all docs
/ errors · HTTP 401

idp_authentication_error

A deployment fronted by a corporate identity provider refused the caller's IdP token.

What it means

A deployment fronted by a corporate identity provider refused the caller's IdP token.

How to recognise it

The gateway answers HTTP 401 with x-ace-error: idp_authentication_error on the response. This refusal has no typed envelope of its own, so the header is the reliable signal; the body is the surface's usual error shape.

Is it ACE or the provider?

x-ace-error is present only on errors ACE originated. A vendor error relayed from upstream — a real provider 429, a provider 401 for a bad pass-through key — carries no x-ace-error, and its own type and code mean what the provider says. Read the header before deciding whether to retry, re-mint a key or surface the error.

Other 401 errors