all docs
/ errors · HTTP 403

skill_locked

A per-request skill override (skill_overrides or x-ace-skills) on a skill the org has locked.

What it means

A per-request skill override (skill_overrides or x-ace-skills) on a skill the org has locked.

How to recognise it

The gateway answers HTTP 403 with x-ace-error: skill_locked on the response. This refusal has no typed envelope of its own, so the header is the reliable signal; the body is the surface's usual error shape.

Is it ACE or the provider?

x-ace-error is present only on errors ACE originated. A vendor error relayed from upstream — a real provider 429, a provider 401 for a bad pass-through key — carries no x-ace-error, and its own type and code mean what the provider says. Read the header before deciding whether to retry, re-mint a key or surface the error.

Other 403 errors

  • model_not_in_scope: Requested model is not enabled for this tenant.
  • invalid_admin_key: Admin-only endpoint called with a non-admin key.
  • idp_forbidden_error: A deployment fronted by a corporate identity provider accepted the caller's IdP token but its group mapping grants no access.