Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

On this page

INVALID_STATE

The Resource is in a state that forbids the call.

The Resource is in a state that forbids the call.

HTTP 400 · gRPC FAILED_PRECONDITION · the error body

#Returned by

MethodScopeWhat it does
access.orgs.deleteaccess:adminDeletes an org and everything in it. Deletion cascades through every service, so it returns an Operation.
access.projects.deleteaccess:adminDeletes a project.
access.envs.deleteaccess:adminDeletes an environment.
access.api_keys.deleteaccess:keys:writeDeletes an API key.
access.api_keys.revokeaccess:keys:writeRevokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data.
access.api_keys.rollaccess:keys:writeRolls an API key: returns a new key with the same spec and revokes the old one after the grace period.
artifacts.artifacts.deleteartifacts:writeDeletes an artifact; fails while a Release references it or a legal hold is active.
assets.assets.retire_variantassets:writeRetires one variant. Its URL answers 404 from then on and its slot is freed.
auth.end_users.suspendauth:writeSuspends an end user: sessions are revoked and sign-in is refused.
auth.end_users.reactivateauth:writeReactivates a suspended end user.
auth.end_users.unlockauth:writeClears an end user's sign-in lock (repeated failed sign-ins) now.
auth.end_users.revoke_sessionsauth:writeRevokes every session of an end user.
auth.sessions.revokeauth:writeRevokes a session.
auth.invitations.createauth:writeCreates an invitation.
auth.invitations.revokeauth:writeRevokes a pending invitation.
auth.invitations.acceptauth:writeAccepts a pending invitation for an end user whose verified email is the invited address, and creates the membership.
auth.email_domains.createauth:writeCreates an email domain; the answer names the TXT record to publish.
auth.email_domains.verifyauth:writeLooks up the domain's TXT record now; found, the domain is verified.
auth.oauth_clients.roll_secretauth:writeIssues a new client secret, returned once; the old one verifies until grace_period ends.
broker.trust_policies.deletebroker:adminDeletes a trust policy.
broker.trust_policies.exchange_tokenbroker:exchangeExchanges the caller's workload identity for a short-lived provider credential under a trust policy (RFC 8693 token exchange). The credential is narrowed to the request and cached per installation and permission set; a permission the Connection lacks is PERMISSION_DENIED with reason CapabilityMissing, never an outage.
build.builds.cancelbuild:writeCancels a queued or running Build; its lease is released and nothing is published.
build.build_caches.deletebuild:writeDeletes a build cache.
config.config_flags.deleteconfig:writeDeletes a config flag; evaluators then get their compiled-in fallback.
config.config_segments.deleteconfig:writeDeletes a config segment; refused while a flag names it.
connections.connection_providers.deleteconnections:adminDeletes a connection provider; it must have no connections.
connections.connections.deleteconnections:writeForgets a connection. The installation itself is removed at the provider.
data.databases.deletedata:writeDeletes a database. Fails while spec.deletion_protection is set.
data.databases.connectdata:writeReturns how to connect to the database: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here.
data.databases.rotate_credentialsdata:writeReplaces the database's engine credentials; the old ones stop working once the new ones are served.
data.databases.restoredata:writeRestores the database in place to a point in time inside its retention window; the database is unavailable while it restores.
data.kv_namespaces.deletedata:writeDeletes a kv namespace. Fails while spec.deletion_protection is set.
data.kv_namespaces.connectdata:writeReturns how to connect to the KV namespace: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here.
data.kv_namespaces.rotate_credentialsdata:writeReplaces the KV namespace's engine credentials; the old ones stop working once the new ones are served.
data.buckets.deletedata:writeDeletes a bucket. Fails while spec.deletion_protection is set.
data.buckets.connectdata:writeReturns how to connect to the bucket: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here.
data.buckets.rotate_credentialsdata:writeReplaces the bucket's engine credentials; the old ones stop working once the new ones are served.
data.search_indexes.deletedata:writeDeletes a search index. Fails while spec.deletion_protection is set.
data.search_indexes.connectdata:writeReturns how to connect to the search index: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here.
data.search_indexes.rotate_credentialsdata:writeReplaces the search index's engine credentials; the old ones stop working once the new ones are served.
events.queues.replayevents:writeMoves dead-lettered messages, optionally bounded by dead-letter time, back to ready.
events.webhook_endpoints.replayevents:writeRedelivers every dead-lettered delivery to the endpoint created in a time range, each as a new attempt.
events.webhook_endpoints.testevents:writeSends a test event (type sylphx.webhook.test) to the endpoint alone, through the same signing, retries, and delivery log as any other event.
events.webhook_deliveries.replayevents:writeRedelivers one delivery now, as a new attempt.
hosting.services.deletehosting:writeDeletes a service.
hosting.service_rollouts.pausehosting:writeHolds a Rollout at its current wave.
hosting.service_rollouts.resumehosting:writeResumes a paused Rollout.
hosting.service_rollouts.aborthosting:writeStops a Rollout; the cells it reached return to the previous Release.
hosting.previews.deletehosting:writeDeletes a preview.
hosting.source_links.deletehosting:writeDeletes a source link.
keys.keys.deletekeys:writeDeletes a key and schedules every version's destruction.
keys.keys.rotatekeys:writeRotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed.
keys.keys.signkeys:signSigns data or a digest with a SIGN key. Every use is audited.
keys.keys.verifykeys:verifyVerifies a signature made by a SIGN key.
keys.keys.encryptkeys:encryptEncrypts data with an ENCRYPT key.
keys.keys.decryptkeys:decryptDecrypts a ciphertext made by Encrypt with this key.
keys.keys.mac_signkeys:signComputes a MAC of data with a MAC key.
keys.keys.mac_verifykeys:verifyVerifies a MAC made by a MAC key, in constant time.
keys.key_versions.destroykeys:writeSchedules a key version's destruction after a 24-hour grace; the primary version cannot be destroyed.
localization.catalogs.deletelocalization:writeDeletes a catalog.
money.price_catalogs.syncbilling:writePushes the catalog to the merchant account's processor now: products and prices by lookup key; an amount change makes a new price.
money.store_purchases.verifybilling:writeVerifies a store purchase with the store, binds it to the subject, and returns its record and a signed grant. Re-verifying returns the same record and grant. Called from the app's server with a secret key that holds billing:write; a publishable key cannot call it.
money.customer_subscriptions.cancelbilling:writeCancels a web subscription, now or at the period end, and optionally refunds its last payment (for example a statutory cancellation window).
money.customer_subscriptions.resumebilling:writeResumes a web subscription set to cancel at its period end.
money.customer_subscriptions.update_quantitybilling:writeChanges the seat quantity of a web subscription, now, and syncs the processor's subscription item to it. A retry with the same Idempotency-Key (required) and the same request changes nothing twice.
money.checkout_sessions.createbilling:writeCreates a hosted checkout for a subject.
money.portal_sessions.createbilling:writeCreates a customer portal session for a subject.
network.domains.deletenetwork:writeDeletes a domain.
network.domains.verifynetwork:writeChecks the verification record now instead of at the next sweep.
network.routes.deletenetwork:writeDeletes a route.
network.egress_identities.deletenetwork:writeDeletes an egress identity.
network.private_links.deletenetwork:writeDeletes a private link.
notify.messages.createnotify:sendSends a Message.
notify.messages.cancelnotify:sendCancels a Message whose deliveries have not been handed off.
notify.inbox_items.mark_readnotify:writeMarks an inbox item read.
notify.inbox_items.mark_unreadnotify:writeMarks an inbox item unread.
notify.inbox_items.archivenotify:writeArchives an inbox item.
notify.broadcasts.sendnotify:sendSends a Broadcast now.
notify.broadcasts.cancelnotify:sendCancels a Broadcast; messages already admitted still deliver.
observability.error_groups.acknowledgeobservability:writeAcknowledges an error group.
observability.error_groups.resolveobservability:writeResolves an error group; a new occurrence reopens it.
observability.error_groups.reopenobservability:writeReopens a resolved or acknowledged error group.
release.releases.createrelease:writeCreates a release: admits it and rolls it out in waves. The Operation is done when the release is live or halted.
runners.scale_sets.deleterunners:writeDeletes a scale set.
sandboxes.pools.deletesandboxes:writeDeletes a pool.
sandboxes.leases.renewsandboxes:writeExtends expire_time, never past the shape's longest lease. Does not change the generation.
sandboxes.leases.releasesandboxes:writeEnds a lease with END_REASON_RELEASED; the machine is destroyed and never leased again, and attached volumes are detached.
sandboxes.leases.pausesandboxes:writePauses a lease: its disk is kept and its machine destroyed; the generation increases. Process memory is not kept.
sandboxes.leases.resumesandboxes:writeResumes a paused lease on a machine granted now, or refuses it; the generation increases.
sandboxes.leases.set_networksandboxes:writeReplaces a running lease's outbound policy. The generation does not change; the new policy applies before the call returns.
sandboxes.leases.mint_tokensandboxes:execMints a lease token for the data plane, bound to the current generation. Hand it to a process that must not hold the Access key.
sandboxes.leases.execsandboxes:execRuns one command in the lease to completion and returns its output, capped at 1 MiB per stream. Long-running or interactive processes use the guest protocol at status.endpoints.guest_uri.
sandboxes.leases.read_filesandboxes:execReads one file from the lease, at most 16 MiB; larger files use the guest's /files.
sandboxes.leases.write_filesandboxes:execWrites one file in the lease, at most 16 MiB, creating parent directories.
sandboxes.leases.list_filessandboxes:execLists one directory in the lease.
sandboxes.leases.remove_filesandboxes:execRemoves one file or directory tree in the lease.
sandboxes.leases.open_portsandboxes:execExposes a guest port.
sandboxes.leases.close_portsandboxes:execStops exposing a guest port.
sandboxes.leases.actsandboxes:execPerforms computer actions on a DESKTOP, BROWSER, or ANDROID lease, in order, and returns each action's result and, when screenshot is set, the screenshot taken after the last action. The actions are the Anthropic computer tool's and OpenAI computer use's, one-to-one. Refused CONTROL_HELD_BY_HUMAN while a human holds control.
sandboxes.leases.open_streamsandboxes:execOpens a read-only live view of a lease's display: a short-lived viewer token bound to the lease and its generation, an embeddable URL, and the WebRTC signaling endpoint with ICE servers. Input needs control (AcquireLeaseControl).
sandboxes.leases.acquire_controlsandboxes:execTakes exclusive input control of a lease's display. A HUMAN acquire preempts an AGENT holder and returns a controller stream; an AGENT acquire is refused CONTROL_HELD_BY_HUMAN while a human holds control. Control lapses at ttl, which the platform caps at 30 minutes.
sandboxes.leases.install_appsandboxes:execInstalls an Android app (APK) on an ANDROID lease.
sandboxes.snapshots.createsandboxes:writeCaptures a running lease's disk as a snapshot.
secrets.secrets.deletesecrets:writeDeletes a secret and destroys every version.
secrets.secret_versions.disablesecrets:writeDisables a secret version: bindings stop delivering it.
secrets.secret_versions.enablesecrets:writeEnables a disabled secret version.
secrets.secret_versions.destroysecrets:writeDestroys a secret version's value irrecoverably.
secrets.secret_versions.accesssecrets:accessReads a secret version's value back. Break-glass: a separate permission, audited on every call, and never exposed to MCP.
secrets.secret_bindings.deletesecrets:writeDeletes a secret binding.
workflows.schedules.pauseworkflows:writePauses a Schedule: no fire starts a Run until it is resumed.
workflows.schedules.resumeworkflows:writeResumes a paused Schedule; missed fires follow catchup_window.
workflows.runs.signalworkflows:runSends a named signal to a running Run; a wait op for that name resumes with its payload. A signal to a closed Run fails with INVALID_STATE.
workflows.runs.cancelworkflows:runRequests cancellation. Timers and waits stop; a running invocation is not interrupted: the handler receives one final invocation with cancel: true, and the Run ends cancelled when it answers.
workflows.jobs.deleteworkflows:writeDeletes a job.
workflows.job_runs.createworkflows:runStarts a run of a Job now. The same Idempotency-Key returns the same run for 24h; a Schedule fire uses {job}:{intended time}. With concurrency forbid, a start while a run is active fails with INVALID_STATE.
workflows.job_runs.cancelworkflows:runCancels a job run: SIGTERM, then SIGKILL after 30s. A closed run fails with INVALID_STATE.
workflows.distributed_jobs.deleteworkflows:writeDeletes a distributed job.
workflows.distributed_runs.createworkflows:runStarts a run of a distributed job. The same Idempotency-Key returns the same run for 24h.
workflows.distributed_runs.cancelworkflows:runCancels a distributed run: workers get SIGTERM and 30s, then leases are released; finished shards are kept. A closed run fails with INVALID_STATE.
workflows.distributed_runs.add_shardsworkflows:runAppends shards to a run started with an open manifest; close ends the manifest, and the run ends once those shards are done.