Bakobo error codes¶
Every error Bakobo reports carries a stable symbolic code, and every code has a page here. If you arrived from the type member of a problem+json response, the page you want is the code itself.
How to read a code¶
A Bakobo error code reads left to right, growing more specific:
The sorter is e for an error, whose consequences are clear, or w for a warning, whose
consequences need someone's judgment. The descriptor says what the obstacle was, and comes from
a closed set of ten. The disposition is the last token, f if retrying changes nothing and r
if it might help — last, so that e.state. matches every target-condition failure whichever way it
disposes.
A first descriptor is a category, never a code. e.proof. names a kind of obstacle rather than one
condition, so every code carries at least one sub-descriptor and a bare descriptor appears only as
a pattern to match against.
The ten obstacles¶
| Descriptor | The obstacle |
|---|---|
e.input. |
What you sent |
e.id. |
Who you are (authentication) |
e.grant. |
What you may do (delegated authority) |
e.feature. |
The availability of a capability |
e.proof. |
Supplied material fails verification against a reference |
e.party. |
Another actor's conduct or choice |
e.state. |
The condition of the target |
e.env. |
A system we depend on that did not deliver |
e.self. |
Us — our fault, or we cannot attribute it |
e.rule. |
A norm we enforce, neither authority nor verification |
Every code (288)¶
| Code | Title |
|---|---|
e.env.answer.malformed.f |
A gate stage answered with something the gate cannot read. |
e.env.filesystem.f |
The filesystem refused, so there is nothing I can do about it from here. |
e.env.hold.unopenable.f |
The file this body takes its hold on could not be opened. |
e.env.mailbox.timeout.r |
No mailbox answered, so nothing was delivered and nothing was read. |
e.env.missing.tui.f |
The interactive pieces of heti are not installed, so I cannot start the terminal interface. |
e.env.observer.unavailable.r |
I could not get a usable answer from the Observer, so I will not conclude the credential is current. |
e.env.oobi.timeout.r |
The OOBI I was given did not answer, so I learned nothing from it. |
e.env.registrar.unavailable.r |
I could not reach the Registrar to change this Observer's subscription. |
e.env.watcher.timeout.r |
A source I asked didn't answer in time. |
e.env.witness.throwaway.r |
I could not stand a temporary witness up, so there is nothing here to point an identifier at. |
e.feature.unsupported.acdc.edges.f |
That credential chains to another through an edge I can't accept without checking it. |
e.feature.unsupported.acdc.edges.operator.f |
That credential's chain uses a rule I cannot evaluate, so I won't pretend it holds. |
e.feature.unsupported.addressing.time.f |
I can't answer a question addressed by wall-clock time, only by a place in the key history. |
e.feature.unsupported.aid.nontrans.f |
This identifier can't rotate, so it has no key history for me to replay. |
e.feature.unsupported.aid.trans.f |
The signer is a transferable AID, which I can't verify from ephemeral evidence alone. |
e.feature.unsupported.alg.f |
The signature uses an algorithm I don't verify. |
e.feature.unsupported.archive.f |
That backup was written in a format this build of heti does not restore. |
e.feature.unsupported.comp.f |
The signature covers a derived component I can't handle. |
e.feature.unsupported.digest.f |
This record was digested with an algorithm we cannot compute. |
e.feature.unsupported.floor.kind.f |
The floor names a predicate kind this body cannot evaluate. |
e.feature.unsupported.floor.version.f |
The floor is written to a version of the artifact this body does not implement. |
e.feature.unsupported.genus.f |
The evidence names a CESR genus version I don't speak, so I won't guess at its framing. |
e.feature.unsupported.group.direct.f |
This group cannot issue directly until its members can jointly anchor that act. |
e.feature.unsupported.group.single-signature.f |
This jointly controlled identifier needs a joint signing ceremony for that act. |
e.feature.unsupported.ipex.f |
That is an IPEX negotiation verb, which I don't speak yet. |
e.feature.unsupported.multisig.sign.f |
Signing as a multisig identifier isn't built yet, so I can't produce this. |
e.feature.unsupported.request-algorithm.f |
This facet's key algorithm cannot be named in the KERI HTTP signature dialect. |
e.feature.unsupported.sedi-profile.f |
That schema claims a SEDI profile I have not reviewed, so I cannot use its profile fields. |
e.feature.unsupported.threshold.nested.f |
That signing threshold has clauses inside clauses, and I don't build groups from those. |
e.grant.constraint.unenforced.f |
The charter carries a constraint this body has no way to apply. |
e.grant.constraint.unrecognized.f |
The charter carries a constraint the standard does not define. |
e.grant.expired.f |
This steward's charter does not authorize it to act at this moment. |
e.grant.quota.dispatch.attempts.f |
The commission has used every attempt its duty allows. |
e.grant.token.scope.f |
The effect-intent does not name a scope inside this steward's publish directory. |
e.grant.token.spent.f |
This effect-intent has already been credentialed once. |
e.id.invalid.batch.f |
That batch is not signed by the Registrar this Observer is subscribed to, so I ignore it. |
e.id.invalid.observer.f |
The answer did not come from the Observer I am pinned to, so I will not use it. |
e.id.invalid.passcode.f |
That passcode doesn't open this lockbox. |
e.id.invalid.secret.f |
That secret doesn't open this archive. |
e.input.charter.unreadable.f |
The charter this body was given is not one it can act under. |
e.input.format.acdc.bytes.f |
Those bytes don't read as an ACDC I can verify. |
e.input.format.acdc.edges.f |
That credential's edge section is not shaped like one, so I refuse it. |
e.input.format.acdc.f |
The credential you asked for does not fit the schema you named, so nothing was issued. |
e.input.format.algorithm.f |
That is not a signing algorithm I can mint with. |
e.input.format.alias.f |
I could not make an alias out of that, so nothing was named. |
e.input.format.alias.flag.f |
That flag cannot go on that alias, so nothing was changed. |
e.input.format.archive.f |
That file is not an archive I can read, so I restored nothing. |
e.input.format.archive.foreign.f |
That is an archive, and it is not a heti lockbox backup. |
e.input.format.batch.f |
That batch does not have the shape a Registrar sends, so I ignore it. |
e.input.format.command.f |
I could not read that command, so I did nothing. |
e.input.format.command.verb.f |
That is not a command I know, so I did nothing. |
e.input.format.config.f |
Your heti settings are not readable as TOML, so I did nothing with them. |
e.input.format.config.witnesses.f |
Your heti settings do not say which witnesses they mean, so I did nothing with them. |
e.input.format.contact.aid.f |
That isn't a well-formed identifier, so there is nothing for me to write down. |
e.input.format.contact.trans.f |
That identifier can rotate its keys, so the identifier alone tells me nothing about it. |
e.input.format.delivery.f |
Those bytes are not something I can carry, or not something I can read as an artifact. |
e.input.format.designator.f |
A designator was named that is not one of the three this module knows. |
e.input.format.designator.source.f |
A source was built for a designator that cannot be one. |
e.input.format.digest.f |
I couldn't read the Content-Digest header. |
e.input.format.duplicate-key.f |
The entry uses one key twice. |
e.input.format.duty.id.f |
The duty's id is not one a commission can be named after. |
e.input.format.encoding.f |
The entry is not UTF-8 without a byte-order mark. |
e.input.format.entry.at.f |
The entry's position is not a whole number counting from zero. |
e.input.format.entry.body.f |
The entry's body is not a mapping. |
e.input.format.entry.kind.f |
The entry names a kind the record does not have. |
e.input.format.entry.missing.f |
The entry's envelope is missing a field every entry carries. |
e.input.format.entry.schema.f |
The entry does not match the schema it names. |
e.input.format.entry.unknown.f |
The entry's envelope carries a field the schema does not declare. |
e.input.format.entry.version.f |
The entry's version is not semver. |
e.input.format.evidence.f |
I couldn't parse the evidence stream, and reading further wouldn't help. |
e.input.format.farnode.unneeded.f |
You presented a far node the credential does not rest on, so I refuse the bundle. |
e.input.format.float.f |
The entry holds a number that is not a whole number. |
e.input.format.floor.entry.id.f |
The floor names one entry twice. |
e.input.format.floor.entry.shape.f |
A floor entry does not carry what its kind needs. |
e.input.format.floor.f |
The floor artifact does not match the floor schema. |
e.input.format.floor.fact.f |
A floor entry reads a fact the floor does not declare. |
e.input.format.floor.fact.shape.f |
A floor entry reads a fact whose declared shape its kind cannot use. |
e.input.format.floor.precondition.f |
A floor entry rests on a precondition the floor does not declare. |
e.input.format.grant.f |
That is not an IPEX grant I can act on, so I stopped before judging anything. |
e.input.format.identifier.f |
That value is not an identifier I can recognize, so I drew nothing for it. |
e.input.format.intent.id.f |
The effect-intent id is not one the record can be about. |
e.input.format.key.f |
The signature names a key I can't read. |
e.input.format.member.absent.f |
That roster doesn't name this identifier, so there is nothing here for it to sign. |
e.input.format.member.dup.f |
You named the same member more than once, and I won't count one key-holder twice. |
e.input.format.member.keys.f |
One of the members you named has more than one signing key, so it cannot contribute one. |
e.input.format.member.leaver.f |
You named somebody as departing who holds no rotation authority here to give up. |
e.input.format.member.leaving.f |
You named the same member as both departing and staying, so I can't tell which you meant. |
e.input.format.nested-said.f |
This nested `d` cannot be issued safely under its schema. |
e.input.format.nonce-seal.f |
That AID or challenge nonce is malformed, so I cannot check its KEL seal. |
e.input.format.not-an-object.f |
The entry is not a JSON object. |
e.input.format.observer.read.f |
A registry read must name one registry by its identifier and carry one nonce of 16 to 64 base64url characters for me to sign over. |
e.input.format.oobi.aid.f |
That address names an identifier and a role, not a document, so it holds no schema. |
e.input.format.oobi.data.f |
That address serves a document, not an identifier, so there is no key state in it. |
e.input.format.oversize.f |
That answered with more than I will hold, so I stopped reading and learned nothing. |
e.input.format.proposal.f |
That isn't a group proposal I can read, so I stopped before deriving anything. |
e.input.format.registry.f |
The registry evidence does not verify, and reading it further would not help. |
e.input.format.request-url.unsigned.f |
This request URL has a query or fragment that its KERI signature cannot cover. |
e.input.format.request.f |
That isn't a delegated establishment event, so there is nothing here to approve. |
e.input.format.resource.f |
The Signify-Resource isn't a valid AID. |
e.input.format.rules.f |
That rules value is not a SAID, so I won't issue a credential that points at it. |
e.input.format.schema.f |
That schema does not address itself, so I won't store it. |
e.input.format.seal.f |
That is not a seal shape I can anchor, so I stopped before writing anything. |
e.input.format.sig.f |
I couldn't parse the Signature header. |
e.input.format.sig.input.f |
I couldn't parse the Signature-Input header. |
e.input.format.sig.label.f |
The Signature-Input and Signature headers must carry exactly one matching signature label. |
e.input.format.sig.value.f |
The Signature header's value isn't a byte sequence, so there is no signature to check. |
e.input.format.signed-acdc.f |
Those bytes do not contain one signed ACDC, so I cannot verify them. |
e.input.format.unparseable.f |
The entry is not one JSON document. |
e.input.format.witness.absent.f |
You asked me to cut a witness this facet has not designated. |
e.input.format.witness.aid.f |
One of the witnesses you named isn't a well-formed identifier. |
e.input.format.witness.dup.f |
You named the same witness more than once, and I won't count it twice. |
e.input.format.witness.overlap.f |
You asked me to cut and add the same witness in one rotation. |
e.input.format.witness.trans.f |
A witness has to be non-transferable, and one you named can rotate its keys. |
e.input.format.witness.url.f |
A witness is named here by its identifier, and an address is not one. |
e.input.missing.blinder.f |
The blinded registry head needs its disclosed state before I can judge the credential. |
e.input.missing.confirmation.abandoned.f |
That was not the word abandoned, so that identifier's future is untouched. |
e.input.missing.confirmation.f |
That was not the word confirmed, so nothing was recorded. |
e.input.missing.confirmation.forgotten.f |
That was not the word forgotten, so this lockbox still keeps that credential. |
e.input.missing.covered-comp.f |
The request is missing something the signature covers, so I can't rebuild what was signed. |
e.input.missing.digest.f |
The request carries a body, but the signature doesn't cover a digest of it, so signing would leave the body unprotected. |
e.input.missing.evidence.f |
You asked me to verify with no materials at all, so there is nothing to replay. |
e.input.missing.evidence.farnode.f |
That credential rests on another you did not present, so I cannot judge its edges. |
e.input.missing.genus.f |
A segment doesn't say which CESR genus it speaks, so I would have to guess at its framing. |
e.input.missing.key.f |
The signature carries no keyid and you supplied no key, so I have nothing to verify against. |
e.input.missing.registry.f |
That credential names no registry, so there is no current state for an Observer to report. |
e.input.missing.resource.f |
The request has no Signify-Resource header, so I don't know whose signature to check. |
e.input.missing.sig.f |
The request has no Signature header, so there is nothing to verify. |
e.input.missing.sig.input.f |
The request has no Signature-Input header, so I don't know which components were signed. |
e.input.missing.sig.label.f |
The signature headers carry no entry for the label I need. |
e.input.range.acdc.oversize.f |
The credential you handed me, or its registry evidence, is larger than I will read. |
e.input.range.blinder.f |
The disclosed blinded state is too large to inspect. |
e.input.range.entry.depth.f |
The entry nests deeper than an entry may nest. |
e.input.range.entry.size.f |
The entry is larger than an entry may be. |
e.input.range.farnode.oversize.f |
One of the far nodes you handed me is larger than I will read. |
e.input.range.farnodes.f |
You handed me more far nodes than I will verify for one credential. |
e.input.range.grant-age.f |
That grant is older than I am willing to hold an unfinished one, so I have not kept it. |
e.input.range.grant.body.oversize.f |
That grant's exchange would be larger than one KERI message can be. |
e.input.range.grant.oversize.f |
That grant is larger than I will read. |
e.input.range.integer.f |
The entry holds a whole number too large to survive being read. |
e.input.range.kel.f |
A source sent more than I will read for one key history, so I stopped reading. |
e.input.range.passcode.f |
That passcode is too short to protect a lockbox, so I won't build one around it. |
e.input.range.roster.f |
That would leave the group with nobody holding rotation authority, which abandons it. |
e.input.range.secret.f |
That secret is too short to protect an archive, so I won't build one around it. |
e.input.range.signed-acdc.f |
This signed ACDC would be too large for its verifier to accept. |
e.input.range.sith.f |
That signing threshold cannot be met by the members you named. |
e.input.range.toad.f |
That witness threshold cannot be met by the witnesses you named. |
e.party.refused.subscription.f |
The Registrar refused this Observer's subscription request. |
e.proof.aggregate.f |
The credential's aggregate does not derive the identifier it claims, so I refuse it. |
e.proof.anchor.chain.f |
The anchor chain does not hold together. |
e.proof.anchor.f |
The only seal for that artifact sits in somebody else's key history, and an endorsement is not a commitment. |
e.proof.anchor.head.f |
An anchor names a commit the record's history does not contain. |
e.proof.attributes.said.f |
That attribute block doesn't address itself, so I stopped rather than quietly relabelling it. |
e.proof.binding.f |
The registry evidence does not bind the credential you presented, so I refuse the substitution. |
e.proof.binding.presentation-registry.f |
The presentation registry disagrees with an identity source, so I refuse the presentation. |
e.proof.binding.sedi-age-identity.f |
That age credential does not bind itself to a Core identity, so I refuse it. |
e.proof.binding.sedi-guardians.f |
That Core's guardians group does not name guardianships the way SEDI does, so I refuse it. |
e.proof.binding.ward-authority.f |
The ward authorization rests on a guardianship its ward's Core does not name, so I refuse the graph. |
e.proof.binding.ward-issuee.f |
A guardianship this Core's guardians group names does not name the Core's issuee as its ward, so I refuse the graph. |
e.proof.blind.f |
The disclosed registry state does not verify, so I cannot judge the credential. |
e.proof.chain.edge.f |
An edge in that credential's chain does not hold, so I refuse it. |
e.proof.claim.proofing-datetime.f |
The signed ACDC does not disclose a valid timezone-aware proofing datetime. |
e.proof.claim.signed-acdc.f |
The signed ACDC does not disclose a valid issuee and challenge nonce. |
e.proof.endorsement.sig.f |
A segment's endorsement doesn't verify, so I can't tell who supplied it. |
e.proof.event.chain.f |
A key event's prior digest doesn't match the event it claims to follow, so the chain breaks. |
e.proof.event.sig.f |
A key event's controller signature doesn't verify, so the key history isn't authentic. |
e.proof.grant.recipient.f |
That grant is addressed to somebody else, so I won't admit it. |
e.proof.presenter.f |
That credential names an issuee, and the party presenting it is neither the issuee nor the issuer. |
e.proof.request.digest.f |
The request body doesn't match its Content-Digest, so I can't treat the body as the one that was signed. |
e.proof.request.sig.f |
The signature doesn't match the request under the signer's key, so I can't treat the request as authentic. |
e.proof.rotation.digest.f |
The keys about to be revealed don't re-digest to what this key history committed to. |
e.proof.rules.said.f |
That rules block doesn't address itself, so I stopped rather than quietly relabelling it. |
e.proof.said.f |
A document does not hash to the SAID it carries. |
e.proof.schema.f |
The credential does not validate against the schema it names, so I refuse it. |
e.proof.schema.said.f |
The address I fetched a schema from served a different schema, so I stored nothing. |
e.proof.sig.f |
The signature doesn't match the data under the signer's key state. |
e.proof.sig.grant.f |
The grant's signature does not verify against its sender's current key state, so I won't admit it. |
e.proof.signature.acdc.f |
The issuer's referenced key state does not satisfy this ACDC's signatures. |
e.proof.signature.reference.f |
The signature names an establishment event that disagrees with the issuer's verified key history. |
e.rule.expired.f |
The signature is past the expiry its own signer declared, so I won't accept it. |
e.rule.stale.f |
The signature is outside the age limit this verifier accepts. |
e.self.config.clock.f |
Nothing was waiting, but these two clocks disagree by too much for that to mean anything. |
e.self.config.dispatch.f |
The command this body would dispatch names a path its sandbox cannot reach. |
e.self.config.duty.f |
The record holds a commission for a duty this body does not carry. |
e.self.config.effect.class.f |
The duty declares an effect class the machine does not have. |
e.self.config.home.f |
The home this body was pointed at is not one it can animate a steward from. |
e.self.config.machine.action.f |
The machine declares an action nothing in the outbox runs. |
e.self.config.machine.cell.f |
The machine declaration says nothing about this combination of state and event. |
e.self.config.machine.declaration.f |
The machine declaration this body loaded does not hold together. |
e.self.config.machine.guard.f |
The machine declaration has no outcome for this point of a guard context. |
e.self.config.mail.credential.f |
This body is configured to use email and has no password to authenticate with. |
e.self.config.mail.f |
The mail configuration is not one this body can open a channel from. |
e.self.config.oracle.f |
The oracle specification is not one this body can grade an artifact with. |
e.self.config.sandbox.f |
The sandbox declaration is not one this body can contain a worker with. |
e.self.corrupt.declarations.f |
I can't read my own record of what this lockbox's witnesses have declared, so I stopped. |
e.self.corrupt.fold.disagrees.f |
The record says a transition reached a state that folding its events does not reach. |
e.self.corrupt.machines.f |
The machine declaration this body loaded is not the one it was built against. |
e.self.corrupt.projection.f |
The record's own account of a transition disagrees with the machine's. |
e.self.corrupt.queue.claim.f |
The record's queue cannot tell whether its last write landed. |
e.self.corrupt.queue.item.f |
An act waiting to be written to the record cannot be read back. |
e.self.record.write.f |
A git command against the record did not succeed. |
e.state.conflict.abandoned.f |
This facet was abandoned, so it cannot perform this act. |
e.state.conflict.acdc.revoked.f |
That credential has been revoked, so I refuse it rather than describe it. |
e.state.conflict.acdc.revoked.farnode.f |
That credential rests on one that has been revoked, so I refuse it. |
e.state.conflict.act.diverged.f |
This group already has a different act in flight at that point in its key history, so signing this one would fork it. |
e.state.conflict.alias.f |
More than one facet answers to that alias, so I won't guess which you meant. |
e.state.conflict.alias.flag.f |
heti keeps that flag up to date itself, so it is not one to edit by hand. |
e.state.conflict.archive.f |
Something is already at that path, and I won't write over a backup nobody asked me to. |
e.state.conflict.attestation.f |
That credential is attested two different ways at once, and I won't choose between them. |
e.state.conflict.batch.old.f |
I have already taken a batch with that number or a later one, so I ignore this one. |
e.state.conflict.batch.subscription.f |
That batch belongs to a subscription this Observer no longer holds, so I ignore it. |
e.state.conflict.core.held.f |
Another body already holds this core. |
e.state.conflict.credential.prefix.f |
More than one credential starts with that, so I won't guess which you meant. |
e.state.conflict.delegator.f |
That request asks a different identifier to approve it, so this one will not. |
e.state.conflict.derivation.f |
I derive a different event from that configuration, so signing it would fork the group. |
e.state.conflict.duplicity.f |
This identifier's key history forks: two valid, conflicting events share one place in it. |
e.state.conflict.ejection.f |
That rotation leaves out a member this group's rotation threshold cannot spare. |
e.state.conflict.f |
The machine is not in a state that admits this event. |
e.state.conflict.facet.mine.f |
That identifier is already one of this lockbox's own facets, so it cannot also be a contact. |
e.state.conflict.facet.multisig.f |
That identifier is a multisig, so this is not an act you can perform alone. |
e.state.conflict.facet.own.f |
That alias names your own identifier, and this act only applies to somebody else's. |
e.state.conflict.facet.solo.f |
That identifier is yours alone, so there is nobody to circulate a proposal to. |
e.state.conflict.facet.theirs.f |
That alias names somebody else's identifier, and you can only act as your own. |
e.state.conflict.file.f |
Something is already at that path, so I wrote nothing. |
e.state.conflict.gid.f |
That signature is for a different group, so I won't fold it into this one. |
e.state.conflict.hold.r |
Another body holds the hold on this core, so this one will not run. |
e.state.conflict.identifier.joint.f |
This identifier is a multisig, so that act has to be proposed rather than performed alone. |
e.state.conflict.lockbox.busy.f |
This lockbox is open in this process, and I won't copy a store somebody is writing to. |
e.state.conflict.lockbox.closed.f |
This lockbox is closed, and I won't quietly reopen one you shut. |
e.state.conflict.lockbox.exists.f |
There is already a lockbox here, and I will not write over key material. |
e.state.conflict.lockbox.held.f |
This lockbox is open in another program on this machine. |
e.state.conflict.lockbox.open.f |
This lockbox is already open in this process, and a second handle onto it can destroy keys. |
e.state.conflict.member.moved.f |
A member's keys have moved since this configuration was made, so it derives nothing now. |
e.state.conflict.not-delegated.f |
That identifier has no delegator, so there is nothing for anybody to approve. |
e.state.conflict.not-sender.f |
That artifact is somebody else's to send, because they are the one who endorsed it. |
e.state.conflict.prior.f |
That rotation follows a different event than this group's latest, so I won't sign it. |
e.state.conflict.record.busy.r |
Another writer holds the record. |
e.state.conflict.record.exists.f |
There is already a record here. |
e.state.conflict.record.genesis.f |
That kind of entry is the record's to write, not a caller's. |
e.state.conflict.record.head.f |
Another writer moved the record while this write was in flight. |
e.state.conflict.record.position.f |
The entry is numbered for a position the record is not at. |
e.state.conflict.record.second-writer.f |
Something else wrote to the record while a queued write was in flight. |
e.state.conflict.registry.choice.f |
That identifier owns more than one registry, so I won't choose which to issue in. |
e.state.conflict.registry.exists.f |
A registry with that identifier is already in this lockbox, and a second one would silently become the first. |
e.state.conflict.registry.f |
The registry evidence conflicts with itself, so no state can be established from it. |
e.state.conflict.registry.gid.f |
That registry event belongs to a different registry than the proposal names, so I won't act on it. |
e.state.conflict.registry.joint.f |
This registry is jointly controlled, so that verb would produce something no verifier could accept. |
e.state.conflict.registry.solo.f |
This registry has one controller, so there is nobody to circulate a proposal to. |
e.state.conflict.revoked.f |
That credential is already revoked, and revoking it again would add nothing but noise. |
e.state.conflict.schema.prefix.f |
More than one schema starts with that, so I won't guess which you meant. |
e.state.conflict.seal.f |
That proposal's anchoring event doesn't seal the registry event it carries, so I won't sign it. |
e.state.conflict.trait.f |
This facet's own configuration forbids the event you asked for. |
e.state.conflict.witness-change.f |
That rotation changes the delegatee's witness pool too much for me to approve unseen. |
e.state.missing.conceal.f |
There is nothing at that path to conceal, so I won't hand back a disclosure that hid nothing. |
e.state.missing.credential.f |
This identifier keeps no copy of that credential, so there is nothing here to act on. |
e.state.missing.effect.intent.f |
The record holds no effect-intent with that id. |
e.state.missing.endpoint.f |
I don't know where to reach one of the witnesses you named, so I won't designate it. |
e.state.missing.entry.schema.f |
The entry names a schema this record does not carry. |
e.state.missing.facet.f |
This lockbox holds no facet like that. |
e.state.missing.farnode.standing.f |
A credential in that chain has a registry that does not establish its standing. |
e.state.missing.issuance.f |
This registry does not currently attest that credential, so there is nothing to revoke. |
e.state.missing.kel.r |
The evidence doesn't reach that far, so gathering more may answer it. |
e.state.missing.kel.roleless.r |
That address established no identifier, and since it names no role it may name a document. |
e.state.missing.lockbox.f |
There is no lockbox where you pointed me. |
e.state.missing.mailbox.f |
I have no mailbox to reach that party at, so there is nowhere to leave this. |
e.state.missing.oobi.f |
I hold no address for that identifier, so there is nothing to fetch. |
e.state.missing.parent.f |
The directory that would hold this lockbox does not exist, and I won't create a tree of them. |
e.state.missing.record.entry.f |
The record has nothing at that path. |
e.state.missing.registry.f |
That identifier owns no registry, and a credential has to be issued in one. |
e.state.missing.registry.named.f |
That identifier owns no registry by that name. |
e.state.missing.schema.f |
I don't hold the schema this credential names, so I cannot validate anything against it. |
e.state.missing.session.facet.f |
No identifier is active, so I don't know in which capacity you mean to act. |
e.state.missing.session.lockbox.f |
No lockbox is open, so there is nothing for that command to work with. |
e.state.pending.agreement.r |
Not enough sources agree yet, so I'm not ready to answer. |
e.state.pending.anchor.r |
Nothing in the issuer's key history anchors that artifact yet, so I can establish nothing about it. |
e.state.pending.approval.r |
This identifier's delegator hasn't approved its latest establishment event yet. |
e.state.pending.batch.backlog.r |
The Observer's batch queue is full, so I have not accepted this batch. |
e.state.pending.corroboration.r |
Too few of this identifier's own witnesses answered for me to trust what I learned. |
e.state.pending.escrow.r |
An event arrived before the one it builds on, so I'm waiting for the gap to be filled. |
e.state.pending.establishment.r |
The issuer's verified key history does not yet contain the signature's named establishment event. |
e.state.pending.freshness.r |
The Observer's last batch is older than your freshness bound, so its registry state may be out of date. |
e.state.pending.member-keys.r |
This group's members haven't rotated their own identifiers yet, so it cannot rotate. |
e.state.pending.nonce-seal.r |
The named challenge nonce is not yet sealed in that identifier's verified key history. |
e.state.pending.observation.r |
My view of a key history is older than the bound you set, so I won't conclude from it. |
e.state.pending.prior.r |
This facet's previous act was still short of its witnesses, so I finished that instead. |
e.state.pending.registry.r |
The Observer has never heard of that credential's registry, so I cannot say it is current. |
e.state.pending.resync.r |
The Observer missed a batch and is resynchronizing, so its registry state may be incomplete. |
e.state.pending.signatures.r |
This group hasn't collected enough signatures yet, so it has no key state to answer from. |
e.state.pending.witness.r |
The log isn't witnessed enough yet for me to accept it, so more receipts may settle it. |