Error codes
When CloudRepo refuses a request, the response carries a code that says why. This page lists the codes
documented so far, with what causes each one and how to fix it. Search the page for the code you got,
or follow a link
that ends in # and the code.
Two hosts answer with these codes:
- Your repository host,
your-org.mycloudrepo.io, which your build tools use to publish and fetch packages. - The CloudRepo API,
api.cloudrepo.io, which the CloudRepo portal uses and which you can call yourself.
Where the code is depends on the response:
- Most JSON responses carry it in the
errorfield, for example{"error": "token_revoked"}. - When your repository host refuses a package request with
403, theerrorfield holds a sentence and the code is in thereason_codefield, for example{"error": "You do not have permissions to access the repository.", "reason_code": "scope_mismatch_repo"}. - A few responses carry it in a
codefield; their entries say so. - Docker answers in the registry’s own format, with an upper-case code in
errors[].code. Those codes are at the end of this page.
Many build tools print only the status, such as 403 Forbidden, and not the code. To read the
code, repeat the request with curl and show the response. Keep your credential in ~/.netrc:
machine your-org.mycloudrepo.iologin you@example.compassword YOUR_REPOSITORY_TOKENcurl --include --netrc https://your-org.mycloudrepo.io/repositories/your-repo/400 Bad Request
Section titled “400 Bad Request”invalid_name
Section titled “invalid_name”Status 400, from the CloudRepo API, when you create a repository token.
Why: the token’s name is empty, is longer than 256 characters, or contains a control character or a character that reverses text direction.
Fix: give the token a short, plain name, such as the name of the build that uses it.
invalid_scope
Section titled “invalid_scope”Status 400, from the CloudRepo API, when you create a repository token.
Why: the request named no scope, or a scope other than read and write.
Fix: ask for read, write, or both.
invalid_token_format
Section titled “invalid_token_format”Status 400, from the CloudRepo API, when you create a repository token.
Why: the request asked for a token format other than generic and npm.
Fix: ask for generic, or npm for a token that npm uses.
missing_repo_ids
Section titled “missing_repo_ids”Status 400, from the CloudRepo API, when you create a repository token.
Why: the request named no repository.
Fix: name at least one repository the token may reach.
missing_expires_at
Section titled “missing_expires_at”Status 400, from the CloudRepo API, when you create a repository token or change an access key’s expiry.
Why: the request did not say when the token expires. Choosing no expiry is allowed, but it has to be asked for.
Fix: send an expiry date, or null for a token that never expires.
invalid_expires_at
Section titled “invalid_expires_at”Status 400, from the CloudRepo API, when you create a repository token, rotate one with a new expiry, or create an access key or change its expiry.
Why: the expiry is not a date CloudRepo can store: it is not a whole number of milliseconds, or it is after the end of the year 9999.
Fix: send the expiry as milliseconds since 1970 (UTC), or null for a token that never expires.
expires_at_in_past
Section titled “expires_at_in_past”Status 400, from the CloudRepo API, when you create a repository token, rotate one with a new expiry, or create an access key or change its expiry.
Why: the expiry you chose has already passed.
Fix: choose a date in the future.
service_key_must_expire
Section titled “service_key_must_expire”Status 400, from the CloudRepo API, when you create or rotate a service key.
What you see:
A service key must have an expiry date no more than 90 days after it is created or rotated. Only a token that belongs to a person can have a later date, or no expiry.Why: a service key belongs to your organization, not to a person, and its expiry can be at most 90 days after you create or rotate it.
Fix: choose an expiry within 90 days, and rotate the key before it expires.
invalid_backing_kind
Section titled “invalid_backing_kind”Status 400, from the CloudRepo API, when you create a repository token.
Why: the request’s backing.kind is not one CloudRepo knows. A service key belongs to the
organization (org) or to one repository (repo).
Fix: send org or repo for a service key, or leave backing out for a token of your own.
invalid_backing_id
Section titled “invalid_backing_id”Status 400, from the CloudRepo API, when you create a service key that belongs to a repository.
Why: the request did not say which repository the key belongs to.
Fix: send that repository’s ID as backing.id.
invalid_service_key_format
Section titled “invalid_service_key_format”Status 400, from the CloudRepo API, when you create a service key.
Why: service keys are created only in the generic format.
Fix: ask for the generic format.
repo_backing_scope_mismatch
Section titled “repo_backing_scope_mismatch”Status 400, from the CloudRepo API, when you create a service key that belongs to a repository.
Why: a key that belongs to one repository can reach only that repository.
Fix: list only the key’s own repository in the request.
missing_confirmation_token
Section titled “missing_confirmation_token”Status 400, from the CloudRepo API, when you create or rotate a repository token.
Why: creating or rotating a token needs a fresh confirmation of who you are, and the request carried none.
Fix: in the portal, confirm your identity when it asks, then try again.
overlap_exceeds_scheduled_end
Section titled “overlap_exceeds_scheduled_end”Status 400, from the CloudRepo API, when you rotate a repository token or an access key.
What you see:
This token is already being rotated and stops working at its scheduled time. A new rotation cannot keep it working longer: choose a shorter overlap, or 0 to end it now.For an access key, the message begins This access key instead of This token.
Why: the token is already being rotated, and a second rotation asked to keep it working past the end the first one set.
Fix: choose a shorter overlap, or 0 to stop the old token now.
invalid_user_id
Section titled “invalid_user_id”Status 400, from the CloudRepo API, when you list repository tokens for a member.
Why: the request named a member, but the name was blank.
Fix: name the member, or leave the parameter out to list your own tokens.
invalid_overlap_hours
Section titled “invalid_overlap_hours”Status 400, from the CloudRepo API, when you rotate an access key or a repository token.
Why: the overlap, how long the old key keeps working after the rotation, is outside 0 to 168 hours.
Fix: choose an overlap from 0, which stops the old key now, to 168 hours, which is one week.
overlap_exceeds_expiry
Section titled “overlap_exceeds_expiry”Status 400, from the CloudRepo API, when you rotate a repository token.
Why: the overlap, how long the old token keeps working after the rotation, is longer than the time the old token has left before it expires. With no overlap chosen, the overlap is 24 hours.
Fix: choose an overlap no longer than the hours the old token has left, or 0 to stop the old token
now.
token_not_found
Section titled “token_not_found”Status 400, from the CloudRepo API, when you rotate a repository token.
Why: CloudRepo found the token when the rotation began, but not when it went to replace it, for example because the token was deleted in between.
Fix: reload your list of tokens. If you still need one, create a new token.
401 Unauthorized
Section titled “401 Unauthorized”step_up_required
Section titled “step_up_required”Status 401 when you create or rotate a repository token, or finish an npm login. Status 403 for
other sensitive actions, such as managing a subscriber’s access keys or setting a proxy repository’s
upstream credentials. From the CloudRepo API.
Why: the action needs a fresh confirmation of who you are. The request carried none, or one that has
expired or was given for a different action. Creating or rotating a token with none answers
missing_confirmation_token instead.
Fix: in the portal, confirm your identity again when it asks, then repeat the action.
403 Forbidden
Section titled “403 Forbidden”repo_access_denied
Section titled “repo_access_denied”Status 403, from the CloudRepo API, when you create a repository token or finish an npm login.
Why: the token would reach a repository that you cannot access yourself.
Fix: choose only repositories you can access, or ask your organization’s owner for access first.
service_key_forbidden
Section titled “service_key_forbidden”Status 403, from the CloudRepo API, when you create a service key.
What you see:
Minting an organization-owned service key requires the manage-owner-account permission.Why: only a member who can manage the organization’s owner account can create a key that belongs to the organization.
Fix: ask your organization’s owner to create the key.
role_mismatch
Section titled “role_mismatch”Status 403, from the CloudRepo API, in each of these cases:
| When | Why | Fix |
|---|---|---|
You create a token with write |
Writing needs both publish and delete access, and you do not hold both in every repository the token would reach. | Create a read token, or ask your organization’s owner for publish and delete access to those repositories first. |
| You create a user, invite one, or change a member’s permissions | You asked for a permission you do not hold yourself. | Grant only permissions you hold, or ask your organization’s owner to make the change. |
| You manage another member as a read-only member | A read-only member can manage only other read-only members. | Ask a member with more access, or your organization’s owner. |
| You reset another member’s password | You are a read-only member, or that member holds a permission you do not. | Ask your organization’s owner to reset it. |
insufficient_permissions
Section titled “insufficient_permissions”Status 403, from the CloudRepo API, when you list another member’s repository tokens.
Why: only a member who can manage the organization’s owner account can list another member’s tokens.
Fix: list your own tokens, or ask your organization’s owner.
scope_mismatch_repo
Section titled “scope_mismatch_repo”Status 403, from your repository host. The code is in the response’s reason_code field, and the
error field holds one of these sentences:
You do not have permissions to access the repository. [2242]You do not have the required permissions [read] for this repository.The second names the action that was refused.
Why: the credential is valid, but it does not allow this action on this repository. It does not
reach the repository, or it can only read and you published or deleted. An access key can only read,
and only the repositories it was given. A token in the npm format works only on npm repositories.
Fix: use a repository token that reaches this repository, with write scope to publish or delete.
If you sign in with your own account, ask your organization’s owner for access to the repository.
With an access key, ask the organization that gave it to you for access to this repository; an
access key can never publish or delete. For a repository that is not npm, replace a token in the
npm format with a repository token created in the portal.
revoked-authority-clamp
Section titled “revoked-authority-clamp”Status 403, from your repository host, when you publish or delete with a repository token. The code
is in the response’s reason_code field.
What you see:
Your credential's backing authority no longer permits this action; the credential was clamped at use time. [7301]Why: the token was created with write, but the member it belongs to can no longer publish or delete
in this repository.
Fix: ask your organization’s owner to give that member write access to the repository again, or use a token that belongs to a member who can write there.
npm_token_not_supported_on_proxy
Section titled “npm_token_not_supported_on_proxy”Status 403, from your repository host. The code is in the response’s code field.
Why: npm sent a token in the npm format to a proxy repository. A proxy repository does not take
npm-format tokens.
Fix: for a proxy repository, use a repository token in the generic format.
404 Not Found
Section titled “404 Not Found”user_not_found
Section titled “user_not_found”Status 404, from the CloudRepo API, when you list a member’s repository tokens.
Why: no member of your organization has that name.
Fix: check the member’s email address in the portal’s user list.
access_key_not_found
Section titled “access_key_not_found”Status 404, from the CloudRepo API, when you manage a subscriber’s access key.
Why: there is no access key with that ID for this subscriber. A key that belongs to a different subscriber gets the same answer.
Fix: check the key’s ID in the subscriber’s list of access keys.
405 Method Not Allowed
Section titled “405 Method Not Allowed”writes_not_permitted_on_proxy
Section titled “writes_not_permitted_on_proxy”Status 405, from your repository host or the CloudRepo API. The code is in the response’s code
field.
What you see:
Writes are not permitted to Proxy Repositories.Why: you published or uploaded to a proxy repository. A proxy repository only holds what it fetches from its upstream.
Fix: publish to a hosted repository instead.
408 Request Timeout
Section titled “408 Request Timeout”request_timeout
Section titled “request_timeout”Status 408, from the CloudRepo API.
What you see:
The request body did not arrive.Why: the request said it had a body, but the body never reached CloudRepo.
Fix: send the request again.
409 Conflict
Section titled “409 Conflict”token_revoked
Section titled “token_revoked”Status 409, from the CloudRepo API, when you rotate a repository token.
What you see:
This token has been revoked, so it cannot be rotated. Create a new token instead.Why: the token was revoked.
Fix: create a new token.
legacy_token
Section titled “legacy_token”Status 409, from the CloudRepo API, when you rotate a repository token.
Why: the token does not record whose token it is, so CloudRepo cannot rotate it. Tokens created before CloudRepo recorded that are like this.
Fix: create a new token instead.
access_key_revoked
Section titled “access_key_revoked”Status 409, from the CloudRepo API, when you rotate an access key or change its expiry.
What you see:
This access key has been revoked, so it cannot be rotated. Create a new access key instead.Or, when you change its expiry:
This access key is being rotated or has been revoked, so its expiry cannot be changed.Why: the key was replaced when it was rotated. Once its overlap has ended it cannot be rotated again, and once a rotation has begun its expiry cannot change.
Fix: use the new key the rotation created, and rotate it or change its expiry instead.
access_key_changed
Section titled “access_key_changed”Status 409, from the CloudRepo API, when you change an access key’s expiry.
What you see:
This access key's expiry changed while you edited it. Reload and try again.Why: someone else changed the key’s expiry after you opened it.
Fix: reload the page, check the new expiry, and make your change again.
conflict
Section titled “conflict”Status 409, from your repository host, when you unpublish or delete an npm package or version.
Why: the package changed after npm read it, for example because another publish or unpublish finished first.
Fix: run the command again, so npm reads the package’s current state first.
user_already_exists
Section titled “user_already_exists”Status 409, from the CloudRepo API, when you accept an invitation.
Why: your organization already has an account at this email address. The invitation is used up.
Fix: sign in with the account you already have. If you cannot, ask your organization’s owner.
410 Gone
Section titled “410 Gone”npm_cli_token_create_disabled
Section titled “npm_cli_token_create_disabled”Status 410, from your repository host, when you run npm token create. The response’s code field
carries the same code in upper case, NPM_CLI_TOKEN_CREATE_DISABLED.
Why: CloudRepo no longer creates tokens through the npm CLI. A token that npm token create made
before reaches no repository, so CloudRepo refuses it at every install and publish.
Fix: in the portal, open Repository Tokens and create a repository token for the repositories
npm uses. Put it in your .npmrc in place of any token npm token create made.
legacy_npm_login_disabled
Section titled “legacy_npm_login_disabled”Status 410, from your repository host, when you run npm login --auth-type=legacy. The response’s
code field carries the same code in upper case, LEGACY_NPM_LOGIN_DISABLED.
Why: npm’s legacy sign-in sends an email address as the user name, which current npm versions do not allow.
Fix: run npm login without --auth-type, which signs in through your browser. For a build, put a
repository token in your .npmrc instead.
413 Content Too Large
Section titled “413 Content Too Large”request_body_too_large
Section titled “request_body_too_large”Status 413, from the CloudRepo API.
What you see:
The request body is larger than this endpoint accepts.Or, for a body with too many items, a message that names the most JSON tokens the endpoint accepts.
Why: the request body is bigger than this endpoint accepts.
Fix: send less in one request. For an action on many items, split it into several requests.
scan_block_size_cap
Section titled “scan_block_size_cap”Status 413, from your repository host, when Docker pulls an image through a Docker proxy
repository. The code is in the response’s code field, beside limit_bytes, the most CloudRepo
accepts, and observed_bytes, the size it received.
Why: the upstream registry sent an image manifest larger than 4 MiB (4,194,304 bytes), the most a Docker proxy repository accepts. CloudRepo did not cache or serve it.
Fix: pull this image from its upstream registry directly. A Docker proxy repository cannot serve a manifest this large.
415 Unsupported Media Type
Section titled “415 Unsupported Media Type”unsupported_media_type
Section titled “unsupported_media_type”Status 415, from the CloudRepo API.
What you see:
Send the request body as JSON, with Content-Type: application/json.Why: the request had a body, but did not say it was JSON.
Fix: send the body as JSON with the header Content-Type: application/json. With curl, add
-H 'Content-Type: application/json'.
503 Service Unavailable
Section titled “503 Service Unavailable”These are temporary. Each response here carries Retry-After: 5, except
membership_lookup_unavailable, which carries no Retry-After.
ddb_unavailable
Section titled “ddb_unavailable”Status 503, from your repository host or the CloudRepo API.
Why: CloudRepo could not read or write its data store for this request.
Fix: wait a few seconds and try again. If it keeps failing, contact support@cloudrepo.io.
repository_token_identity_unavailable
Section titled “repository_token_identity_unavailable”Status 503, from your repository host, when your build sends a repository token.
Why: CloudRepo could not look up whose token it is, so it did not decide whether to accept it. Your token was not refused.
Fix: run the build again. If it keeps failing, contact support@cloudrepo.io.
membership_lookup_unavailable
Section titled “membership_lookup_unavailable”Status 503, from the CloudRepo API, when you list a member’s tokens or change a member’s access.
Why: CloudRepo could not read your organization’s member list for this request.
Fix: try again in a moment. If it keeps failing, contact support@cloudrepo.io.
sso_config_unavailable
Section titled “sso_config_unavailable”Status 503, from your repository host or the CloudRepo API.
What you see, from Maven, npm, pip or Docker:
SSO configuration is temporarily unavailable. Please retry shortly.Some of these responses carry no sentence, and a build tool may show only the status, 503. From
the CloudRepo API, for example when you create or rotate a repository token, add a user, or accept
an invitation, the response carries the code and no sentence.
Why: CloudRepo could not read your organization’s sign-in settings for this request.
Fix: wait a few seconds, then try again. If it keeps failing for more than a few minutes, contact support@cloudrepo.io with the time it happened.
Docker registry codes
Section titled “Docker registry codes”Docker answers in the registry’s format: a JSON body with a list of errors, each with an upper-case
code and a message. The Docker CLI prints the code in lower case, with spaces for underscores.
UNAUTHORIZED
Section titled “UNAUTHORIZED”Status 401, from your repository host.
What you see, from the Docker CLI:
unauthorized: authentication requiredWhy: Docker sent no credential, or one CloudRepo did not accept.
Fix: sign in to your organization’s host with your email address and a repository token. CloudRepo’s registry does not check the user name when the password is a repository token. Pipe the token in:
echo "$CLOUDREPO_TOKEN" | docker login your-org.mycloudrepo.io --username you@example.com --password-stdinDENIED
Section titled “DENIED”Status 403, from your repository host.
| What you see | Why | Fix |
|---|---|---|
denied: insufficient permissions |
Your credential does not reach this repository, or you pushed or deleted with one that cannot write to it. | Use a repository token that reaches this repository, with write scope to push or delete. |
denied: requested scope not authorized for this token |
You signed in with an access key, and the subscriber or group that owns it has not been given this repository. | Ask the organization that gave you the key for access to this repository. |
NAME_INVALID
Section titled “NAME_INVALID”Status 400, from your repository host.
| What you see | Why | Fix |
|---|---|---|
name invalid: Docker image names require at least two segments: <repository>/<image> |
The image reference has no repository in it. | Name the image under its repository: your-org.mycloudrepo.io/repositories/your-repo/my-app:1.0.0. |
name invalid: invalid image name |
A part of the image name is not lower-case letters and digits, joined by ., _ or -. |
Rename the image, for example my-app rather than My_App/. |
name invalid: invalid repository name |
The repository part of the reference is not a valid repository name. | Check the repository name in the portal and use it exactly. |
name invalid: Invalid OCI path |
The reference is not your-org.mycloudrepo.io/repositories/<repository>/<image>: it leaves out repositories/, or names no image after the repository. |
Name the image under its repository: your-org.mycloudrepo.io/repositories/your-repo/my-app:1.0.0. |
name invalid: invalid tag format |
The tag does not start with a letter, a digit or _, holds a character other than letters, digits, ., _ and -, or is longer than 128 characters. |
Use a tag such as 1.0.0 or latest. |
NAME_UNKNOWN
Section titled “NAME_UNKNOWN”Status 404, from your repository host.
| What you see | Why | Fix |
|---|---|---|
name unknown: repository not found |
No Docker repository in your organization has that name. | Check the repository name in the reference, after /repositories/. |
name unknown: group repository has no members |
The group has no member repository it can serve to you: it has none, or you cannot read any of them. | Add a member repository to the group in the portal, or pull with a credential that can read its members. |
MANIFEST_UNKNOWN
Section titled “MANIFEST_UNKNOWN”Status 404, from your repository host.
What you see, from the Docker CLI:
manifest unknown: manifest not foundWhy: the repository has no image with that tag or digest. For a group repository, none of its members has it.
Fix: check the tag and the repository name in the image reference.
BLOB_UNKNOWN
Section titled “BLOB_UNKNOWN”Status 404, from your repository host.
Why: Docker asked for a layer the repository does not hold. During a push this is normal: Docker checks for each layer before it uploads it. During a pull, the image’s manifest names a layer that is missing.
Fix: during a pull, push the image again so every layer is uploaded.
MANIFEST_BLOB_UNKNOWN
Section titled “MANIFEST_BLOB_UNKNOWN”Status 400, from your repository host, when you push an image.
Why: the image’s manifest names a layer that was never uploaded to this repository.
Fix: push the image again.
MANIFEST_INVALID
Section titled “MANIFEST_INVALID”Status 400, from your repository host, when you push an image.
| What you see | Why | Fix |
|---|---|---|
manifest invalid: unsupported manifest media type |
The client sent a manifest type CloudRepo does not store. | Push with the Docker CLI or another OCI client that sends a Docker or OCI image manifest. |
manifest invalid: manifest exceeds maximum size |
The manifest is larger than CloudRepo accepts. | Push an image with fewer layers or platforms in one manifest. |
manifest invalid: manifest body is not valid JSON or computed digest does not match reference |
The manifest arrived damaged, or does not match the digest it was pushed under. | Push again. |
DIGEST_INVALID
Section titled “DIGEST_INVALID”Status 400, from your repository host.
Why: a layer’s content does not match its digest, so it arrived damaged, or a digest in the request
is not a sha256: digest.
Fix: push again. Use sha256 digests.
SIZE_INVALID
Section titled “SIZE_INVALID”Status 400, from your repository host, when you push an image.
Why: one layer of the image is larger than CloudRepo accepts.
Fix: make the layer smaller, for example by splitting a large build step into several. If you cannot, contact support@cloudrepo.io.
BLOB_UPLOAD_UNKNOWN
Section titled “BLOB_UPLOAD_UNKNOWN”Status 404, from your repository host, when you push an image.
Why: Docker continued a layer upload that CloudRepo no longer has, for example after a long pause or a failed upload.
Fix: push again. Docker starts a new upload.
BLOB_UPLOAD_INVALID
Section titled “BLOB_UPLOAD_INVALID”Status 400, from your repository host, when you push an image.
Why: Docker sent a piece of a layer with no content.
Fix: push again.
UNSUPPORTED
Section titled “UNSUPPORTED”Status 405, or 400, from your repository host.
| What you see | Why | Fix |
|---|---|---|
unsupported: Writes are not permitted to group repositories |
You pushed to a group repository. A group has no storage of its own. | Push to one of the group’s hosted member repositories. The image appears through the group at once. |
unsupported: method not allowed |
The client used a request method this part of the registry does not take, such as deleting a single layer. | Use the requests the registry supports: pull, push, and deleting an image’s manifest. |
unsupported: catalog not yet implemented |
The client asked for the registry’s catalog of repositories, which CloudRepo does not serve. | List your repositories in the portal. |
UNKNOWN
Section titled “UNKNOWN”Status 500, from your repository host.
Why: CloudRepo failed unexpectedly while answering Docker.
Fix: try again. If it keeps failing, contact support@cloudrepo.io with the time of the failure.