---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "INVALID_STATE"
description: "INVALID_STATE (FAILED_PRECONDITION, HTTP 400): The Resource is in a state that forbids the call."
type: reference
product: platform
summary: "The Resource is in a state that forbids the call."
updated: 2026-09-28
nav: false
---

The Resource is in a state that forbids the call.

**HTTP** 400 · **gRPC** `FAILED_PRECONDITION` · [the error body](/docs/platform/errors)

## Returned by

| Method | Scope | What it does |
| --- | --- | --- |
| [`access.orgs.delete`](/docs/api/orgs/delete) | `access:admin` | Deletes an org and everything in it. Deletion cascades through every service, so it returns an Operation. |
| [`access.projects.delete`](/docs/api/projects/delete) | `access:admin` | Deletes a project. |
| [`access.envs.delete`](/docs/api/envs/delete) | `access:admin` | Deletes an environment. |
| [`access.api_keys.delete`](/docs/api/api_keys/delete) | `access:keys:write` | Deletes an API key. |
| [`access.api_keys.revoke`](/docs/api/api_keys/revoke) | `access:keys:write` | Revokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data. |
| [`access.api_keys.roll`](/docs/api/api_keys/roll) | `access:keys:write` | Rolls an API key: returns a new key with the same spec and revokes the old one after the grace period. |
| [`artifacts.artifacts.delete`](/docs/api/artifacts/delete) | `artifacts:write` | Deletes an artifact; fails while a Release references it or a legal hold is active. |
| [`assets.assets.retire_variant`](/docs/api/assets/retire_variant) | `assets:write` | Retires one variant. Its URL answers 404 from then on and its slot is freed. |
| [`auth.end_users.suspend`](/docs/api/end_users/suspend) | `auth:write` | Suspends an end user: sessions are revoked and sign-in is refused. |
| [`auth.end_users.reactivate`](/docs/api/end_users/reactivate) | `auth:write` | Reactivates a suspended end user. |
| [`auth.end_users.unlock`](/docs/api/end_users/unlock) | `auth:write` | Clears an end user's sign-in lock (repeated failed sign-ins) now. |
| [`auth.end_users.revoke_sessions`](/docs/api/end_users/revoke_sessions) | `auth:write` | Revokes every session of an end user. |
| [`auth.sessions.revoke`](/docs/api/sessions/revoke) | `auth:write` | Revokes a session. |
| [`auth.invitations.create`](/docs/api/invitations/create) | `auth:write` | Creates an invitation. |
| [`auth.invitations.revoke`](/docs/api/invitations/revoke) | `auth:write` | Revokes a pending invitation. |
| [`auth.invitations.accept`](/docs/api/invitations/accept) | `auth:write` | Accepts a pending invitation for an end user whose verified email is the invited address, and creates the membership. |
| [`auth.email_domains.create`](/docs/api/email_domains/create) | `auth:write` | Creates an email domain; the answer names the TXT record to publish. |
| [`auth.email_domains.verify`](/docs/api/email_domains/verify) | `auth:write` | Looks up the domain's TXT record now; found, the domain is verified. |
| [`auth.oauth_clients.roll_secret`](/docs/api/oauth_clients/roll_secret) | `auth:write` | Issues a new client secret, returned once; the old one verifies until `grace_period` ends. |
| [`broker.trust_policies.delete`](/docs/api/trust_policies/delete) | `broker:admin` | Deletes a trust policy. |
| [`broker.trust_policies.exchange_token`](/docs/api/trust_policies/exchange_token) | `broker:exchange` | Exchanges the caller's workload identity for a short-lived provider credential under a trust policy (RFC 8693 token exchange). The credential is narrowed to the request and cached per installation and permission set; a permission the Connection lacks is PERMISSION_DENIED with reason `CapabilityMissing`, never an outage. |
| [`build.builds.cancel`](/docs/api/builds/cancel) | `build:write` | Cancels a queued or running Build; its lease is released and nothing is published. |
| [`build.build_caches.delete`](/docs/api/build_caches/delete) | `build:write` | Deletes a build cache. |
| [`config.config_flags.delete`](/docs/api/config_flags/delete) | `config:write` | Deletes a config flag; evaluators then get their compiled-in fallback. |
| [`config.config_segments.delete`](/docs/api/config_segments/delete) | `config:write` | Deletes a config segment; refused while a flag names it. |
| [`connections.connection_providers.delete`](/docs/api/connection_providers/delete) | `connections:admin` | Deletes a connection provider; it must have no connections. |
| [`connections.connections.delete`](/docs/api/connections/delete) | `connections:write` | Forgets a connection. The installation itself is removed at the provider. |
| [`data.databases.delete`](/docs/api/databases/delete) | `data:write` | Deletes a database. Fails while `spec.deletion_protection` is set. |
| [`data.databases.connect`](/docs/api/databases/connect) | `data:write` | Returns how to connect to the database: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here. |
| [`data.databases.rotate_credentials`](/docs/api/databases/rotate_credentials) | `data:write` | Replaces the database's engine credentials; the old ones stop working once the new ones are served. |
| [`data.databases.restore`](/docs/api/databases/restore) | `data:write` | Restores the database in place to a point in time inside its retention window; the database is unavailable while it restores. |
| [`data.kv_namespaces.delete`](/docs/api/kv_namespaces/delete) | `data:write` | Deletes a kv namespace. Fails while `spec.deletion_protection` is set. |
| [`data.kv_namespaces.connect`](/docs/api/kv_namespaces/connect) | `data:write` | Returns how to connect to the KV namespace: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here. |
| [`data.kv_namespaces.rotate_credentials`](/docs/api/kv_namespaces/rotate_credentials) | `data:write` | Replaces the KV namespace's engine credentials; the old ones stop working once the new ones are served. |
| [`data.buckets.delete`](/docs/api/buckets/delete) | `data:write` | Deletes a bucket. Fails while `spec.deletion_protection` is set. |
| [`data.buckets.connect`](/docs/api/buckets/connect) | `data:write` | Returns how to connect to the bucket: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here. |
| [`data.buckets.rotate_credentials`](/docs/api/buckets/rotate_credentials) | `data:write` | Replaces the bucket's engine credentials; the old ones stop working once the new ones are served. |
| [`data.search_indexes.delete`](/docs/api/search_indexes/delete) | `data:write` | Deletes a search index. Fails while `spec.deletion_protection` is set. |
| [`data.search_indexes.connect`](/docs/api/search_indexes/connect) | `data:write` | Returns how to connect to the search index: its endpoint and its own engine credentials. The credentials are not API keys and are returned only here. |
| [`data.search_indexes.rotate_credentials`](/docs/api/search_indexes/rotate_credentials) | `data:write` | Replaces the search index's engine credentials; the old ones stop working once the new ones are served. |
| [`events.queues.replay`](/docs/api/queues/replay) | `events:write` | Moves dead-lettered messages, optionally bounded by dead-letter time, back to ready. |
| [`events.webhook_endpoints.replay`](/docs/api/webhook_endpoints/replay) | `events:write` | Redelivers every dead-lettered delivery to the endpoint created in a time range, each as a new attempt. |
| [`events.webhook_endpoints.test`](/docs/api/webhook_endpoints/test) | `events:write` | Sends a test event (`type` `sylphx.webhook.test`) to the endpoint alone, through the same signing, retries, and delivery log as any other event. |
| [`events.webhook_deliveries.replay`](/docs/api/webhook_deliveries/replay) | `events:write` | Redelivers one delivery now, as a new attempt. |
| [`hosting.services.delete`](/docs/api/services/delete) | `hosting:write` | Deletes a service. |
| [`hosting.service_rollouts.pause`](/docs/api/service_rollouts/pause) | `hosting:write` | Holds a Rollout at its current wave. |
| [`hosting.service_rollouts.resume`](/docs/api/service_rollouts/resume) | `hosting:write` | Resumes a paused Rollout. |
| [`hosting.service_rollouts.abort`](/docs/api/service_rollouts/abort) | `hosting:write` | Stops a Rollout; the cells it reached return to the previous Release. |
| [`hosting.previews.delete`](/docs/api/previews/delete) | `hosting:write` | Deletes a preview. |
| [`hosting.source_links.delete`](/docs/api/source_links/delete) | `hosting:write` | Deletes a source link. |
| [`keys.keys.delete`](/docs/api/keys/delete) | `keys:write` | Deletes a key and schedules every version's destruction. |
| [`keys.keys.rotate`](/docs/api/keys/rotate) | `keys:write` | Rotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed. |
| [`keys.keys.sign`](/docs/api/keys/sign) | `keys:sign` | Signs data or a digest with a SIGN key. Every use is audited. |
| [`keys.keys.verify`](/docs/api/keys/verify) | `keys:verify` | Verifies a signature made by a SIGN key. |
| [`keys.keys.encrypt`](/docs/api/keys/encrypt) | `keys:encrypt` | Encrypts data with an ENCRYPT key. |
| [`keys.keys.decrypt`](/docs/api/keys/decrypt) | `keys:decrypt` | Decrypts a ciphertext made by Encrypt with this key. |
| [`keys.keys.mac_sign`](/docs/api/keys/mac_sign) | `keys:sign` | Computes a MAC of data with a MAC key. |
| [`keys.keys.mac_verify`](/docs/api/keys/mac_verify) | `keys:verify` | Verifies a MAC made by a MAC key, in constant time. |
| [`keys.key_versions.destroy`](/docs/api/key_versions/destroy) | `keys:write` | Schedules a key version's destruction after a 24-hour grace; the primary version cannot be destroyed. |
| [`localization.catalogs.delete`](/docs/api/catalogs/delete) | `localization:write` | Deletes a catalog. |
| [`money.price_catalogs.sync`](/docs/api/price_catalogs/sync) | `billing:write` | Pushes the catalog to the merchant account's processor now: products and prices by lookup key; an amount change makes a new price. |
| [`money.store_purchases.verify`](/docs/api/store_purchases/verify) | `billing:write` | Verifies a store purchase with the store, binds it to the subject, and returns its record and a signed grant. Re-verifying returns the same record and grant. Called from the app's server with a secret key that holds `billing:write`; a publishable key cannot call it. |
| [`money.customer_subscriptions.cancel`](/docs/api/customer_subscriptions/cancel) | `billing:write` | Cancels a web subscription, now or at the period end, and optionally refunds its last payment (for example a statutory cancellation window). |
| [`money.customer_subscriptions.resume`](/docs/api/customer_subscriptions/resume) | `billing:write` | Resumes a web subscription set to cancel at its period end. |
| [`money.customer_subscriptions.update_quantity`](/docs/api/customer_subscriptions/update_quantity) | `billing:write` | Changes the seat quantity of a web subscription, now, and syncs the processor's subscription item to it. A retry with the same `Idempotency-Key` (required) and the same request changes nothing twice. |
| [`money.checkout_sessions.create`](/docs/api/checkout_sessions/create) | `billing:write` | Creates a hosted checkout for a subject. |
| [`money.portal_sessions.create`](/docs/api/portal_sessions/create) | `billing:write` | Creates a customer portal session for a subject. |
| [`network.domains.delete`](/docs/api/domains/delete) | `network:write` | Deletes a domain. |
| [`network.domains.verify`](/docs/api/domains/verify) | `network:write` | Checks the verification record now instead of at the next sweep. |
| [`network.routes.delete`](/docs/api/routes/delete) | `network:write` | Deletes a route. |
| [`network.egress_identities.delete`](/docs/api/egress_identities/delete) | `network:write` | Deletes an egress identity. |
| [`network.private_links.delete`](/docs/api/private_links/delete) | `network:write` | Deletes a private link. |
| [`notify.messages.create`](/docs/api/messages/create) | `notify:send` | Sends a Message. |
| [`notify.messages.cancel`](/docs/api/messages/cancel) | `notify:send` | Cancels a Message whose deliveries have not been handed off. |
| [`notify.inbox_items.mark_read`](/docs/api/inbox_items/mark_read) | `notify:write` | Marks an inbox item read. |
| [`notify.inbox_items.mark_unread`](/docs/api/inbox_items/mark_unread) | `notify:write` | Marks an inbox item unread. |
| [`notify.inbox_items.archive`](/docs/api/inbox_items/archive) | `notify:write` | Archives an inbox item. |
| [`notify.broadcasts.send`](/docs/api/broadcasts/send) | `notify:send` | Sends a Broadcast now. |
| [`notify.broadcasts.cancel`](/docs/api/broadcasts/cancel) | `notify:send` | Cancels a Broadcast; messages already admitted still deliver. |
| [`observability.error_groups.acknowledge`](/docs/api/error_groups/acknowledge) | `observability:write` | Acknowledges an error group. |
| [`observability.error_groups.resolve`](/docs/api/error_groups/resolve) | `observability:write` | Resolves an error group; a new occurrence reopens it. |
| [`observability.error_groups.reopen`](/docs/api/error_groups/reopen) | `observability:write` | Reopens a resolved or acknowledged error group. |
| [`release.releases.create`](/docs/api/releases/create) | `release:write` | Creates a release: admits it and rolls it out in waves. The Operation is done when the release is live or halted. |
| [`runners.scale_sets.delete`](/docs/api/scale_sets/delete) | `runners:write` | Deletes a scale set. |
| [`sandboxes.pools.delete`](/docs/api/pools/delete) | `sandboxes:write` | Deletes a pool. |
| [`sandboxes.leases.renew`](/docs/api/leases/renew) | `sandboxes:write` | Extends `expire_time`, never past the shape's longest lease. Does not change the generation. |
| [`sandboxes.leases.release`](/docs/api/leases/release) | `sandboxes:write` | Ends a lease with END_REASON_RELEASED; the machine is destroyed and never leased again, and attached volumes are detached. |
| [`sandboxes.leases.pause`](/docs/api/leases/pause) | `sandboxes:write` | Pauses a lease: its disk is kept and its machine destroyed; the generation increases. Process memory is not kept. |
| [`sandboxes.leases.resume`](/docs/api/leases/resume) | `sandboxes:write` | Resumes a paused lease on a machine granted now, or refuses it; the generation increases. |
| [`sandboxes.leases.set_network`](/docs/api/leases/set_network) | `sandboxes:write` | Replaces a running lease's outbound policy. The generation does not change; the new policy applies before the call returns. |
| [`sandboxes.leases.mint_token`](/docs/api/leases/mint_token) | `sandboxes:exec` | Mints a lease token for the data plane, bound to the current generation. Hand it to a process that must not hold the Access key. |
| [`sandboxes.leases.exec`](/docs/api/leases/exec) | `sandboxes:exec` | Runs one command in the lease to completion and returns its output, capped at 1 MiB per stream. Long-running or interactive processes use the guest protocol at `status.endpoints.guest_uri`. |
| [`sandboxes.leases.read_file`](/docs/api/leases/read_file) | `sandboxes:exec` | Reads one file from the lease, at most 16 MiB; larger files use the guest's `/files`. |
| [`sandboxes.leases.write_file`](/docs/api/leases/write_file) | `sandboxes:exec` | Writes one file in the lease, at most 16 MiB, creating parent directories. |
| [`sandboxes.leases.list_files`](/docs/api/leases/list_files) | `sandboxes:exec` | Lists one directory in the lease. |
| [`sandboxes.leases.remove_file`](/docs/api/leases/remove_file) | `sandboxes:exec` | Removes one file or directory tree in the lease. |
| [`sandboxes.leases.open_port`](/docs/api/leases/open_port) | `sandboxes:exec` | Exposes a guest port. |
| [`sandboxes.leases.close_port`](/docs/api/leases/close_port) | `sandboxes:exec` | Stops exposing a guest port. |
| [`sandboxes.leases.act`](/docs/api/leases/act) | `sandboxes:exec` | Performs computer actions on a DESKTOP, BROWSER, or ANDROID lease, in order, and returns each action's result and, when `screenshot` is set, the screenshot taken after the last action. The actions are the Anthropic computer tool's and OpenAI computer use's, one-to-one. Refused CONTROL_HELD_BY_HUMAN while a human holds control. |
| [`sandboxes.leases.open_stream`](/docs/api/leases/open_stream) | `sandboxes:exec` | Opens a read-only live view of a lease's display: a short-lived viewer token bound to the lease and its generation, an embeddable URL, and the WebRTC signaling endpoint with ICE servers. Input needs control (AcquireLeaseControl). |
| [`sandboxes.leases.acquire_control`](/docs/api/leases/acquire_control) | `sandboxes:exec` | Takes exclusive input control of a lease's display. A HUMAN acquire preempts an AGENT holder and returns a controller stream; an AGENT acquire is refused CONTROL_HELD_BY_HUMAN while a human holds control. Control lapses at `ttl`, which the platform caps at 30 minutes. |
| [`sandboxes.leases.install_app`](/docs/api/leases/install_app) | `sandboxes:exec` | Installs an Android app (APK) on an ANDROID lease. |
| [`sandboxes.snapshots.create`](/docs/api/snapshots/create) | `sandboxes:write` | Captures a running lease's disk as a snapshot. |
| [`secrets.secrets.delete`](/docs/api/secrets/delete) | `secrets:write` | Deletes a secret and destroys every version. |
| [`secrets.secret_versions.disable`](/docs/api/secret_versions/disable) | `secrets:write` | Disables a secret version: bindings stop delivering it. |
| [`secrets.secret_versions.enable`](/docs/api/secret_versions/enable) | `secrets:write` | Enables a disabled secret version. |
| [`secrets.secret_versions.destroy`](/docs/api/secret_versions/destroy) | `secrets:write` | Destroys a secret version's value irrecoverably. |
| [`secrets.secret_versions.access`](/docs/api/secret_versions/access) | `secrets:access` | Reads a secret version's value back. Break-glass: a separate permission, audited on every call, and never exposed to MCP. |
| [`secrets.secret_bindings.delete`](/docs/api/secret_bindings/delete) | `secrets:write` | Deletes a secret binding. |
| [`workflows.schedules.pause`](/docs/api/schedules/pause) | `workflows:write` | Pauses a Schedule: no fire starts a Run until it is resumed. |
| [`workflows.schedules.resume`](/docs/api/schedules/resume) | `workflows:write` | Resumes a paused Schedule; missed fires follow `catchup_window`. |
| [`workflows.runs.signal`](/docs/api/runs/signal) | `workflows:run` | Sends a named signal to a running Run; a `wait` op for that name resumes with its payload. A signal to a closed Run fails with INVALID_STATE. |
| [`workflows.runs.cancel`](/docs/api/runs/cancel) | `workflows:run` | Requests cancellation. Timers and waits stop; a running invocation is not interrupted: the handler receives one final invocation with `cancel: true`, and the Run ends `cancelled` when it answers. |
| [`workflows.jobs.delete`](/docs/api/jobs/delete) | `workflows:write` | Deletes a job. |
| [`workflows.job_runs.create`](/docs/api/job_runs/create) | `workflows:run` | Starts a run of a Job now. The same `Idempotency-Key` returns the same run for 24h; a Schedule fire uses `{job}:{intended time}`. With concurrency `forbid`, a start while a run is active fails with INVALID_STATE. |
| [`workflows.job_runs.cancel`](/docs/api/job_runs/cancel) | `workflows:run` | Cancels a job run: SIGTERM, then SIGKILL after 30s. A closed run fails with INVALID_STATE. |
| [`workflows.distributed_jobs.delete`](/docs/api/distributed_jobs/delete) | `workflows:write` | Deletes a distributed job. |
| [`workflows.distributed_runs.create`](/docs/api/distributed_runs/create) | `workflows:run` | Starts a run of a distributed job. The same `Idempotency-Key` returns the same run for 24h. |
| [`workflows.distributed_runs.cancel`](/docs/api/distributed_runs/cancel) | `workflows:run` | Cancels a distributed run: workers get SIGTERM and 30s, then leases are released; finished shards are kept. A closed run fails with INVALID_STATE. |
| [`workflows.distributed_runs.add_shards`](/docs/api/distributed_runs/add_shards) | `workflows:run` | Appends shards to a run started with an open manifest; `close` ends the manifest, and the run ends once those shards are done. |
