/ errors · HTTP 403
invalid_admin_key
Admin-only endpoint called with a non-admin key.
What it means
An admin-only endpoint was called with a key that is not an admin key.
How to recognise it
The gateway answers HTTP 403 with x-ace-error: invalid_admin_key on the response, and a body in the shared error envelope:
{
"error": {
"message": "...",
"type": "invalid_admin_key",
"code": 403
}
}
On a vendor-shaped surface (/anthropic/…, /gemini/…, /bedrock/…) the body wears that vendor's error envelope instead; the x-ace-error header is the same everywhere.
Is it ACE or the provider?
x-ace-error is present only on errors ACE originated. A vendor error relayed from upstream — a real provider 429, a provider 401 for a bad pass-through key — carries no x-ace-error, and its own type and code mean what the provider says. Read the header before deciding whether to retry, re-mint a key or surface the error.
Other 403 errors
model_not_in_scope: Requested model is not enabled for this tenant.skill_locked: A per-request skill override (skill_overridesorx-ace-skills) on a skill the org has locked.idp_forbidden_error: A deployment fronted by a corporate identity provider accepted the caller's IdP token but its group mapping grants no access.
Related
- Error contracts & status codes: the full taxonomy
- Response header specification
- Echo mode: reproduce a call without spending