Skip to content

Bakobo error codes

Every error Bakobo reports carries a stable symbolic code, and every code has a page here. If you arrived from the type member of a problem+json response, the page you want is the code itself.

How to read a code

A Bakobo error code reads left to right, growing more specific:

<sorter>.<descriptor>[.<sub-descriptor>...].<disposition>

The sorter is e for an error, whose consequences are clear, or w for a warning, whose consequences need someone's judgment. The descriptor says what the obstacle was, and comes from a closed set of ten. The disposition is the last token, f if retrying changes nothing and r if it might help — last, so that e.state. matches every target-condition failure whichever way it disposes.

A first descriptor is a category, never a code. e.proof. names a kind of obstacle rather than one condition, so every code carries at least one sub-descriptor and a bare descriptor appears only as a pattern to match against.

The ten obstacles

Descriptor The obstacle
e.input. What you sent
e.id. Who you are (authentication)
e.grant. What you may do (delegated authority)
e.feature. The availability of a capability
e.proof. Supplied material fails verification against a reference
e.party. Another actor's conduct or choice
e.state. The condition of the target
e.env. A system we depend on that did not deliver
e.self. Us — our fault, or we cannot attribute it
e.rule. A norm we enforce, neither authority nor verification

Every code (288)

Code Title
e.env.answer.malformed.f A gate stage answered with something the gate cannot read.
e.env.filesystem.f The filesystem refused, so there is nothing I can do about it from here.
e.env.hold.unopenable.f The file this body takes its hold on could not be opened.
e.env.mailbox.timeout.r No mailbox answered, so nothing was delivered and nothing was read.
e.env.missing.tui.f The interactive pieces of heti are not installed, so I cannot start the terminal interface.
e.env.observer.unavailable.r I could not get a usable answer from the Observer, so I will not conclude the credential is current.
e.env.oobi.timeout.r The OOBI I was given did not answer, so I learned nothing from it.
e.env.registrar.unavailable.r I could not reach the Registrar to change this Observer's subscription.
e.env.watcher.timeout.r A source I asked didn't answer in time.
e.env.witness.throwaway.r I could not stand a temporary witness up, so there is nothing here to point an identifier at.
e.feature.unsupported.acdc.edges.f That credential chains to another through an edge I can't accept without checking it.
e.feature.unsupported.acdc.edges.operator.f That credential's chain uses a rule I cannot evaluate, so I won't pretend it holds.
e.feature.unsupported.addressing.time.f I can't answer a question addressed by wall-clock time, only by a place in the key history.
e.feature.unsupported.aid.nontrans.f This identifier can't rotate, so it has no key history for me to replay.
e.feature.unsupported.aid.trans.f The signer is a transferable AID, which I can't verify from ephemeral evidence alone.
e.feature.unsupported.alg.f The signature uses an algorithm I don't verify.
e.feature.unsupported.archive.f That backup was written in a format this build of heti does not restore.
e.feature.unsupported.comp.f The signature covers a derived component I can't handle.
e.feature.unsupported.digest.f This record was digested with an algorithm we cannot compute.
e.feature.unsupported.floor.kind.f The floor names a predicate kind this body cannot evaluate.
e.feature.unsupported.floor.version.f The floor is written to a version of the artifact this body does not implement.
e.feature.unsupported.genus.f The evidence names a CESR genus version I don't speak, so I won't guess at its framing.
e.feature.unsupported.group.direct.f This group cannot issue directly until its members can jointly anchor that act.
e.feature.unsupported.group.single-signature.f This jointly controlled identifier needs a joint signing ceremony for that act.
e.feature.unsupported.ipex.f That is an IPEX negotiation verb, which I don't speak yet.
e.feature.unsupported.multisig.sign.f Signing as a multisig identifier isn't built yet, so I can't produce this.
e.feature.unsupported.request-algorithm.f This facet's key algorithm cannot be named in the KERI HTTP signature dialect.
e.feature.unsupported.sedi-profile.f That schema claims a SEDI profile I have not reviewed, so I cannot use its profile fields.
e.feature.unsupported.threshold.nested.f That signing threshold has clauses inside clauses, and I don't build groups from those.
e.grant.constraint.unenforced.f The charter carries a constraint this body has no way to apply.
e.grant.constraint.unrecognized.f The charter carries a constraint the standard does not define.
e.grant.expired.f This steward's charter does not authorize it to act at this moment.
e.grant.quota.dispatch.attempts.f The commission has used every attempt its duty allows.
e.grant.token.scope.f The effect-intent does not name a scope inside this steward's publish directory.
e.grant.token.spent.f This effect-intent has already been credentialed once.
e.id.invalid.batch.f That batch is not signed by the Registrar this Observer is subscribed to, so I ignore it.
e.id.invalid.observer.f The answer did not come from the Observer I am pinned to, so I will not use it.
e.id.invalid.passcode.f That passcode doesn't open this lockbox.
e.id.invalid.secret.f That secret doesn't open this archive.
e.input.charter.unreadable.f The charter this body was given is not one it can act under.
e.input.format.acdc.bytes.f Those bytes don't read as an ACDC I can verify.
e.input.format.acdc.edges.f That credential's edge section is not shaped like one, so I refuse it.
e.input.format.acdc.f The credential you asked for does not fit the schema you named, so nothing was issued.
e.input.format.algorithm.f That is not a signing algorithm I can mint with.
e.input.format.alias.f I could not make an alias out of that, so nothing was named.
e.input.format.alias.flag.f That flag cannot go on that alias, so nothing was changed.
e.input.format.archive.f That file is not an archive I can read, so I restored nothing.
e.input.format.archive.foreign.f That is an archive, and it is not a heti lockbox backup.
e.input.format.batch.f That batch does not have the shape a Registrar sends, so I ignore it.
e.input.format.command.f I could not read that command, so I did nothing.
e.input.format.command.verb.f That is not a command I know, so I did nothing.
e.input.format.config.f Your heti settings are not readable as TOML, so I did nothing with them.
e.input.format.config.witnesses.f Your heti settings do not say which witnesses they mean, so I did nothing with them.
e.input.format.contact.aid.f That isn't a well-formed identifier, so there is nothing for me to write down.
e.input.format.contact.trans.f That identifier can rotate its keys, so the identifier alone tells me nothing about it.
e.input.format.delivery.f Those bytes are not something I can carry, or not something I can read as an artifact.
e.input.format.designator.f A designator was named that is not one of the three this module knows.
e.input.format.designator.source.f A source was built for a designator that cannot be one.
e.input.format.digest.f I couldn't read the Content-Digest header.
e.input.format.duplicate-key.f The entry uses one key twice.
e.input.format.duty.id.f The duty's id is not one a commission can be named after.
e.input.format.encoding.f The entry is not UTF-8 without a byte-order mark.
e.input.format.entry.at.f The entry's position is not a whole number counting from zero.
e.input.format.entry.body.f The entry's body is not a mapping.
e.input.format.entry.kind.f The entry names a kind the record does not have.
e.input.format.entry.missing.f The entry's envelope is missing a field every entry carries.
e.input.format.entry.schema.f The entry does not match the schema it names.
e.input.format.entry.unknown.f The entry's envelope carries a field the schema does not declare.
e.input.format.entry.version.f The entry's version is not semver.
e.input.format.evidence.f I couldn't parse the evidence stream, and reading further wouldn't help.
e.input.format.farnode.unneeded.f You presented a far node the credential does not rest on, so I refuse the bundle.
e.input.format.float.f The entry holds a number that is not a whole number.
e.input.format.floor.entry.id.f The floor names one entry twice.
e.input.format.floor.entry.shape.f A floor entry does not carry what its kind needs.
e.input.format.floor.f The floor artifact does not match the floor schema.
e.input.format.floor.fact.f A floor entry reads a fact the floor does not declare.
e.input.format.floor.fact.shape.f A floor entry reads a fact whose declared shape its kind cannot use.
e.input.format.floor.precondition.f A floor entry rests on a precondition the floor does not declare.
e.input.format.grant.f That is not an IPEX grant I can act on, so I stopped before judging anything.
e.input.format.identifier.f That value is not an identifier I can recognize, so I drew nothing for it.
e.input.format.intent.id.f The effect-intent id is not one the record can be about.
e.input.format.key.f The signature names a key I can't read.
e.input.format.member.absent.f That roster doesn't name this identifier, so there is nothing here for it to sign.
e.input.format.member.dup.f You named the same member more than once, and I won't count one key-holder twice.
e.input.format.member.keys.f One of the members you named has more than one signing key, so it cannot contribute one.
e.input.format.member.leaver.f You named somebody as departing who holds no rotation authority here to give up.
e.input.format.member.leaving.f You named the same member as both departing and staying, so I can't tell which you meant.
e.input.format.nested-said.f This nested `d` cannot be issued safely under its schema.
e.input.format.nonce-seal.f That AID or challenge nonce is malformed, so I cannot check its KEL seal.
e.input.format.not-an-object.f The entry is not a JSON object.
e.input.format.observer.read.f A registry read must name one registry by its identifier and carry one nonce of 16 to 64 base64url characters for me to sign over.
e.input.format.oobi.aid.f That address names an identifier and a role, not a document, so it holds no schema.
e.input.format.oobi.data.f That address serves a document, not an identifier, so there is no key state in it.
e.input.format.oversize.f That answered with more than I will hold, so I stopped reading and learned nothing.
e.input.format.proposal.f That isn't a group proposal I can read, so I stopped before deriving anything.
e.input.format.registry.f The registry evidence does not verify, and reading it further would not help.
e.input.format.request-url.unsigned.f This request URL has a query or fragment that its KERI signature cannot cover.
e.input.format.request.f That isn't a delegated establishment event, so there is nothing here to approve.
e.input.format.resource.f The Signify-Resource isn't a valid AID.
e.input.format.rules.f That rules value is not a SAID, so I won't issue a credential that points at it.
e.input.format.schema.f That schema does not address itself, so I won't store it.
e.input.format.seal.f That is not a seal shape I can anchor, so I stopped before writing anything.
e.input.format.sig.f I couldn't parse the Signature header.
e.input.format.sig.input.f I couldn't parse the Signature-Input header.
e.input.format.sig.label.f The Signature-Input and Signature headers must carry exactly one matching signature label.
e.input.format.sig.value.f The Signature header's value isn't a byte sequence, so there is no signature to check.
e.input.format.signed-acdc.f Those bytes do not contain one signed ACDC, so I cannot verify them.
e.input.format.unparseable.f The entry is not one JSON document.
e.input.format.witness.absent.f You asked me to cut a witness this facet has not designated.
e.input.format.witness.aid.f One of the witnesses you named isn't a well-formed identifier.
e.input.format.witness.dup.f You named the same witness more than once, and I won't count it twice.
e.input.format.witness.overlap.f You asked me to cut and add the same witness in one rotation.
e.input.format.witness.trans.f A witness has to be non-transferable, and one you named can rotate its keys.
e.input.format.witness.url.f A witness is named here by its identifier, and an address is not one.
e.input.missing.blinder.f The blinded registry head needs its disclosed state before I can judge the credential.
e.input.missing.confirmation.abandoned.f That was not the word abandoned, so that identifier's future is untouched.
e.input.missing.confirmation.f That was not the word confirmed, so nothing was recorded.
e.input.missing.confirmation.forgotten.f That was not the word forgotten, so this lockbox still keeps that credential.
e.input.missing.covered-comp.f The request is missing something the signature covers, so I can't rebuild what was signed.
e.input.missing.digest.f The request carries a body, but the signature doesn't cover a digest of it, so signing would leave the body unprotected.
e.input.missing.evidence.f You asked me to verify with no materials at all, so there is nothing to replay.
e.input.missing.evidence.farnode.f That credential rests on another you did not present, so I cannot judge its edges.
e.input.missing.genus.f A segment doesn't say which CESR genus it speaks, so I would have to guess at its framing.
e.input.missing.key.f The signature carries no keyid and you supplied no key, so I have nothing to verify against.
e.input.missing.registry.f That credential names no registry, so there is no current state for an Observer to report.
e.input.missing.resource.f The request has no Signify-Resource header, so I don't know whose signature to check.
e.input.missing.sig.f The request has no Signature header, so there is nothing to verify.
e.input.missing.sig.input.f The request has no Signature-Input header, so I don't know which components were signed.
e.input.missing.sig.label.f The signature headers carry no entry for the label I need.
e.input.range.acdc.oversize.f The credential you handed me, or its registry evidence, is larger than I will read.
e.input.range.blinder.f The disclosed blinded state is too large to inspect.
e.input.range.entry.depth.f The entry nests deeper than an entry may nest.
e.input.range.entry.size.f The entry is larger than an entry may be.
e.input.range.farnode.oversize.f One of the far nodes you handed me is larger than I will read.
e.input.range.farnodes.f You handed me more far nodes than I will verify for one credential.
e.input.range.grant-age.f That grant is older than I am willing to hold an unfinished one, so I have not kept it.
e.input.range.grant.body.oversize.f That grant's exchange would be larger than one KERI message can be.
e.input.range.grant.oversize.f That grant is larger than I will read.
e.input.range.integer.f The entry holds a whole number too large to survive being read.
e.input.range.kel.f A source sent more than I will read for one key history, so I stopped reading.
e.input.range.passcode.f That passcode is too short to protect a lockbox, so I won't build one around it.
e.input.range.roster.f That would leave the group with nobody holding rotation authority, which abandons it.
e.input.range.secret.f That secret is too short to protect an archive, so I won't build one around it.
e.input.range.signed-acdc.f This signed ACDC would be too large for its verifier to accept.
e.input.range.sith.f That signing threshold cannot be met by the members you named.
e.input.range.toad.f That witness threshold cannot be met by the witnesses you named.
e.party.refused.subscription.f The Registrar refused this Observer's subscription request.
e.proof.aggregate.f The credential's aggregate does not derive the identifier it claims, so I refuse it.
e.proof.anchor.chain.f The anchor chain does not hold together.
e.proof.anchor.f The only seal for that artifact sits in somebody else's key history, and an endorsement is not a commitment.
e.proof.anchor.head.f An anchor names a commit the record's history does not contain.
e.proof.attributes.said.f That attribute block doesn't address itself, so I stopped rather than quietly relabelling it.
e.proof.binding.f The registry evidence does not bind the credential you presented, so I refuse the substitution.
e.proof.binding.presentation-registry.f The presentation registry disagrees with an identity source, so I refuse the presentation.
e.proof.binding.sedi-age-identity.f That age credential does not bind itself to a Core identity, so I refuse it.
e.proof.binding.sedi-guardians.f That Core's guardians group does not name guardianships the way SEDI does, so I refuse it.
e.proof.binding.ward-authority.f The ward authorization rests on a guardianship its ward's Core does not name, so I refuse the graph.
e.proof.binding.ward-issuee.f A guardianship this Core's guardians group names does not name the Core's issuee as its ward, so I refuse the graph.
e.proof.blind.f The disclosed registry state does not verify, so I cannot judge the credential.
e.proof.chain.edge.f An edge in that credential's chain does not hold, so I refuse it.
e.proof.claim.proofing-datetime.f The signed ACDC does not disclose a valid timezone-aware proofing datetime.
e.proof.claim.signed-acdc.f The signed ACDC does not disclose a valid issuee and challenge nonce.
e.proof.endorsement.sig.f A segment's endorsement doesn't verify, so I can't tell who supplied it.
e.proof.event.chain.f A key event's prior digest doesn't match the event it claims to follow, so the chain breaks.
e.proof.event.sig.f A key event's controller signature doesn't verify, so the key history isn't authentic.
e.proof.grant.recipient.f That grant is addressed to somebody else, so I won't admit it.
e.proof.presenter.f That credential names an issuee, and the party presenting it is neither the issuee nor the issuer.
e.proof.request.digest.f The request body doesn't match its Content-Digest, so I can't treat the body as the one that was signed.
e.proof.request.sig.f The signature doesn't match the request under the signer's key, so I can't treat the request as authentic.
e.proof.rotation.digest.f The keys about to be revealed don't re-digest to what this key history committed to.
e.proof.rules.said.f That rules block doesn't address itself, so I stopped rather than quietly relabelling it.
e.proof.said.f A document does not hash to the SAID it carries.
e.proof.schema.f The credential does not validate against the schema it names, so I refuse it.
e.proof.schema.said.f The address I fetched a schema from served a different schema, so I stored nothing.
e.proof.sig.f The signature doesn't match the data under the signer's key state.
e.proof.sig.grant.f The grant's signature does not verify against its sender's current key state, so I won't admit it.
e.proof.signature.acdc.f The issuer's referenced key state does not satisfy this ACDC's signatures.
e.proof.signature.reference.f The signature names an establishment event that disagrees with the issuer's verified key history.
e.rule.expired.f The signature is past the expiry its own signer declared, so I won't accept it.
e.rule.stale.f The signature is outside the age limit this verifier accepts.
e.self.config.clock.f Nothing was waiting, but these two clocks disagree by too much for that to mean anything.
e.self.config.dispatch.f The command this body would dispatch names a path its sandbox cannot reach.
e.self.config.duty.f The record holds a commission for a duty this body does not carry.
e.self.config.effect.class.f The duty declares an effect class the machine does not have.
e.self.config.home.f The home this body was pointed at is not one it can animate a steward from.
e.self.config.machine.action.f The machine declares an action nothing in the outbox runs.
e.self.config.machine.cell.f The machine declaration says nothing about this combination of state and event.
e.self.config.machine.declaration.f The machine declaration this body loaded does not hold together.
e.self.config.machine.guard.f The machine declaration has no outcome for this point of a guard context.
e.self.config.mail.credential.f This body is configured to use email and has no password to authenticate with.
e.self.config.mail.f The mail configuration is not one this body can open a channel from.
e.self.config.oracle.f The oracle specification is not one this body can grade an artifact with.
e.self.config.sandbox.f The sandbox declaration is not one this body can contain a worker with.
e.self.corrupt.declarations.f I can't read my own record of what this lockbox's witnesses have declared, so I stopped.
e.self.corrupt.fold.disagrees.f The record says a transition reached a state that folding its events does not reach.
e.self.corrupt.machines.f The machine declaration this body loaded is not the one it was built against.
e.self.corrupt.projection.f The record's own account of a transition disagrees with the machine's.
e.self.corrupt.queue.claim.f The record's queue cannot tell whether its last write landed.
e.self.corrupt.queue.item.f An act waiting to be written to the record cannot be read back.
e.self.record.write.f A git command against the record did not succeed.
e.state.conflict.abandoned.f This facet was abandoned, so it cannot perform this act.
e.state.conflict.acdc.revoked.f That credential has been revoked, so I refuse it rather than describe it.
e.state.conflict.acdc.revoked.farnode.f That credential rests on one that has been revoked, so I refuse it.
e.state.conflict.act.diverged.f This group already has a different act in flight at that point in its key history, so signing this one would fork it.
e.state.conflict.alias.f More than one facet answers to that alias, so I won't guess which you meant.
e.state.conflict.alias.flag.f heti keeps that flag up to date itself, so it is not one to edit by hand.
e.state.conflict.archive.f Something is already at that path, and I won't write over a backup nobody asked me to.
e.state.conflict.attestation.f That credential is attested two different ways at once, and I won't choose between them.
e.state.conflict.batch.old.f I have already taken a batch with that number or a later one, so I ignore this one.
e.state.conflict.batch.subscription.f That batch belongs to a subscription this Observer no longer holds, so I ignore it.
e.state.conflict.core.held.f Another body already holds this core.
e.state.conflict.credential.prefix.f More than one credential starts with that, so I won't guess which you meant.
e.state.conflict.delegator.f That request asks a different identifier to approve it, so this one will not.
e.state.conflict.derivation.f I derive a different event from that configuration, so signing it would fork the group.
e.state.conflict.duplicity.f This identifier's key history forks: two valid, conflicting events share one place in it.
e.state.conflict.ejection.f That rotation leaves out a member this group's rotation threshold cannot spare.
e.state.conflict.f The machine is not in a state that admits this event.
e.state.conflict.facet.mine.f That identifier is already one of this lockbox's own facets, so it cannot also be a contact.
e.state.conflict.facet.multisig.f That identifier is a multisig, so this is not an act you can perform alone.
e.state.conflict.facet.own.f That alias names your own identifier, and this act only applies to somebody else's.
e.state.conflict.facet.solo.f That identifier is yours alone, so there is nobody to circulate a proposal to.
e.state.conflict.facet.theirs.f That alias names somebody else's identifier, and you can only act as your own.
e.state.conflict.file.f Something is already at that path, so I wrote nothing.
e.state.conflict.gid.f That signature is for a different group, so I won't fold it into this one.
e.state.conflict.hold.r Another body holds the hold on this core, so this one will not run.
e.state.conflict.identifier.joint.f This identifier is a multisig, so that act has to be proposed rather than performed alone.
e.state.conflict.lockbox.busy.f This lockbox is open in this process, and I won't copy a store somebody is writing to.
e.state.conflict.lockbox.closed.f This lockbox is closed, and I won't quietly reopen one you shut.
e.state.conflict.lockbox.exists.f There is already a lockbox here, and I will not write over key material.
e.state.conflict.lockbox.held.f This lockbox is open in another program on this machine.
e.state.conflict.lockbox.open.f This lockbox is already open in this process, and a second handle onto it can destroy keys.
e.state.conflict.member.moved.f A member's keys have moved since this configuration was made, so it derives nothing now.
e.state.conflict.not-delegated.f That identifier has no delegator, so there is nothing for anybody to approve.
e.state.conflict.not-sender.f That artifact is somebody else's to send, because they are the one who endorsed it.
e.state.conflict.prior.f That rotation follows a different event than this group's latest, so I won't sign it.
e.state.conflict.record.busy.r Another writer holds the record.
e.state.conflict.record.exists.f There is already a record here.
e.state.conflict.record.genesis.f That kind of entry is the record's to write, not a caller's.
e.state.conflict.record.head.f Another writer moved the record while this write was in flight.
e.state.conflict.record.position.f The entry is numbered for a position the record is not at.
e.state.conflict.record.second-writer.f Something else wrote to the record while a queued write was in flight.
e.state.conflict.registry.choice.f That identifier owns more than one registry, so I won't choose which to issue in.
e.state.conflict.registry.exists.f A registry with that identifier is already in this lockbox, and a second one would silently become the first.
e.state.conflict.registry.f The registry evidence conflicts with itself, so no state can be established from it.
e.state.conflict.registry.gid.f That registry event belongs to a different registry than the proposal names, so I won't act on it.
e.state.conflict.registry.joint.f This registry is jointly controlled, so that verb would produce something no verifier could accept.
e.state.conflict.registry.solo.f This registry has one controller, so there is nobody to circulate a proposal to.
e.state.conflict.revoked.f That credential is already revoked, and revoking it again would add nothing but noise.
e.state.conflict.schema.prefix.f More than one schema starts with that, so I won't guess which you meant.
e.state.conflict.seal.f That proposal's anchoring event doesn't seal the registry event it carries, so I won't sign it.
e.state.conflict.trait.f This facet's own configuration forbids the event you asked for.
e.state.conflict.witness-change.f That rotation changes the delegatee's witness pool too much for me to approve unseen.
e.state.missing.conceal.f There is nothing at that path to conceal, so I won't hand back a disclosure that hid nothing.
e.state.missing.credential.f This identifier keeps no copy of that credential, so there is nothing here to act on.
e.state.missing.effect.intent.f The record holds no effect-intent with that id.
e.state.missing.endpoint.f I don't know where to reach one of the witnesses you named, so I won't designate it.
e.state.missing.entry.schema.f The entry names a schema this record does not carry.
e.state.missing.facet.f This lockbox holds no facet like that.
e.state.missing.farnode.standing.f A credential in that chain has a registry that does not establish its standing.
e.state.missing.issuance.f This registry does not currently attest that credential, so there is nothing to revoke.
e.state.missing.kel.r The evidence doesn't reach that far, so gathering more may answer it.
e.state.missing.kel.roleless.r That address established no identifier, and since it names no role it may name a document.
e.state.missing.lockbox.f There is no lockbox where you pointed me.
e.state.missing.mailbox.f I have no mailbox to reach that party at, so there is nowhere to leave this.
e.state.missing.oobi.f I hold no address for that identifier, so there is nothing to fetch.
e.state.missing.parent.f The directory that would hold this lockbox does not exist, and I won't create a tree of them.
e.state.missing.record.entry.f The record has nothing at that path.
e.state.missing.registry.f That identifier owns no registry, and a credential has to be issued in one.
e.state.missing.registry.named.f That identifier owns no registry by that name.
e.state.missing.schema.f I don't hold the schema this credential names, so I cannot validate anything against it.
e.state.missing.session.facet.f No identifier is active, so I don't know in which capacity you mean to act.
e.state.missing.session.lockbox.f No lockbox is open, so there is nothing for that command to work with.
e.state.pending.agreement.r Not enough sources agree yet, so I'm not ready to answer.
e.state.pending.anchor.r Nothing in the issuer's key history anchors that artifact yet, so I can establish nothing about it.
e.state.pending.approval.r This identifier's delegator hasn't approved its latest establishment event yet.
e.state.pending.batch.backlog.r The Observer's batch queue is full, so I have not accepted this batch.
e.state.pending.corroboration.r Too few of this identifier's own witnesses answered for me to trust what I learned.
e.state.pending.escrow.r An event arrived before the one it builds on, so I'm waiting for the gap to be filled.
e.state.pending.establishment.r The issuer's verified key history does not yet contain the signature's named establishment event.
e.state.pending.freshness.r The Observer's last batch is older than your freshness bound, so its registry state may be out of date.
e.state.pending.member-keys.r This group's members haven't rotated their own identifiers yet, so it cannot rotate.
e.state.pending.nonce-seal.r The named challenge nonce is not yet sealed in that identifier's verified key history.
e.state.pending.observation.r My view of a key history is older than the bound you set, so I won't conclude from it.
e.state.pending.prior.r This facet's previous act was still short of its witnesses, so I finished that instead.
e.state.pending.registry.r The Observer has never heard of that credential's registry, so I cannot say it is current.
e.state.pending.resync.r The Observer missed a batch and is resynchronizing, so its registry state may be incomplete.
e.state.pending.signatures.r This group hasn't collected enough signatures yet, so it has no key state to answer from.
e.state.pending.witness.r The log isn't witnessed enough yet for me to accept it, so more receipts may settle it.