TheAuthError carries a code, message, and optional details. All SDK functions return a Result union instead of throwing, with matching HTTP status codes on REST.
theAuth returns structured errors in the following shape:
theauth.authorize() and theauth.delegate() do not return the permission and delegation codes in the tables below. authorize() returns { allowed, reason, auditId } where reason is free-form text (for example No permission grants agent "x" access to "write" on "mcp:github:repos"), and delegate() throws a plain Error with a descriptive message (a subset violation or a depth overrun). Treat the Agent, Permission, Token, and Delegation tables as a reference vocabulary for your own HTTP layer, not as values the TypeScript core emits. The MCP module returns Result errors with codes such as INVALID_CLIENT, INVALID_GRANT, LOGIN_REQUIRED, INVALID_TOKEN, TOKEN_EXPIRED, INVALID_AUDIENCE, INVALID_ISSUER, INSUFFICIENT_SCOPE, UNAUTHORIZED, and SERVER_ERROR.