Skip to content

Errors

Ramose errors are tagged and safe to branch on. Public errors explain what a caller can do next without exposing hidden resources, policy internals, storage identities, or query plans.

New here? Start with Troubleshooting.

TagMeaningCaller action
TxRejectedA commit violated the catalog or storage constraintsRefresh authoritative state; change the intent before retrying
UnavailableThe service is temporarily unable to serve the requestHonor retry guidance and retain stale data
InvalidRequestA data-plane request is malformedFix the caller; do not repeat unchanged
DatabaseNotFoundThe requested public route is not availableVerify the deployment URL and route
UnauthorizedAuthentication or authorization failedRefresh identity or stop; do not reveal hidden state
QueryBudgetExceededA valid query exceeded configured workNarrow filters, projection, recursion, or page size
InternalErrorAn unexpected server failure occurredShow a generic message and correlate server logs
NetworkErrorThe request did not reach a conclusive responseKeep queued work and reconnect
OperationRejectedThe authoritative operation refused the intentPresent the public reason; retry only after a meaningful change
CodeMeaningCaller action
invalid_queryQuery grammar, type, bound, or cursor is invalidFix the query; do not repeat unchanged
unknown_definitionA public catalog reference is unknownRediscover or update the client catalog
catalog_changedThe inspected catalog token is staleRediscover and rebuild the request
query_budget_exceededA valid query exceeded configured workNarrow filters, projection, recursion, or page size
invalid_inputInput failed the operation schemaCorrect input from the catalog
inaccessibleA database, definition, entity, or target cannot be revealedStop or ask the user for access
operation_rejectedThe authoritative operation refused the intentPresent the public reason; retry only after a meaningful change
invocation_conflictAn invocation id identifies a different prior intentFix caller state; never silently repeat as new work

inaccessible intentionally covers missing and unauthorized cases when distinguishing them would disclose information. .one() may also produce NotOne; schema policy validation may fail before deployment.

A rejected receipt rolls back that optimistic layer and reapplies later layers. Preserve user-authored input when the UI offers a corrected new invocation.

The browser client resumes database synchronization and replays durable queued invocations. It does not blindly repeat invalid queries, policy denials, domain rejections, or invocation conflicts.

  • pending query state: show an initial skeleton because no complete local answer exists.
  • stale query state: keep the complete result visible and label connectivity or catch-up.
  • rejected receipt: identify the action, show its public reason, and display authoritative state after rollback.
  • unauthenticated: pause protected work and start session recovery without clearing another principal’s data into the new session.
  • inaccessible: do not reveal whether the requested resource exists.