help
Every error code a first-hour call can return, each with its own meaning/cause/fix.
- bearer_invalid -- The call carried no usable credential: no Authorization: Bearer header, and (for host.tool_publish and friends) no tenant_key argument either.
- tenant_key_missing -- A tenant_key argument was required for this call (no Authorization header was sent on this connection) and none was given, or it wasn't a string.
- tenant_key_invalid -- A tenant_key argument was present but matched no tenant.
- rate_limited -- signup's own per-source rate limit was exceeded.
- signup_paused -- The operator has paused new signups host-wide.
- tool_not_found -- The named tool doesn't exist for this tenant (or, for a shared/cross-tenant call, doesn't exist, isn't shared with you, or your group isn't in its sharing list).
- unknown_kind -- host.tool_publish's kind argument named a kind this host doesn't register.
- spec_too_large -- The spec argument serializes to more bytes than this host allows for one tool.
- invalid_spec -- The kind rejected the spec's shape -- a required field missing, or a field that doesn't parse the way that kind expects.
- invalid_params -- A control-plane call argument was missing, the wrong type, or otherwise malformed -- distinct from invalid_spec, which is about a tool's own spec.
- host_not_allowed -- An http-kind spec (or call) named a URL whose host this host's egress policy refuses to reach.
- handle_taken -- The agent-directory handle you tried to claim is already held by someone else.
- handle_reserved -- The agent-directory handle you tried to claim is reserved by the operator (e.g. admin, host, mcphost, system).
- spec_not_exposed -- A tool was shared with you, but not with expose_spec: true, so host.tool_spec_shared can't read its source.
- service_unavailable -- The host refused the call because a resource it depends on (most commonly disk headroom) is below its safety floor.
- internal -- Something failed on this host's side that isn't one of the named error codes above.