Skip to content
Covo Developers

Reference

Errors

Every error code the API and MCP server return, what it means and what to do.

StatusCodeMeaning and what to do
400bad_requestAn input is invalid. field names it; details lists each problem.
401unauthorizedNo token, or unknown, revoked or expired. OAuth: refresh or reconnect. Personal: create a new one.
403insufficient_scopeThe token lacks the scope the operation needs.
403role_insufficientThe person's role on this Concierge does not allow it (publishing needs admin).
403account_suspendedThe account is paused (email not confirmed, payment, or a rules violation). The person signs in to Studio to fix it.
403plan_limitThe plan does not include this or is full; details has the limit.
403agent_disabledThe Concierge was disabled by the platform; nothing can change it until it is re-enabled.
404agent_not_foundUnknown agent, or not reachable with this token.
404draft_not_found, version_not_found, test_run_not_foundUnknown id for this agent. List them first.
409draft_closedThe draft was already applied or discarded. Create a new one.
409confirmation_requiredSensitive write: ask the person, then retry with confirm: true.
409version_conflictThe agent changed since you read it. Read again, then redo the change.
409idempotency_in_progressThe first call with this key is still running. Retry shortly.
422idempotency_key_reusedSame key, different input. Use a new key.
422not_readySomething required is missing before publishing; the message says what.
422changes_invalidA change set does not fit the configuration schema; details lists each problem. Check get_configuration_schema.
422version_unrestorableThat version cannot be restored (for example it no longer fits the schema).
429rate_limitedWait Retry-After seconds.
500internalOur side. Retry later; quote requestId if it continues.

OAuth endpoints

/oauth/token, /oauth/register and /oauth/revoke answer in RFC 6749 form: {"error": "...", "error_description": "..."}, with invalid_request, invalid_client (401), invalid_grant, unsupported_grant_type, invalid_redirect_uri or invalid_client_metadata.