guardrail_violation
Prompt-injection or jailbreak guardrail tripped (names detected rule).
What it means
A prompt-injection or jailbreak guardrail tripped. Carries a detected field naming what fired.
How to recognise it
The gateway answers HTTP 400 with x-ace-error: guardrail_violation on the response, and a body in the shared error envelope:
{
"error": {
"message": "...",
"type": "guardrail_violation",
"code": 400
}
}
On a vendor-shaped surface (/anthropic/…, /gemini/…, /bedrock/…) the body wears that vendor's error envelope instead; the x-ace-error header is the same everywhere.
Is it ACE or the provider?
x-ace-error is present only on errors ACE originated. A vendor error relayed from upstream — a real provider 429, a provider 401 for a bad pass-through key — carries no x-ace-error, and its own type and code mean what the provider says. Read the header before deciding whether to retry, re-mint a key or surface the error.
Other 400 errors
request_error: The request was refused as sent — a body that does not parse, a missing or malformed field, a/v1/executevalidation failure, an unknownx-ace-skillspair, a Bedrock path/bodymodelIdmismatch, an API key sent beside an access-key pair, a mode this deployment cannot serve.
Related
- Error contracts & status codes: the full taxonomy
- Response header specification
- Echo mode: reproduce a call without spending