A console or /admin-api write gave an RFC 8705 certificate subject attribute a value that is not what it names. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0135 A console or /admin-api write set a second RFC 8705 certificate subject attribute beside the one the entry holds. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0136 A console or /admin-api write put a value other than TRUE or FALSE on oauthTlsClientCertificateBoundAccessTokens. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0140 A console or /admin-api write put a value on oauthStepUpAcrValues that cannot be an acr value. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0141 A console or /admin-api write put a value on oauthStepUpMaxAge that is not a whole number of seconds. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0150 A console or /admin-api write put a value on appCorsOrigin that is not an exact origin — a path, a wildcard, null, a user name, or no host. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0160 A SAML signing certificate (samlSigningCertificate or samlSpMetadataSigningCertificate, or an observed one being confirmed) is not an X.509 certificate whose key makes an XML signature this service verifies (RSA, EC, EdDSA, DSA, ML-DSA, SLH-DSA), so nothing was written. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0161 Consuming SAML metadata tried to write an attribute that is not one of the metadata fields — a programming error, refused. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0162 The application entry would not take the consumed SAML metadata (the directory refused the write). the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0163 A confirm or discard of a SAML service provider’s observed signing certificate found none on the entry. the caller’s refusal (errors on a console or /admin-api reply)
STS-REG-0164 An RFC 7591 registration or RFC 7592 update named an id_token_encrypted_response_alg or _enc this service cannot honour (a symmetric family, an unknown content encryption), or an enc with no alg. invalid_client_metadata (HTTP 400)
STS-REG-0165 A registration named id_token_encrypted_response_alg with no inline jwks key of the right type to encrypt to (a jwks_uri is never fetched). invalid_client_metadata (HTTP 400)
STS-REG-0166 Every client secret an application holds has expired, or one expires within oauth2.clientSecretExpiryWarningDays — found by the daily scheduler job oauth2.client-secret-expiry. none — an audit row and a warning; rotate the secret on /admin/applications
STS-REG-0167 A client registration named a subject_type, sector_identifier_uri or token_endpoint_auth_signing_alg this service cannot honour (OIDC Core sections 8 and 9). HTTP 400 {error: invalid_client_metadata}
STS-REG-0168 A console or /admin-api write set oauthSubjectType, oauthSectorIdentifierUri or oauthTokenEndpointAuthSigningAlg to a value this service cannot honour. HTTP 400
STS-REG-0169 A registered sector_identifier_uri could not be fetched, was not a JSON array of URIs, or did not list every redirect_uri (OIDC Core section 8.1). HTTP 400 {error: invalid_client_metadata}
STS-REG-0170 A client registration named a frontchannel_logout_uri whose scheme, host and port match none of its redirect_uris (Front-Channel Logout 1.0 section 2). HTTP 400 {error: invalid_client_metadata}
STS-REG-0171 A console or /admin-api write set oauthFrontchannelLogoutUri to a URI whose scheme, host and port match none of the entry’s oauthRedirectUri values (Front-Channel Logout 1.0 section 2). HTTP 400
STS-REG-0172 A console or /admin-api write put a value on oauthAllowedScope that is not an RFC 6749 section 3.3 scope token. HTTP 400
STS-REG-0173 An RFC 7591 registration or RFC 7592 update named one of this service’s own protected scopes in scope (or sent a scope that is not a string); only an administrator declares those. invalid_client_metadata (HTTP 400)
STS-REG-0174 Under a FAPI profile, a registration declared a token_endpoint_auth_method FAPI does not allow (FAPI 1.0 Part 1 section 5.2.2 item 4). HTTP 400 {error: invalid_client_metadata}
STS-REG-0175 Under a FAPI profile, a registration’s jwks held an RSA key under 2048 bits or an EC key under 160 (FAPI 1.0 Part 1 section 5.2.2 items 5 and 6). HTTP 400 {error: invalid_client_metadata}
STS-REG-0176 Under a FAPI profile, a registration named a redirect URI that is not https (FAPI 1.0 Part 1 section 5.2.2 item 20). HTTP 400 {error: invalid_redirect_uri}
STS-REG-0177 Under FAPI 1.0 Advanced, a registration named a signing algorithm other than PS256 or ES256, or the RSA1_5 encryption algorithm (Part 2 sections 8.6 and 8.6.1). HTTP 400 {error: invalid_client_metadata}
STS-REG-0178 Under FAPI 1.0 Advanced, a registration named a response type other than code id_token or code (Part 2 section 5.2.2 item 2). HTTP 400 {error: invalid_client_metadata}
STS-REG-0179 A registration’s JARM members were malformed: authorization_signed_response_alg not an algorithm this service signs with (none included), an encryption alg that is not one of the asymmetric families, or an enc without an alg (JARM section 3). HTTP 400 {error: invalid_client_metadata}
STS-REG-0180 A registration named authorization_encrypted_response_alg and its jwks holds no key to encrypt its authorization responses to (JARM section 3). HTTP 400 {error: invalid_client_metadata}
STS-REG-0181 A registration named an application_type other than web or native (OpenID Connect Registration section 2) (#120). HTTP 400 {error: invalid_client_metadata}
STS-REG-0182 A redirect URI does not suit the application_type: a native client’s must be a loopback http URL or a private-use scheme, a web client using the implicit grant’s must be https and not localhost (OpenID Connect Registration section 2) (#120). HTTP 400 {error: invalid_redirect_uri}
STS-REG-0183 grant_types and response_types disagree (RFC 7591 section 2.1): a response type needs the grant that redeems it (#120). HTTP 400 {error: invalid_client_metadata}
STS-REG-0184 A client registered for authorization_code or implicit named no redirect_uris (#120). HTTP 400 {error: invalid_client_metadata}
STS-REG-0185 id_token_signed_response_alg or userinfo_signed_response_alg names an algorithm this service does not sign with (#120). HTTP 400 {error: invalid_client_metadata}
STS-REG-0186 A registration carried jwks together with jwks_uri, or a jwks_uri that is not https (RFC 7591 section 2) (#120). HTTP 400 {error: invalid_client_metadata}
STS-REG-0187 default_max_age, require_auth_time or default_acr_values is not of its type (OpenID Connect Registration section 2) (#120). HTTP 400 {error: invalid_client_metadata}
STS-REG-0188 initiate_login_uri is not an https URL (OpenID Connect Registration section 2) (#120). HTTP 400 {error: invalid_client_metadata}
STS-REG-0189 A backchannel_logout_uri with the http scheme for a public client: Back-Channel Logout 1.0 section 2.2 allows http only to a confidential one (#123). At registration, a create and an attribute write. HTTP 400 {error: invalid_client_metadata}
STS-REG-0190 A backchannel_logout_uri the outbound policy would not dial (http with federation.outboundAllowHttp off, or in product mode): every delivery would be dead-lettered, so it is refused where it is written (#123). HTTP 400 {error: invalid_client_metadata}
STS-REG-0191 A generic application edit tried to remove a value of oauthGlobalConsent. A global consent is withdrawn only through the consent register (revoke-global-consent), which also revokes what was issued under it and records when (#172). HTTP 400 page / {ok: false}
STS-REG-0192 A consent was withdrawn and its tokens revoked, but the withdrawal instant could not be written onto the person’s or the application’s entry, so a re-consent could revive a refresh token the revocation did not reach (#172). none — logged
STS-REG-0193 A write setting an application’s override of a development-only setting — saml2SignAssertion, saml11SignAssertion or saml11SignResponse to FALSE, or saml2KeyTransportAlgorithm to rsa-1_5 — was refused because the realm is in product mode, where the value would be ignored (#181). console: the page’s error list; /admin-api: HTTP 400 { ok: false, errors }
STS-REG-0194 A write of a delegation policy attribute was refused (#108): appNotDelegated that is not TRUE or FALSE, delegation semantics that are neither delegation nor impersonation (#186), or an appDelegationSubjectGroup value that is not a DN. console: the page’s error list; /admin-api: HTTP 400
STS-REG-0195 A write of gnapMtlsTrust on an application was refused: the value is neither pki nor pinned (#107). console: the page’s error list; /admin-api: HTTP 400
STS-REG-0196 A write of gnapMtlsTrust=pinned on an application was refused because the realm holds GNAP mutual TLS to a PKI (gnap.mtlsTrust resolves to pki); an entry may be stricter than the realm, never weaker (#107). console: the page’s error list; /admin-api: HTTP 400
STS-REG-0197 A registration’s CIBA metadata was refused: an unknown backchannel_token_delivery_mode, no https notification endpoint for ping or push, a signing algorithm that is not asymmetric, or a user code parameter that is not a boolean (#131). invalid_client_metadata (HTTP 400)
STS-REG-0198 FAPI-CIBA: a registration under a FAPI profile asked for the push delivery mode, which the profile does not allow (#142). invalid_client_metadata (HTTP 400)
STS-REG-0199 A command_endpoint (OpenID Provider Commands, #151) was not an https URL with no fragment, at registration or update (a console or API write is refused under STS-REG-0071). HTTP 400 {error: invalid_client_metadata}
STS-REG-0200 A claim-set attribute claim named an attribute it may not carry: not an attribute name, a secret or binary value (userPassword, jpegPhoto, a certificate), or one this service keeps (sts, hoba, app, pwd) (#94). HTTP 400 (console and API)
STS-REG-0201 A JWT or UserInfo attribute claim named a type that is not string, number, boolean or json (#94). HTTP 400 (console and API)
STS-REG-0202 A per-receiver Shared Signals override on an application entry was given a value its setting does not take, or a reason language that is not a BCP 47 tag. HTTP 400 (console and API)
STS-REG-0203 An application attribute whose values are a closed set (the token endpoint authentication method, a CIBA delivery mode or signing algorithm, a GNAP key proof, algorithm, start mode or token format) was given a value outside it. HTTP 400 (console and API)
STS-REG-0204 A DID document value was refused: a didPublicKeyJwk that is not a public EC, OKP, RSA or AKP JWK (a private member is refused), a didService that is not |<http(s) URL>, or a didAlsoKnownAs that is not an absolute URI. none (a console or management API refusal, HTTP 400)
STS-REG-0205 An application carries its own claim or SAML attribute rows (oauthClaims*, saml2CustomAttributes, saml11CustomAttributes) that are not a JSON array or that the claim-set rules refuse; they are ignored at issuance and the realm’s set is issued. none (logged at issuance; nothing is refused)
STS-REG-0206 An application’s own custom claim or SAML attribute was refused: an unknown claim set, a row the claim-set rules refuse (a reserved name, an attribute that may not be released, a type that is not one), a name to remove that it does not hold, or an application not declared for the set’s protocol. none (a console or management API refusal, HTTP 400)
STS-REG-0207 An application’s token endpoint authentication methods (oauthTokenEndpointAuthMethod) were refused: “none” declares a public client and cannot be held beside any other method. none (a console or management API refusal, HTTP 400)
STS-REG-0208 A client secret was not added or rotated in: the application already holds oauth2.clientSecretsMax secrets. Remove one first. none (a console or management API refusal, HTTP 400)
STS-REG-0209 A client secret was not removed: no secret on the application has the id named. none (a console or management API refusal, HTTP 400)
STS-REG-0210 The client secret pinned by adminApi.clientSecret on sts-management-api was not removed: every /admin-api token is minted with it. none (a console or management API refusal, HTTP 400)
STS-REG-0211 A client secret was not added: its lifetime or description is not one this service accepts. none (a console or management API refusal, HTTP 400)
STS-REG-0212 A sealed client secret will not open under this process’s key-encryption key — it was written under a different one — so it authenticates nothing until it is replaced. none (logged; the token endpoint answers invalid_client)
STS-REG-0213 A client secret could not be sealed, so it was not written: storing it in the clear where keys persist would put a working client credential in every directory dump. none (a console or management API refusal, HTTP 400)
STS-REG-0294 An access type was not declared on an application: no such application, or the definition built from the fields does not read (the access-type catalogue’s grammar, #432). none (a console or management API refusal, HTTP 400)
STS-REG-0295 An access type could not be taken off an application: it declares no type of that name (#432). none (a console or management API refusal, HTTP 400)
STS-REG-0334 A gnapOwnerLookupUri is not an https URL template with a host, no user information, query or fragment, and {identifier} exactly once as a whole path segment (#432 phase 5). none (a console or management API refusal, HTTP 400)

STS-DBG

Protocol debugger. The embedded identity protocol debugger: its listener, its sign-in, the access token its api requires, the permission that token carries, and the api process it forwards to.

Raised from: debugger/, and the debugger scope rule in oauth-oidc/oauth2.ts.

Code What failed Client sees
STS-DBG-0001 The debugger permission was asked for by somebody who may not hold it — not a person, not signed in, not in the default realm, or not a console administrator — and was left off the token. none — the token is issued without that scope (RFC 6749 section 3.3)
STS-DBG-0002 A request to the debugger carried no debugger session and no bearer token, and was not a page a browser could be sent to sign in from. HTTP 401 with WWW-Authenticate: Bearer
STS-DBG-0003 A debugger access token did not verify against the default realm’s signing key, or could not be read. HTTP 401 invalid_token
STS-DBG-0004 A debugger access token had expired. HTTP 401 invalid_token
STS-DBG-0005 A token presented to the debugger was not a JWT access token (typ at+jwt). HTTP 401 invalid_token
STS-DBG-0006 A debugger access token was issued by somebody other than this service’s default authorization server. HTTP 401 invalid_token
STS-DBG-0007 A debugger access token was addressed to a different audience. HTTP 403 insufficient_scope
STS-DBG-0008 A debugger access token did not carry the debugger permission. HTTP 403 insufficient_scope
STS-DBG-0009 The access policy refused the debugger to the token’s subject — ordinarily because they no longer hold a console role. HTTP 403 page or JSON
STS-DBG-0010 The debugger’s api process is not running, so an /api call could not be forwarded. HTTP 502
STS-DBG-0011 Forwarding an /api call to the debugger’s api process failed or timed out. HTTP 502 or 504
STS-DBG-0012 An /api request body was larger than debugger.maxRequestBytes. HTTP 413
STS-DBG-0013 The debugger’s api process exited or did not report that it was listening in time. none — logged; it is forked again
STS-DBG-0014 The debugger’s api process failed to start debugger.restartLimit times in a row and was given up on. none — logged; /api answers 502
STS-DBG-0015 The debugger was enabled and its built UI or api was not where debugger.uiDirectory or debugger.apiDirectory says, so it was not started. none — logged and shown on /admin/debugger
STS-DBG-0016 The debugger listener could not bind its port. none — logged and shown on /admin/debugger
STS-DBG-0017 The debugger could not start a sign-in: its client is missing from the registry, or the address it was reached at is not a registered redirect URI in product mode. HTTP page (500 or 403)
STS-DBG-0018 The debugger’s sign-in callback refused what the authorization server sent back. HTTP 400 page
STS-DBG-0019 A signed-in administrator asked the debugger for a path it does not serve. HTTP 404
STS-DBG-0020 An entry in debugger.allowedDestinations is not a CIDR range and was left out of the allow-list. none — logged at startup
STS-DBG-0021 A sign-out from the debugger did not carry the session’s CSRF token. HTTP 403 page
STS-DBG-0022 A method other than GET or HEAD was sent to the debugger’s static pages. HTTP 405
STS-DBG-0023 The /admin/debugger page or GET /admin-api/debugger could not build its report. HTTP 500 page or JSON
STS-DBG-0024 The debugger permission was refused because neither console role group has a member: the empty-roster rule that opens the console to everybody does not open the debugger. none at issuance (the scope is left off); HTTP 403 at the debugger
STS-DBG-0030 A certificate-bound access token (RFC 8705 cnf x5t#S256) was presented to the debugger on a connection without that certificate. invalid_token (HTTP 401)
STS-DBG-0031 A DPoP-bound access token (cnf.jkt) was presented to the debugger as a Bearer token. invalid_token (HTTP 401)
STS-DBG-0032 A DPoP proof presented to the debugger did not verify, and the proof check reported no code of its own. invalid_dpop_proof (HTTP 401)
STS-DBG-0033 Product mode: the debugger permission was refused to the bootstrap administrator because it has not yet claimed the console with its password; until it has, its roles are honoured at the console alone, from a password sign-in (#103). none at issuance (the scope is left off); HTTP 403 at the debugger

Adding a code

This page is generated. A new failure is a row in the CODES table in common/error_codes.js, a mark(), errorCode or tag() where the failure is detected, and node common/error_codes.js --docs. The test suite fails until all three are done.