/ errors · HTTP 403
skill_locked
A per-request skill override (skill_overrides or x-ace-skills) on a skill the org has locked.
What it means
A per-request skill override (skill_overrides or x-ace-skills) on a skill the org has locked.
How to recognise it
The gateway answers HTTP 403 with x-ace-error: skill_locked on the response. This refusal has no typed envelope of its own, so the header is the reliable signal; the body is the surface's usual error shape.
Is it ACE or the provider?
x-ace-error is present only on errors ACE originated. A vendor error relayed from upstream — a real provider 429, a provider 401 for a bad pass-through key — carries no x-ace-error, and its own type and code mean what the provider says. Read the header before deciding whether to retry, re-mint a key or surface the error.
Other 403 errors
model_not_in_scope: Requested model is not enabled for this tenant.invalid_admin_key: Admin-only endpoint called with a non-admin key.idp_forbidden_error: A deployment fronted by a corporate identity provider accepted the caller's IdP token but its group mapping grants no access.
Related
- Error contracts & status codes: the full taxonomy
- Response header specification
- Echo mode: reproduce a call without spending