Source: schemas/wire_error.schema.json

Generated automatically from the published contract sources.

Source path: schemas/wire_error.schema.json.

Schema fields

JSON pointer Description and constraints
"" (root) Every refusal the management plane returns (MAPI-10 in the management API contract) takes this shape, whose base members are six. They are the contract version, a machine-readable slug, the action where one is in question, a human detail, the reference the action dispatcher minted for the call, and help, the address of the refusal's row on the refusals page. Beyond them it carries the members the refusal's row of wire_errors.json names under members (MAPI-15), each admitted under the refusals whose rows name it and under no other, and none required. The declarations after the base six and the conditionals are generated from those rows and never written apart from them. MAN-12's named-refusal discipline, applied to the plane itself.

$schema: https://json\-schema\.org/draft/2020\-12/schema
version: 2026-10-07.1
title: Turn Zero Cloud — wire error shape, contract version 1
Type: object
Additional properties: false
Required fields: ["contract_version","error"]
/properties/contract_version MAPI-02: the version, stated in every exchange — refusals included.

Required value: 1
/properties/error The machine-readable refusal: not_yet_provisioned, unknown_action, method_not_allowed, and the slugs each action's implementation adds.

Type: string
Pattern: ^[a-z][a-z0-9_]*$
/properties/action The action in question, where one is.

Type: string
Pattern: ^[a-z][a-z0-9_]*$
/properties/detail The human sentence; never required to be machine-parsed.

Type: string
/properties/reference The short reference the action dispatcher minted for the call: ten lowercase hexadecimal characters, carried by every refusal the dispatcher answers and written to the call’s record row, so a report that quotes it is checked against the platform’s own record. Admitted on every refusal and required on none.

Type: string
Pattern: ^[0-9a-f]{10}$
/properties/help The address of the refusal's row on the refusals page, <origin>/cloud/reference/refusals/#<refusal name>, on the estate's public origin, the production origin standing in for a loopback or http one. It is carried by every refusal the action dispatcher answers to a dispatched call and by the unknown_action, method_not_allowed, and not_yet_provisioned refusals the actions routes answer before dispatch. Admitted on every refusal and required on none.

Type: string
/properties/accounts
/properties/admitted
/properties/application
/properties/audience
/properties/bound
/properties/ceiling
/properties/client_secret_name
/properties/configured_tenant
/properties/creation
/properties/credential_kind
/properties/entry
/properties/environment
/properties/expected_sha256
/properties/file
/properties/gap
/properties/grant
/properties/incoming_closure_hash
/properties/level
/properties/measure
/properties/missing
/properties/path
/properties/plan
/properties/posture
/properties/quantity
/properties/received_sha256
/properties/refusal
/properties/region
/properties/schedules
/properties/scope
/properties/served_closure_hash
/properties/sign_in_methods
/properties/space
/properties/standing
/properties/tenant
/properties/value
/properties/version
/properties/violations
/allOf/0
/allOf/0/if Required fields: ["error"]
/allOf/0/if/properties/error Required value: account_credential_required
/allOf/0/then
/allOf/0/then/properties/scope The bound of the token presented: a token minted for one application, under which halting production is refused.

Type: object
/allOf/0/then/properties/scope/properties/kind The kind of bound, always application here.

Type: string
/allOf/0/then/properties/scope/properties/application The id of the application the token is bounded to.

Type: string
/allOf/1
/allOf/1/if Required fields: ["error"]
/allOf/1/if/properties/error Required value: account_not_synthetic
/allOf/1/then
/allOf/1/then/properties/accounts The account ids the request named that stand and are not synthetic, as the caller wrote them. The list is never empty.

Type: array
/allOf/1/then/properties/accounts/items Type: string
/allOf/2
/allOf/2/if Required fields: ["error"]
/allOf/2/if/properties/error Required value: account_outside_batches
/allOf/2/then
/allOf/2/then/properties/accounts The account ids the request named that lie in no batch the caller's own credential seeded, as the caller wrote them. The list is never empty. The member is left out where the request repeated a request_id another credential's purge carries.

Type: array
/allOf/2/then/properties/accounts/items Type: string
/allOf/2/then/properties/grant The synthetic grant that bounds the caller's credential, present on the purge's refusal.

Type: string
Pattern: ^[a-z][a-z0-9_]*$
/allOf/3
/allOf/3/if Required fields: ["error"]
/allOf/3/if/properties/error Required value: binding_refused
/allOf/3/then
/allOf/3/then/properties/application The id of the application the standing upstream of that name is bound to, which is not the application this declaration named.

Type: string
/allOf/4
/allOf/4/if Required fields: ["error"]
/allOf/4/if/properties/error Required value: creation_contradicts_audience
/allOf/4/then
/allOf/4/then/properties/audience The audience the application's manifest declares, invited at this refusal.

Type: string
/allOf/4/then/properties/creation The creation mode the call named, open at this refusal.

Type: string
/allOf/5
/allOf/5/if Required fields: ["error"]
/allOf/5/if/properties/error Required value: custody_entry_missing
/allOf/5/then
/allOf/5/then/properties/client_secret_name The secret name the call, or the manifest's realm member, gave as the work-account client secret, the Apple signing key, or the push provider credential, for which custody holds no entry at the application's scope.

Type: string
/allOf/5/then/properties/application The id of the application whose realm the call, the submission, or create_environment configures, and at whose scope the entry was looked up.

Type: string
/allOf/6
/allOf/6/if Required fields: ["error"]
/allOf/6/if/properties/error Required value: declared_audience_contradicts_route
/allOf/6/then
/allOf/6/then/properties/audience The audience the submitted manifest declares, invited at this refusal.

Type: string
/allOf/6/then/properties/environment The environment whose standing realm names the work-account route, development or production, the first one found.

Type: string
/allOf/6/then/properties/sign_in_methods The sign-in methods that realm is configured with, the work-account route entra among them.

Type: array
/allOf/6/then/properties/sign_in_methods/items Type: string
/allOf/7
/allOf/7/if Required fields: ["error"]
/allOf/7/if/properties/error Required value: declared_tenant_contradicts_route
/allOf/7/then
/allOf/7/then/properties/tenant The Entra tenant the submitted manifest declares under the workforce audience.

Type: string
/allOf/7/then/properties/configured_tenant The Entra tenant the work-account route of that environment's realm is configured against.

Type: string
/allOf/7/then/properties/environment The environment whose standing realm's work-account route names another tenant, development or production, the first one found.

Type: string
/allOf/8
/allOf/8/if Required fields: ["error"]
/allOf/8/if/properties/error Required value: egress_key_not_admitted
/allOf/8/then
/allOf/8/then/properties/credential_kind The kind of the credential refused, egress_key at this refusal.

Type: string
/allOf/9
/allOf/9/if Required fields: ["error"]
/allOf/9/if/properties/error Required value: end_user_credential_not_admitted
/allOf/9/then
/allOf/9/then/properties/credential_kind The kind of the credential refused, end_user at this refusal.

Type: string
/allOf/10
/allOf/10/if Required fields: ["error"]
/allOf/10/if/properties/error Required value: feedback_queue_bounded
/allOf/10/then
/allOf/10/then/properties/grant The grant that bounds the credential presented.

Type: string
Pattern: ^[a-z][a-z0-9_]*$
/allOf/10/then/properties/admitted The actions the bound admits, in the enumeration's order: the rows the grant marks and the rows whose admits mark names it. The rows marked access: anonymous lie outside the bound and are not listed.

Type: array
/allOf/10/then/properties/admitted/items Type: string
/allOf/11
/allOf/11/if Required fields: ["error"]
/allOf/11/if/properties/error Required value: grant_not_held
/allOf/11/then
/allOf/11/then/properties/grant The requested grant the minting session does not itself hold.

Type: string
Pattern: ^[a-z][a-z0-9_]*$
/allOf/12
/allOf/12/if Required fields: ["error"]
/allOf/12/if/properties/error Required value: grant_required
/allOf/12/then
/allOf/12/then/properties/grant The grant the action requires and the credential does not hold.

Type: string
Pattern: ^[a-z][a-z0-9_]*$
/allOf/13
/allOf/13/if Required fields: ["error"]
/allOf/13/if/properties/error Required value: grant_scope_refused
/allOf/13/then
/allOf/13/then/properties/grant The grant requested for an application-bounded token, which carries neither super_admin nor a narrow grant.

Type: string
Pattern: ^[a-z][a-z0-9_]*$
/allOf/14
/allOf/14/if Required fields: ["error"]
/allOf/14/if/properties/error Required value: invited_realm_refuses_work_account
/allOf/14/then
/allOf/14/then/properties/creation The creation mode the realm would enforce after the call, invited at this refusal.

Type: string
/allOf/14/then/properties/audience The audience the application's recorded manifest declares: public, invited, or workforce.

Type: string
/allOf/15
/allOf/15/if Required fields: ["error"]
/allOf/15/if/properties/error Required value: issue_refused
/allOf/15/then
/allOf/15/then/properties/refusal The issue service's own refusal name, one the Issue Tracking contract states.

Type: string
/allOf/16
/allOf/16/if Required fields: ["error"]
/allOf/16/if/properties/error Required value: issues_bounded
/allOf/16/then
/allOf/16/then/properties/grant The grant that bounds the credential presented.

Type: string
Pattern: ^[a-z][a-z0-9_]*$
/allOf/16/then/properties/admitted The actions the bound admits, in the enumeration's order: the rows the grant marks and the rows whose admits mark names it. The rows marked access: anonymous lie outside the bound and are not listed.

Type: array
/allOf/16/then/properties/admitted/items Type: string
/allOf/17
/allOf/17/if Required fields: ["error"]
/allOf/17/if/properties/error Required value: issues_level_refused
/allOf/17/then
/allOf/17/then/properties/level The level of the token's issues grant.

Type: string
/allOf/17/then/properties/admitted The acts the level admits, in the relay's order.

Type: array
/allOf/17/then/properties/admitted/items Type: string
/allOf/18
/allOf/18/if Required fields: ["error"]
/allOf/18/if/properties/error Required value: local_route_required
/allOf/18/then
/allOf/18/then/properties/application The id of the application whose platform-minted development credential the call asked to re-mint.

Type: string
/allOf/19
/allOf/19/if Required fields: ["error"]
/allOf/19/if/properties/error Required value: manifest_invalid
/allOf/19/then
/allOf/19/then/properties/violations One entry per violation, each the JSON path of the failing member, a colon, and the message. The root of the document is written as a single slash.

Type: array
/allOf/19/then/properties/violations/items Type: string
/allOf/20
/allOf/20/if Required fields: ["error"]
/allOf/20/if/properties/error Required value: plan_quantity_unset
/allOf/20/then
/allOf/20/then/properties/plan The plan whose served quantity is Unset: free, standard, or pro, or unlimited, the company's own plan, which no customer act selects yet.

Type: string
/allOf/20/then/properties/measure The registry name of the measure whose quantity is Unset for that plan, for example schedule-count-limit.

Type: string
/allOf/21
/allOf/21/if Required fields: ["error"]
/allOf/21/if/properties/error Required value: plan_schedule_conflict
/allOf/21/then
/allOf/21/then/properties/plan The plan the call moves the application onto, the plan set_plan names or unlimited on set_unlimited_plan, whose schedule rows do not admit the standing declarations. Unlimited is the company's own plan, which no customer act selects yet.

Type: string
/allOf/21/then/properties/schedules One entry per conflict between a standing schedule and the target plan. The list is never empty, and one schedule appears once per measure it violates.

Type: array
/allOf/21/then/properties/schedules/items Type: object
/allOf/21/then/properties/schedules/items/properties/schedule The schedule's declared name.

Type: string
/allOf/21/then/properties/schedules/items/properties/measure The measure violated: schedule-minimum-interval or schedule-count-limit.

Type: string
/allOf/21/then/properties/schedules/items/properties/bound The target plan's served quantity for that measure: minutes for the interval, a count for the limit.

Type: integer
/allOf/21/then/properties/schedules/items/properties/cron The schedule's cron expression as recorded.

Type: string
/allOf/21/then/properties/schedules/items/properties/gap The shortest gap in whole minutes between the expression's consecutive due times, on an interval entry alone.

Type: integer
/allOf/22
/allOf/22/if Required fields: ["error"]
/allOf/22/if/properties/error Required value: platform_minted_name
/allOf/22/then
/allOf/22/then/properties/application The id of the account's application whose platform-minted credential name the request named.

Type: string
/allOf/23
/allOf/23/if Required fields: ["error"]
/allOf/23/if/properties/error Required value: platform_space_configure_refused
/allOf/23/then
/allOf/23/then/properties/space The space the request named.

Type: string
/allOf/24
/allOf/24/if Required fields: ["error"]
/allOf/24/if/properties/error Required value: publication_bounded
/allOf/24/then
/allOf/24/then/properties/grant The grant that bounds the credential presented.

Type: string
Pattern: ^[a-z][a-z0-9_]*$
/allOf/24/then/properties/admitted The actions the bound admits, in the enumeration's order: the rows the grant marks and the rows whose admits mark names it. The rows marked access: anonymous lie outside the bound and are not listed.

Type: array
/allOf/24/then/properties/admitted/items Type: string
/allOf/25
/allOf/25/if Required fields: ["error"]
/allOf/25/if/properties/error Required value: publish_incomplete
/allOf/25/then
/allOf/25/then/properties/missing What the commit names and the puts never wrote, never empty. For publish_library each entry is a blob's sha256. For publish_public_files each entry is a file name, or a site-relative path for the site.

Type: array
/allOf/25/then/properties/missing/items Type: string
/allOf/26
/allOf/26/if Required fields: ["error"]
/allOf/26/if/properties/error Required value: published_bytes_differ
/allOf/26/then
/allOf/26/then/properties/file The published versioned name whose recorded sha256 differs from the incoming file's. For the site it is the full versioned name, the source commit's folder included.

Type: string
/allOf/27
/allOf/27/if Required fields: ["error"]
/allOf/27/if/properties/error Required value: region_unavailable
/allOf/27/then
/allOf/27/then/properties/region The region the submitted manifest declares, one the platform does not offer yet.

Type: string
/allOf/28
/allOf/28/if Required fields: ["error"]
/allOf/28/if/properties/error Required value: rotation_in_flight
/allOf/28/then
/allOf/28/then/properties/application The id of the application whose development database credential the call asked to re-mint.

Type: string
/allOf/29
/allOf/29/if Required fields: ["error"]
/allOf/29/if/properties/error Required value: route_set_contradicts_audience
/allOf/29/then
/allOf/29/then/properties/audience The audience the application's recorded manifest declares, workforce at this refusal.

Type: string
/allOf/29/then/properties/tenant The Entra tenant the manifest declares, present only where the call named a different tenant.

Type: string
/allOf/30
/allOf/30/if Required fields: ["error"]
/allOf/30/if/properties/error Required value: schedule_count_over_plan
/allOf/30/then
/allOf/30/then/properties/path The JSON path of the first schedule declaration past the plan's count.

Type: string
/allOf/30/then/properties/plan The application's plan: free, standard, or pro, or unlimited, the company's own plan, which no customer act selects yet.

Type: string
/allOf/30/then/properties/measure The measure the refusal is keyed on, schedule-count-limit.

Type: string
/allOf/30/then/properties/quantity The plan's served count limit, the number of schedules an application on the plan declares at most.

Type: integer
/allOf/31
/allOf/31/if Required fields: ["error"]
/allOf/31/if/properties/error Required value: schedule_interval_below_plan
/allOf/31/then
/allOf/31/then/properties/path The JSON path of the cron expression whose due times fall too close together.

Type: string
/allOf/31/then/properties/plan The application's plan: free, standard, or pro, or unlimited, the company's own plan, which no customer act selects yet.

Type: string
/allOf/31/then/properties/measure The measure the refusal is keyed on, schedule-minimum-interval.

Type: string
/allOf/31/then/properties/quantity The plan's served minimum interval in minutes, the floor.

Type: integer
/allOf/31/then/properties/gap The shortest gap in whole minutes between the expression's consecutive due times, less than the floor.

Type: integer
/allOf/32
/allOf/32/if Required fields: ["error"]
/allOf/32/if/properties/error Required value: scope_fixed
/allOf/32/then
/allOf/32/then/properties/scope The kind of scope the name stands at: account or application.

Type: string
/allOf/32/then/properties/application The id of the application whose scope the name stands at, null where it stands at the account scope.

Type: ["string","null"]
/allOf/32/then/properties/environment The environment of that application scope, development or production, null where the name stands at the account scope.

Type: ["string","null"]
/allOf/33
/allOf/33/if Required fields: ["error"]
/allOf/33/if/properties/error Required value: secret_grant_expired
/allOf/33/then
/allOf/33/then/properties/credential_kind The kind of the credential refused: secret_grant.

Type: string
/allOf/34
/allOf/34/if Required fields: ["error"]
/allOf/34/if/properties/error Required value: secret_grant_not_admitted
/allOf/34/then
/allOf/34/then/properties/credential_kind The kind of the credential refused: secret_grant.

Type: string
/allOf/35
/allOf/35/if Required fields: ["error"]
/allOf/35/if/properties/error Required value: secret_grant_spent
/allOf/35/then
/allOf/35/then/properties/credential_kind The kind of the credential refused: secret_grant.

Type: string
/allOf/36
/allOf/36/if Required fields: ["error"]
/allOf/36/if/properties/error Required value: space_not_owned
/allOf/36/then
/allOf/36/then/properties/space The space the request named.

Type: string
/allOf/37
/allOf/37/if Required fields: ["error"]
/allOf/37/if/properties/error Required value: synthetic_ceiling_reached
/allOf/37/then
/allOf/37/then/properties/ceiling The name of the ceiling reached: standing_accounts, seeded_per_day, standing_applications, paid_applications, or, under the synthetic_seed_purge grant, standing_accounts_per_credential. For an account seeded under that grant, paid_applications_per_account names the ceiling on its paid-plan applications.

Type: string
/allOf/37/then/properties/value The ceiling's constant, under the mode read or, for standing_accounts_per_credential and paid_applications_per_account, under the synthetic_seed_purge grant.

Type: integer
/allOf/37/then/properties/standing The count measured against the ceiling before the call. For seeded_per_day it is the accounts this operator's account seeded in the current UTC day. For standing_accounts_per_credential it is the standing synthetic accounts the calling credential seeded. For paid_applications_per_account it is the paid-plan applications the account holds, the one being moved counted out.

Type: integer
/allOf/38
/allOf/38/if Required fields: ["error"]
/allOf/38/if/properties/error Required value: synthetic_estate_bounded
/allOf/38/then
/allOf/38/then/properties/grant The grant that bounds the credential presented.

Type: string
Pattern: ^[a-z][a-z0-9_]*$
/allOf/38/then/properties/admitted The actions the bound admits, in the enumeration's order: the rows the grant marks and the rows whose admits mark names it. The rows marked access: anonymous lie outside the bound and are not listed.

Type: array
/allOf/38/then/properties/admitted/items Type: string
/allOf/39
/allOf/39/if Required fields: ["error"]
/allOf/39/if/properties/error Required value: synthetic_posture_refuses
/allOf/39/then
/allOf/39/then/properties/bound The name of the bound that refused: accounts_per_seed, token_expiry_days, or products on a seed, all on a purge.

Type: string
/allOf/39/then/properties/value The bound's constant, under the effective mode or under the caller's bounding grant, present on a seed's refusal that names accounts_per_seed or token_expiry_days.

Type: integer
/allOf/39/then/properties/posture The mode the refused act met: the effective seed mode on a seed, the standing mode on a purge.

Type: string
/allOf/39/then/properties/grant The bounding grant the caller's credential holds without super_admin, present only where the grant is why the act was refused: all on a purge, or a seed past the grant's own bounds.

Type: string
Pattern: ^[a-z][a-z0-9_]*$
/allOf/40
/allOf/40/if Required fields: ["error"]
/allOf/40/if/properties/error Required value: synthetic_seed_purge_bounded
/allOf/40/then
/allOf/40/then/properties/grant The grant that bounds the credential presented.

Type: string
Pattern: ^[a-z][a-z0-9_]*$
/allOf/40/then/properties/admitted The actions the bound admits, in the enumeration's order: the rows the grant marks and the rows whose admits mark names it. The rows marked access: anonymous lie outside the bound and are not listed.

Type: array
/allOf/40/then/properties/admitted/items Type: string
/allOf/41
/allOf/41/if Required fields: ["error"]
/allOf/41/if/properties/error Required value: token_scope_refused
/allOf/41/then
/allOf/41/then/properties/scope The bound of the token presented: the one application it reaches, outside which the request's subject lies.

Type: object
/allOf/41/then/properties/scope/properties/kind The kind of bound, always application here.

Type: string
/allOf/41/then/properties/scope/properties/application The id of the application the token is bounded to, null where the credential's bound names none.

Type: ["string","null"]
/allOf/42
/allOf/42/if Required fields: ["error"]
/allOf/42/if/properties/error Required value: transfer_grant_not_admitted
/allOf/42/then
/allOf/42/then/properties/credential_kind The kind of the credential refused: transfer_grant on the storage surface, the actions, and every other surface, and on the deploy command's progress read any kind presented.

Type: string
/allOf/43
/allOf/43/if Required fields: ["error"]
/allOf/43/if/properties/error Required value: upload_hash_mismatch
/allOf/43/then
/allOf/43/then/properties/received_sha256 The SHA-256 of the bytes refused, 64 lower-case hexadecimal characters: the body the write carried, or the stored file the start read.

Type: string
/allOf/43/then/properties/expected_sha256 The SHA-256 the preparing `deploy` call named as `zip_sha256`, 64 lower-case hexadecimal characters, which the upload's grant records.

Type: string
/allOf/43/then/properties/credential_kind The kind of the credential whose binding refused the bytes, transfer_grant: the upload's grant, at the write and at the start alike.

Type: string
/allOf/44
/allOf/44/if Required fields: ["error"]
/allOf/44/if/properties/error Required value: version_reused
/allOf/44/then
/allOf/44/then/properties/entry The name of the entry whose version is reused, left out where it is not in a library entry name's shape.

Type: string
/allOf/44/then/properties/version The version the entry keeps, which the served catalog already holds under another closure, left out where it is not in a version's shape.

Type: string
/allOf/44/then/properties/served_closure_hash The closure hash the served catalog records for the entry, left out where it is not 64 lower-case hexadecimal characters.

Type: string
/allOf/44/then/properties/incoming_closure_hash The closure hash this catalog states for the entry, left out where it is not 64 lower-case hexadecimal characters.

Type: string
/allOf/45
/allOf/45/if
/allOf/45/if/properties/error
/allOf/45/if/properties/error/not Allowed values: ["account_not_synthetic","account_outside_batches"]
/allOf/45/then
/allOf/45/then/properties/accounts false
/allOf/46
/allOf/46/if
/allOf/46/if/properties/error
/allOf/46/if/properties/error/not Allowed values: ["feedback_queue_bounded","issues_bounded","issues_level_refused","publication_bounded","synthetic_estate_bounded","synthetic_seed_purge_bounded"]
/allOf/46/then
/allOf/46/then/properties/admitted false
/allOf/47
/allOf/47/if
/allOf/47/if/properties/error
/allOf/47/if/properties/error/not Allowed values: ["binding_refused","custody_entry_missing","local_route_required","platform_minted_name","rotation_in_flight","scope_fixed"]
/allOf/47/then
/allOf/47/then/properties/application false
/allOf/48
/allOf/48/if
/allOf/48/if/properties/error
/allOf/48/if/properties/error/not Allowed values: ["creation_contradicts_audience","declared_audience_contradicts_route","invited_realm_refuses_work_account","route_set_contradicts_audience"]
/allOf/48/then
/allOf/48/then/properties/audience false
/allOf/49
/allOf/49/if
/allOf/49/if/properties/error
/allOf/49/if/properties/error/not Allowed values: ["synthetic_posture_refuses"]
/allOf/49/then
/allOf/49/then/properties/bound false
/allOf/50
/allOf/50/if
/allOf/50/if/properties/error
/allOf/50/if/properties/error/not Allowed values: ["synthetic_ceiling_reached"]
/allOf/50/then
/allOf/50/then/properties/ceiling false
/allOf/51
/allOf/51/if
/allOf/51/if/properties/error
/allOf/51/if/properties/error/not Allowed values: ["custody_entry_missing"]
/allOf/51/then
/allOf/51/then/properties/client_secret_name false
/allOf/52
/allOf/52/if
/allOf/52/if/properties/error
/allOf/52/if/properties/error/not Allowed values: ["declared_tenant_contradicts_route"]
/allOf/52/then
/allOf/52/then/properties/configured_tenant false
/allOf/53
/allOf/53/if
/allOf/53/if/properties/error
/allOf/53/if/properties/error/not Allowed values: ["creation_contradicts_audience","invited_realm_refuses_work_account"]
/allOf/53/then
/allOf/53/then/properties/creation false
/allOf/54
/allOf/54/if
/allOf/54/if/properties/error
/allOf/54/if/properties/error/not Allowed values: ["egress_key_not_admitted","end_user_credential_not_admitted","secret_grant_expired","secret_grant_not_admitted","secret_grant_spent","transfer_grant_not_admitted","upload_hash_mismatch"]
/allOf/54/then
/allOf/54/then/properties/credential_kind false
/allOf/55
/allOf/55/if
/allOf/55/if/properties/error
/allOf/55/if/properties/error/not Allowed values: ["version_reused"]
/allOf/55/then
/allOf/55/then/properties/entry false
/allOf/56
/allOf/56/if
/allOf/56/if/properties/error
/allOf/56/if/properties/error/not Allowed values: ["declared_audience_contradicts_route","declared_tenant_contradicts_route","scope_fixed"]
/allOf/56/then
/allOf/56/then/properties/environment false
/allOf/57
/allOf/57/if
/allOf/57/if/properties/error
/allOf/57/if/properties/error/not Allowed values: ["upload_hash_mismatch"]
/allOf/57/then
/allOf/57/then/properties/expected_sha256 false
/allOf/58
/allOf/58/if
/allOf/58/if/properties/error
/allOf/58/if/properties/error/not Allowed values: ["published_bytes_differ"]
/allOf/58/then
/allOf/58/then/properties/file false
/allOf/59
/allOf/59/if
/allOf/59/if/properties/error
/allOf/59/if/properties/error/not Allowed values: ["schedule_interval_below_plan"]
/allOf/59/then
/allOf/59/then/properties/gap false
/allOf/60
/allOf/60/if
/allOf/60/if/properties/error
/allOf/60/if/properties/error/not Allowed values: ["account_outside_batches","feedback_queue_bounded","grant_not_held","grant_required","grant_scope_refused","issues_bounded","publication_bounded","synthetic_estate_bounded","synthetic_posture_refuses","synthetic_seed_purge_bounded"]
/allOf/60/then
/allOf/60/then/properties/grant false
/allOf/61
/allOf/61/if
/allOf/61/if/properties/error
/allOf/61/if/properties/error/not Allowed values: ["version_reused"]
/allOf/61/then
/allOf/61/then/properties/incoming_closure_hash false
/allOf/62
/allOf/62/if
/allOf/62/if/properties/error
/allOf/62/if/properties/error/not Allowed values: ["issues_level_refused"]
/allOf/62/then
/allOf/62/then/properties/level false
/allOf/63
/allOf/63/if
/allOf/63/if/properties/error
/allOf/63/if/properties/error/not Allowed values: ["plan_quantity_unset","schedule_count_over_plan","schedule_interval_below_plan"]
/allOf/63/then
/allOf/63/then/properties/measure false
/allOf/64
/allOf/64/if
/allOf/64/if/properties/error
/allOf/64/if/properties/error/not Allowed values: ["publish_incomplete"]
/allOf/64/then
/allOf/64/then/properties/missing false
/allOf/65
/allOf/65/if
/allOf/65/if/properties/error
/allOf/65/if/properties/error/not Allowed values: ["schedule_count_over_plan","schedule_interval_below_plan"]
/allOf/65/then
/allOf/65/then/properties/path false
/allOf/66
/allOf/66/if
/allOf/66/if/properties/error
/allOf/66/if/properties/error/not Allowed values: ["plan_quantity_unset","plan_schedule_conflict","schedule_count_over_plan","schedule_interval_below_plan"]
/allOf/66/then
/allOf/66/then/properties/plan false
/allOf/67
/allOf/67/if
/allOf/67/if/properties/error
/allOf/67/if/properties/error/not Allowed values: ["synthetic_posture_refuses"]
/allOf/67/then
/allOf/67/then/properties/posture false
/allOf/68
/allOf/68/if
/allOf/68/if/properties/error
/allOf/68/if/properties/error/not Allowed values: ["schedule_count_over_plan","schedule_interval_below_plan"]
/allOf/68/then
/allOf/68/then/properties/quantity false
/allOf/69
/allOf/69/if
/allOf/69/if/properties/error
/allOf/69/if/properties/error/not Allowed values: ["upload_hash_mismatch"]
/allOf/69/then
/allOf/69/then/properties/received_sha256 false
/allOf/70
/allOf/70/if
/allOf/70/if/properties/error
/allOf/70/if/properties/error/not Allowed values: ["issue_refused"]
/allOf/70/then
/allOf/70/then/properties/refusal false
/allOf/71
/allOf/71/if
/allOf/71/if/properties/error
/allOf/71/if/properties/error/not Allowed values: ["region_unavailable"]
/allOf/71/then
/allOf/71/then/properties/region false
/allOf/72
/allOf/72/if
/allOf/72/if/properties/error
/allOf/72/if/properties/error/not Allowed values: ["plan_schedule_conflict"]
/allOf/72/then
/allOf/72/then/properties/schedules false
/allOf/73
/allOf/73/if
/allOf/73/if/properties/error
/allOf/73/if/properties/error/not Allowed values: ["account_credential_required","scope_fixed","token_scope_refused"]
/allOf/73/then
/allOf/73/then/properties/scope false
/allOf/74
/allOf/74/if
/allOf/74/if/properties/error
/allOf/74/if/properties/error/not Allowed values: ["version_reused"]
/allOf/74/then
/allOf/74/then/properties/served_closure_hash false
/allOf/75
/allOf/75/if
/allOf/75/if/properties/error
/allOf/75/if/properties/error/not Allowed values: ["declared_audience_contradicts_route"]
/allOf/75/then
/allOf/75/then/properties/sign_in_methods false
/allOf/76
/allOf/76/if
/allOf/76/if/properties/error
/allOf/76/if/properties/error/not Allowed values: ["platform_space_configure_refused","space_not_owned"]
/allOf/76/then
/allOf/76/then/properties/space false
/allOf/77
/allOf/77/if
/allOf/77/if/properties/error
/allOf/77/if/properties/error/not Allowed values: ["synthetic_ceiling_reached"]
/allOf/77/then
/allOf/77/then/properties/standing false
/allOf/78
/allOf/78/if
/allOf/78/if/properties/error
/allOf/78/if/properties/error/not Allowed values: ["declared_tenant_contradicts_route","route_set_contradicts_audience"]
/allOf/78/then
/allOf/78/then/properties/tenant false
/allOf/79
/allOf/79/if
/allOf/79/if/properties/error
/allOf/79/if/properties/error/not Allowed values: ["synthetic_ceiling_reached","synthetic_posture_refuses"]
/allOf/79/then
/allOf/79/then/properties/value false
/allOf/80
/allOf/80/if
/allOf/80/if/properties/error
/allOf/80/if/properties/error/not Allowed values: ["version_reused"]
/allOf/80/then
/allOf/80/then/properties/version false
/allOf/81
/allOf/81/if
/allOf/81/if/properties/error
/allOf/81/if/properties/error/not Allowed values: ["manifest_invalid"]
/allOf/81/then
/allOf/81/then/properties/violations false

Complete source

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "version": "2026-10-07.1",
  "title": "Turn Zero Cloud — wire error shape, contract version 1",
  "description": "Every refusal the management plane returns (MAPI-10 in the management API contract) takes this shape, whose base members are six. They are the contract version, a machine-readable slug, the action where one is in question, a human detail, the reference the action dispatcher minted for the call, and help, the address of the refusal's row on the refusals page. Beyond them it carries the members the refusal's row of wire_errors.json names under members (MAPI-15), each admitted under the refusals whose rows name it and under no other, and none required. The declarations after the base six and the conditionals are generated from those rows and never written apart from them. MAN-12's named-refusal discipline, applied to the plane itself.",
  "type": "object",
  "additionalProperties": false,
  "required": [
    "contract_version",
    "error"
  ],
  "properties": {
    "contract_version": {
      "description": "MAPI-02: the version, stated in every exchange — refusals included.",
      "const": 1
    },
    "error": {
      "description": "The machine-readable refusal: not_yet_provisioned, unknown_action, method_not_allowed, and the slugs each action's implementation adds.",
      "type": "string",
      "pattern": "^[a-z][a-z0-9_]*$"
    },
    "action": {
      "description": "The action in question, where one is.",
      "type": "string",
      "pattern": "^[a-z][a-z0-9_]*$"
    },
    "detail": {
      "description": "The human sentence; never required to be machine-parsed.",
      "type": "string"
    },
    "reference": {
      "description": "The short reference the action dispatcher minted for the call: ten lowercase hexadecimal characters, carried by every refusal the dispatcher answers and written to the call’s record row, so a report that quotes it is checked against the platform’s own record. Admitted on every refusal and required on none.",
      "type": "string",
      "pattern": "^[0-9a-f]{10}$"
    },
    "help": {
      "description": "The address of the refusal's row on the refusals page, <origin>/cloud/reference/refusals/#<refusal name>, on the estate's public origin, the production origin standing in for a loopback or http one. It is carried by every refusal the action dispatcher answers to a dispatched call and by the unknown_action, method_not_allowed, and not_yet_provisioned refusals the actions routes answer before dispatch. Admitted on every refusal and required on none.",
      "type": "string"
    },
    "accounts": {},
    "admitted": {},
    "application": {},
    "audience": {},
    "bound": {},
    "ceiling": {},
    "client_secret_name": {},
    "configured_tenant": {},
    "creation": {},
    "credential_kind": {},
    "entry": {},
    "environment": {},
    "expected_sha256": {},
    "file": {},
    "gap": {},
    "grant": {},
    "incoming_closure_hash": {},
    "level": {},
    "measure": {},
    "missing": {},
    "path": {},
    "plan": {},
    "posture": {},
    "quantity": {},
    "received_sha256": {},
    "refusal": {},
    "region": {},
    "schedules": {},
    "scope": {},
    "served_closure_hash": {},
    "sign_in_methods": {},
    "space": {},
    "standing": {},
    "tenant": {},
    "value": {},
    "version": {},
    "violations": {}
  },
  "allOf": [
    {
      "if": {
        "properties": {
          "error": {
            "const": "account_credential_required"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "scope": {
            "type": "object",
            "description": "The bound of the token presented: a token minted for one application, under which halting production is refused.",
            "properties": {
              "kind": {
                "type": "string",
                "description": "The kind of bound, always application here."
              },
              "application": {
                "type": "string",
                "description": "The id of the application the token is bounded to."
              }
            }
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "account_not_synthetic"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "accounts": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "The account ids the request named that stand and are not synthetic, as the caller wrote them. The list is never empty."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "account_outside_batches"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "accounts": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "The account ids the request named that lie in no batch the caller's own credential seeded, as the caller wrote them. The list is never empty. The member is left out where the request repeated a request_id another credential's purge carries."
          },
          "grant": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9_]*$",
            "description": "The synthetic grant that bounds the caller's credential, present on the purge's refusal."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "binding_refused"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "application": {
            "type": "string",
            "description": "The id of the application the standing upstream of that name is bound to, which is not the application this declaration named."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "creation_contradicts_audience"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "audience": {
            "type": "string",
            "description": "The audience the application's manifest declares, invited at this refusal."
          },
          "creation": {
            "type": "string",
            "description": "The creation mode the call named, open at this refusal."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "custody_entry_missing"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "client_secret_name": {
            "type": "string",
            "description": "The secret name the call, or the manifest's realm member, gave as the work-account client secret, the Apple signing key, or the push provider credential, for which custody holds no entry at the application's scope."
          },
          "application": {
            "type": "string",
            "description": "The id of the application whose realm the call, the submission, or create_environment configures, and at whose scope the entry was looked up."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "declared_audience_contradicts_route"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "audience": {
            "type": "string",
            "description": "The audience the submitted manifest declares, invited at this refusal."
          },
          "environment": {
            "type": "string",
            "description": "The environment whose standing realm names the work-account route, development or production, the first one found."
          },
          "sign_in_methods": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "The sign-in methods that realm is configured with, the work-account route entra among them."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "declared_tenant_contradicts_route"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "tenant": {
            "type": "string",
            "description": "The Entra tenant the submitted manifest declares under the workforce audience."
          },
          "configured_tenant": {
            "type": "string",
            "description": "The Entra tenant the work-account route of that environment's realm is configured against."
          },
          "environment": {
            "type": "string",
            "description": "The environment whose standing realm's work-account route names another tenant, development or production, the first one found."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "egress_key_not_admitted"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "credential_kind": {
            "type": "string",
            "description": "The kind of the credential refused, egress_key at this refusal."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "end_user_credential_not_admitted"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "credential_kind": {
            "type": "string",
            "description": "The kind of the credential refused, end_user at this refusal."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "feedback_queue_bounded"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "grant": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9_]*$",
            "description": "The grant that bounds the credential presented."
          },
          "admitted": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "The actions the bound admits, in the enumeration's order: the rows the grant marks and the rows whose admits mark names it. The rows marked access: anonymous lie outside the bound and are not listed."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "grant_not_held"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "grant": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9_]*$",
            "description": "The requested grant the minting session does not itself hold."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "grant_required"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "grant": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9_]*$",
            "description": "The grant the action requires and the credential does not hold."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "grant_scope_refused"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "grant": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9_]*$",
            "description": "The grant requested for an application-bounded token, which carries neither super_admin nor a narrow grant."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "invited_realm_refuses_work_account"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "creation": {
            "type": "string",
            "description": "The creation mode the realm would enforce after the call, invited at this refusal."
          },
          "audience": {
            "type": "string",
            "description": "The audience the application's recorded manifest declares: public, invited, or workforce."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "issue_refused"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "refusal": {
            "type": "string",
            "description": "The issue service's own refusal name, one the Issue Tracking contract states."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "issues_bounded"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "grant": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9_]*$",
            "description": "The grant that bounds the credential presented."
          },
          "admitted": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "The actions the bound admits, in the enumeration's order: the rows the grant marks and the rows whose admits mark names it. The rows marked access: anonymous lie outside the bound and are not listed."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "issues_level_refused"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "level": {
            "type": "string",
            "description": "The level of the token's issues grant."
          },
          "admitted": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "The acts the level admits, in the relay's order."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "local_route_required"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "application": {
            "type": "string",
            "description": "The id of the application whose platform-minted development credential the call asked to re-mint."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "manifest_invalid"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "violations": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "One entry per violation, each the JSON path of the failing member, a colon, and the message. The root of the document is written as a single slash."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "plan_quantity_unset"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "plan": {
            "type": "string",
            "description": "The plan whose served quantity is Unset: free, standard, or pro, or unlimited, the company's own plan, which no customer act selects yet."
          },
          "measure": {
            "type": "string",
            "description": "The registry name of the measure whose quantity is Unset for that plan, for example schedule-count-limit."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "plan_schedule_conflict"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "plan": {
            "type": "string",
            "description": "The plan the call moves the application onto, the plan set_plan names or unlimited on set_unlimited_plan, whose schedule rows do not admit the standing declarations. Unlimited is the company's own plan, which no customer act selects yet."
          },
          "schedules": {
            "type": "array",
            "description": "One entry per conflict between a standing schedule and the target plan. The list is never empty, and one schedule appears once per measure it violates.",
            "items": {
              "type": "object",
              "properties": {
                "schedule": {
                  "type": "string",
                  "description": "The schedule's declared name."
                },
                "measure": {
                  "type": "string",
                  "description": "The measure violated: schedule-minimum-interval or schedule-count-limit."
                },
                "bound": {
                  "type": "integer",
                  "description": "The target plan's served quantity for that measure: minutes for the interval, a count for the limit."
                },
                "cron": {
                  "type": "string",
                  "description": "The schedule's cron expression as recorded."
                },
                "gap": {
                  "type": "integer",
                  "description": "The shortest gap in whole minutes between the expression's consecutive due times, on an interval entry alone."
                }
              }
            }
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "platform_minted_name"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "application": {
            "type": "string",
            "description": "The id of the account's application whose platform-minted credential name the request named."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "platform_space_configure_refused"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "space": {
            "type": "string",
            "description": "The space the request named."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "publication_bounded"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "grant": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9_]*$",
            "description": "The grant that bounds the credential presented."
          },
          "admitted": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "The actions the bound admits, in the enumeration's order: the rows the grant marks and the rows whose admits mark names it. The rows marked access: anonymous lie outside the bound and are not listed."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "publish_incomplete"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "missing": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "What the commit names and the puts never wrote, never empty. For publish_library each entry is a blob's sha256. For publish_public_files each entry is a file name, or a site-relative path for the site."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "published_bytes_differ"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "file": {
            "type": "string",
            "description": "The published versioned name whose recorded sha256 differs from the incoming file's. For the site it is the full versioned name, the source commit's folder included."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "region_unavailable"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "region": {
            "type": "string",
            "description": "The region the submitted manifest declares, one the platform does not offer yet."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "rotation_in_flight"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "application": {
            "type": "string",
            "description": "The id of the application whose development database credential the call asked to re-mint."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "route_set_contradicts_audience"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "audience": {
            "type": "string",
            "description": "The audience the application's recorded manifest declares, workforce at this refusal."
          },
          "tenant": {
            "type": "string",
            "description": "The Entra tenant the manifest declares, present only where the call named a different tenant."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "schedule_count_over_plan"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "path": {
            "type": "string",
            "description": "The JSON path of the first schedule declaration past the plan's count."
          },
          "plan": {
            "type": "string",
            "description": "The application's plan: free, standard, or pro, or unlimited, the company's own plan, which no customer act selects yet."
          },
          "measure": {
            "type": "string",
            "description": "The measure the refusal is keyed on, schedule-count-limit."
          },
          "quantity": {
            "type": "integer",
            "description": "The plan's served count limit, the number of schedules an application on the plan declares at most."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "schedule_interval_below_plan"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "path": {
            "type": "string",
            "description": "The JSON path of the cron expression whose due times fall too close together."
          },
          "plan": {
            "type": "string",
            "description": "The application's plan: free, standard, or pro, or unlimited, the company's own plan, which no customer act selects yet."
          },
          "measure": {
            "type": "string",
            "description": "The measure the refusal is keyed on, schedule-minimum-interval."
          },
          "quantity": {
            "type": "integer",
            "description": "The plan's served minimum interval in minutes, the floor."
          },
          "gap": {
            "type": "integer",
            "description": "The shortest gap in whole minutes between the expression's consecutive due times, less than the floor."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "scope_fixed"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "scope": {
            "type": "string",
            "description": "The kind of scope the name stands at: account or application."
          },
          "application": {
            "type": [
              "string",
              "null"
            ],
            "description": "The id of the application whose scope the name stands at, null where it stands at the account scope."
          },
          "environment": {
            "type": [
              "string",
              "null"
            ],
            "description": "The environment of that application scope, development or production, null where the name stands at the account scope."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "secret_grant_expired"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "credential_kind": {
            "type": "string",
            "description": "The kind of the credential refused: secret_grant."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "secret_grant_not_admitted"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "credential_kind": {
            "type": "string",
            "description": "The kind of the credential refused: secret_grant."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "secret_grant_spent"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "credential_kind": {
            "type": "string",
            "description": "The kind of the credential refused: secret_grant."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "space_not_owned"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "space": {
            "type": "string",
            "description": "The space the request named."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "synthetic_ceiling_reached"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "ceiling": {
            "type": "string",
            "description": "The name of the ceiling reached: standing_accounts, seeded_per_day, standing_applications, paid_applications, or, under the synthetic_seed_purge grant, standing_accounts_per_credential. For an account seeded under that grant, paid_applications_per_account names the ceiling on its paid-plan applications."
          },
          "value": {
            "type": "integer",
            "description": "The ceiling's constant, under the mode read or, for standing_accounts_per_credential and paid_applications_per_account, under the synthetic_seed_purge grant."
          },
          "standing": {
            "type": "integer",
            "description": "The count measured against the ceiling before the call. For seeded_per_day it is the accounts this operator's account seeded in the current UTC day. For standing_accounts_per_credential it is the standing synthetic accounts the calling credential seeded. For paid_applications_per_account it is the paid-plan applications the account holds, the one being moved counted out."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "synthetic_estate_bounded"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "grant": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9_]*$",
            "description": "The grant that bounds the credential presented."
          },
          "admitted": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "The actions the bound admits, in the enumeration's order: the rows the grant marks and the rows whose admits mark names it. The rows marked access: anonymous lie outside the bound and are not listed."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "synthetic_posture_refuses"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "bound": {
            "type": "string",
            "description": "The name of the bound that refused: accounts_per_seed, token_expiry_days, or products on a seed, all on a purge."
          },
          "value": {
            "type": "integer",
            "description": "The bound's constant, under the effective mode or under the caller's bounding grant, present on a seed's refusal that names accounts_per_seed or token_expiry_days."
          },
          "posture": {
            "type": "string",
            "description": "The mode the refused act met: the effective seed mode on a seed, the standing mode on a purge."
          },
          "grant": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9_]*$",
            "description": "The bounding grant the caller's credential holds without super_admin, present only where the grant is why the act was refused: all on a purge, or a seed past the grant's own bounds."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "synthetic_seed_purge_bounded"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "grant": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9_]*$",
            "description": "The grant that bounds the credential presented."
          },
          "admitted": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "The actions the bound admits, in the enumeration's order: the rows the grant marks and the rows whose admits mark names it. The rows marked access: anonymous lie outside the bound and are not listed."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "token_scope_refused"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "scope": {
            "type": "object",
            "description": "The bound of the token presented: the one application it reaches, outside which the request's subject lies.",
            "properties": {
              "kind": {
                "type": "string",
                "description": "The kind of bound, always application here."
              },
              "application": {
                "type": [
                  "string",
                  "null"
                ],
                "description": "The id of the application the token is bounded to, null where the credential's bound names none."
              }
            }
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "transfer_grant_not_admitted"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "credential_kind": {
            "type": "string",
            "description": "The kind of the credential refused: transfer_grant on the storage surface, the actions, and every other surface, and on the deploy command's progress read any kind presented."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "upload_hash_mismatch"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "received_sha256": {
            "type": "string",
            "description": "The SHA-256 of the bytes refused, 64 lower-case hexadecimal characters: the body the write carried, or the stored file the start read."
          },
          "expected_sha256": {
            "type": "string",
            "description": "The SHA-256 the preparing `deploy` call named as `zip_sha256`, 64 lower-case hexadecimal characters, which the upload's grant records."
          },
          "credential_kind": {
            "type": "string",
            "description": "The kind of the credential whose binding refused the bytes, transfer_grant: the upload's grant, at the write and at the start alike."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "const": "version_reused"
          }
        },
        "required": [
          "error"
        ]
      },
      "then": {
        "properties": {
          "entry": {
            "type": "string",
            "description": "The name of the entry whose version is reused, left out where it is not in a library entry name's shape."
          },
          "version": {
            "type": "string",
            "description": "The version the entry keeps, which the served catalog already holds under another closure, left out where it is not in a version's shape."
          },
          "served_closure_hash": {
            "type": "string",
            "description": "The closure hash the served catalog records for the entry, left out where it is not 64 lower-case hexadecimal characters."
          },
          "incoming_closure_hash": {
            "type": "string",
            "description": "The closure hash this catalog states for the entry, left out where it is not 64 lower-case hexadecimal characters."
          }
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "account_not_synthetic",
                "account_outside_batches"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "accounts": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "feedback_queue_bounded",
                "issues_bounded",
                "issues_level_refused",
                "publication_bounded",
                "synthetic_estate_bounded",
                "synthetic_seed_purge_bounded"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "admitted": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "binding_refused",
                "custody_entry_missing",
                "local_route_required",
                "platform_minted_name",
                "rotation_in_flight",
                "scope_fixed"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "application": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "creation_contradicts_audience",
                "declared_audience_contradicts_route",
                "invited_realm_refuses_work_account",
                "route_set_contradicts_audience"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "audience": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "synthetic_posture_refuses"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "bound": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "synthetic_ceiling_reached"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "ceiling": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "custody_entry_missing"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "client_secret_name": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "declared_tenant_contradicts_route"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "configured_tenant": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "creation_contradicts_audience",
                "invited_realm_refuses_work_account"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "creation": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "egress_key_not_admitted",
                "end_user_credential_not_admitted",
                "secret_grant_expired",
                "secret_grant_not_admitted",
                "secret_grant_spent",
                "transfer_grant_not_admitted",
                "upload_hash_mismatch"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "credential_kind": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "version_reused"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "entry": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "declared_audience_contradicts_route",
                "declared_tenant_contradicts_route",
                "scope_fixed"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "environment": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "upload_hash_mismatch"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "expected_sha256": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "published_bytes_differ"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "file": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "schedule_interval_below_plan"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "gap": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "account_outside_batches",
                "feedback_queue_bounded",
                "grant_not_held",
                "grant_required",
                "grant_scope_refused",
                "issues_bounded",
                "publication_bounded",
                "synthetic_estate_bounded",
                "synthetic_posture_refuses",
                "synthetic_seed_purge_bounded"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "grant": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "version_reused"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "incoming_closure_hash": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "issues_level_refused"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "level": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "plan_quantity_unset",
                "schedule_count_over_plan",
                "schedule_interval_below_plan"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "measure": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "publish_incomplete"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "missing": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "schedule_count_over_plan",
                "schedule_interval_below_plan"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "path": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "plan_quantity_unset",
                "plan_schedule_conflict",
                "schedule_count_over_plan",
                "schedule_interval_below_plan"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "plan": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "synthetic_posture_refuses"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "posture": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "schedule_count_over_plan",
                "schedule_interval_below_plan"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "quantity": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "upload_hash_mismatch"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "received_sha256": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "issue_refused"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "refusal": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "region_unavailable"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "region": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "plan_schedule_conflict"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "schedules": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "account_credential_required",
                "scope_fixed",
                "token_scope_refused"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "scope": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "version_reused"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "served_closure_hash": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "declared_audience_contradicts_route"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "sign_in_methods": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "platform_space_configure_refused",
                "space_not_owned"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "space": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "synthetic_ceiling_reached"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "standing": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "declared_tenant_contradicts_route",
                "route_set_contradicts_audience"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "tenant": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "synthetic_ceiling_reached",
                "synthetic_posture_refuses"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "value": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "version_reused"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "version": false
        }
      }
    },
    {
      "if": {
        "properties": {
          "error": {
            "not": {
              "enum": [
                "manifest_invalid"
              ]
            }
          }
        }
      },
      "then": {
        "properties": {
          "violations": false
        }
      }
    }
  ]
}