Gateway error codes What the Gateway returns when something is wrong, and what each one means for you. Code Meaning What to do 401 No token, or an invalid one The device may be revoked or its session expired — sign in again in the Endpoint Suite 403 The token lacks gateway:invoke Grant the scope, or use a credential that has it 409 Ambiguous provider key — the model is in more than one key's enabled-models list Make the model lists disjoint on Providers 424 No provider key configured for this request Add a matching key on Providers, or move the tool to subscription mode Upstream errors Errors from the AI provider itself are passed through unchanged and appear in Activity with the Upstream error outcome. Rate limits, provider outages and model deprecations all arrive this way. The provider's own message tells you which. Blocked is not an error A request stopped by your policy is not a failure of the Gateway. It shows in Activity as Blocked, with the rule that stopped it in the Signals column. If a developer reports "an error", check the outcome column before assuming something is broken — it may be working exactly as configured. Revocation timing Revoking a device, or a device session expiring, takes effect within roughly 30 seconds rather than instantly. The Gateway notices at the next token refresh.