Skip to main content
theAuth returns structured errors in the following shape:
All SDK functions that can fail return a Result<T> discriminated union rather than throwing:
For REST API calls, errors are returned as JSON with the corresponding HTTP status code:

Error code reference

theauth.authorize() and theauth.delegate() do not return the permission and delegation codes in the tables below. authorize() returns { allowed, reason, auditId } where reason is free-form text (for example No permission grants agent "x" access to "write" on "mcp:github:repos"), and delegate() throws a plain Error with a descriptive message (a subset violation or a depth overrun). Treat the Agent, Permission, Token, and Delegation tables as a reference vocabulary for your own HTTP layer, not as values the TypeScript core emits. The MCP module returns Result errors with codes such as INVALID_CLIENT, INVALID_GRANT, LOGIN_REQUIRED, INVALID_TOKEN, TOKEN_EXPIRED, INVALID_AUDIENCE, INVALID_ISSUER, INSUFFICIENT_SCOPE, UNAUTHORIZED, and SERVER_ERROR.

Agent errors

Permission errors

Token errors

Delegation errors

MCP / OAuth errors

General errors

API reference

Full REST endpoint reference with request and response shapes.

Agent identity

Agent creation, rotation, and revocation that produce these error codes.

Permissions

Permission and delegation errors explained in context.

Test utilities

Assert on error codes in unit tests without a real database.
Last modified on October 7, 2026