Skip to main content
Troubleshooting

Error codes

Most errors the UI or the API returns carry a code. Each code's HTTP status, meaning and remedy by area, plus a few common messages that have no code.

Error responses have the form {"detail": "<message>", "code": "<code>", "params": {...}}. The UI shows the message in the current language, API clients branch on code, and the values in params fill in the message.

Raw errors from Zabbix and from the model go to the server log only, never into the response. For details, run docker compose -f docker-compose.prod.yml logs gateway.

Sign-in and permissions

CodeHTTPMeaningRemedy
login_required401Not signed in, or the session expiredSign in again
permission_denied403The current role (params.role) lacks the permission params.permissionAsk an administrator to adjust Role permissions in Settings
admin_session_or_token_required403An admin action with no valid session and no X-RST-Admin-TokenSign in again, or send RST_ADMIN_TOKEN from ops scripts
setting_locked_by_env409The setting params.key is pinned by the environment variable params.envChange it in .env and recreate the container
eula_not_accepted403This account has not accepted this version of the license agreement (params.version)Read and accept it
rate_limited429Too many requestsWait params.seconds seconds; limits are set with RST_RATELIMIT_*

License

CodeHTTPMeaningRemedy
feature_needs_standard403params.feature needs Professional or Enterprise. Possible values: alert_triage (alert correlation), alert_investigation (fault investigation, remote ping and traceroute), detection_rule_copilot (triggers and monitoring config, maintenance-window assistant), platform_ops_copilot (platform checkup)Activate a license; see Editions
reports_need_professional403Reports, scheduled reports and inspections need Professional or EnterpriseActivate a license
feature_needs_enterprise403params.feature needs Enterprise. Possible values: sso_oidc (SSO, auditor role), offline_issuance (offline activation)Activate an Enterprise license; Professional licenses activate online
feature_sealed403No valid license, or the license lacks the feature key for this featureActivate a license that includes it; if an offline license lacks the key, ask us to reissue it
license_invalid403License verification failed (signature, decryption or tampering); everything except sign-in, the license agreement and the License page is refusedAsk sales to reissue it
license_status_abnormal403The license is in an unexpected stateCheck the License page
users_need_professional403Community Edition has one user; returned when creating or enabling an account, and the UI shows an upgrade dialogActivate a Professional or Enterprise license
user_seats_exhausted403All params.seats user seats on the license are in use; returned when creating or enabling an accountDisable an account, or buy more seats
seats_exceeded_admin_only403More accounts are enabled than the params.seats seats of the current license (expired, revoked, or fewer seats); returned to non-admins on sign-in or on any requestAn admin renews the license, or disables extra accounts on the Users page
machine_id_unreadable503Cannot read this machine's hardware identity (params.reason)Check that state/machine-id exists and is mounted as /etc/machine-id
license_deactivate_error500Deactivation failed (params.reason)Act on the reason

Zabbix

CodeHTTPMeaningRemedy
zabbix_unreachable502Cannot reach the Zabbix APICheck ZABBIX_URL, the network and the certificate
zabbix_auth_failedConnection test resultThe API token or username / password is invalidReplace the credentials; see Zabbix permissions
zabbix_request_failedConnection test resultThe Zabbix API returned an error (params.reason is Zabbix's own text)Act on the reason
zabbix_not_api400The address is not a Zabbix JSON-RPC endpointUse an address ending in /api_jsonrpc.php
zabbix_url_invalid400Not an http(s) URL, or it contains a username and passwordUse https://<host>/api_jsonrpc.php
zabbix_version_unsupported502The Zabbix version (params.version) is below 6.0Upgrade Zabbix; 6.0, 6.4, 7.0, 7.2 and 7.4 are verified
zabbix_query_failed502A Zabbix query failedSearch the gateway log for zabbix_call_failed
zabbix_call_rejected, zabbix_call_rejected_repair_failed400Zabbix rejected the generated API call and auto-repair did not helpExpand the API call in the chat, edit it and retry, or rephrase the question
secret_reentry_required400The connection address changed; stored credentials are not sent to a new addressEnter the token, password or API key again
index_not_whitelisted403Host group params.index is outside the host group allowlist (params.patterns)An administrator adds it to Host group allowlist in Settings
hosts_not_whitelisted403Some hosts are outside the host group allowlistSame as above
group_required_by_whitelist400A host group allowlist is active and the request named no host groupChoose a host group
host_group_not_found404Zabbix has no host group params.groupCheck the name
host_not_found, host_not_in_topology404Host params.hostid does not exist, or is not in the topologyNone
hostid_not_numeric, hostid_or_group_required, too_many_hosts400hostid is not numeric; no hostid or host group given; more than params.limit hosts at onceFix the request
maintenance_not_found404Maintenance params.id does not exist or was deletedNone
maintenance_not_managed403Maintenance params.name was not created by this productDelete it in Zabbix
maintenance_out_of_scope403The maintenance covers hosts or host groups outside the host group allowlistHandle it in Zabbix
diagnostics_script_scope_invalid403The Zabbix script params.script does not have the scope "Manual host action"Change the script's scope in Zabbix

Models and knowledge base

CodeHTTPMeaningRemedy
llm_timeout504The model call timed outRetry later, or raise the timeout in AI settings
llm_unavailable503Every enabled provider failedCheck the provider settings and the network path to the model endpoint
llm_unparseable502The model's output could not be parsedRetry
llm_request_failed502Any other model call failureSearch the gateway log for llm_call_failed
model_required400No model name givenFill it in
connection_test_failed400The connection test failed (params.reason)Act on the reason
kb_dim_mismatch409The knowledge base was built with params.index_dims-dimension vectors; the current model has params.real_dimsSwitch back to the original embedding model, or delete the knowledge base documents and upload them again

Feature calls

CodeHTTPMeaning
alerts_aggregate_failed502Alert statistics failed (params.reason)
platform_checkup_failed500The platform checkup failed; see the gateway log
nothing_to_explain400The query returned no rows, so there is nothing to interpret
invalid_time400params.what is not a valid time (params.value)
dsl_empty, cluster_empty, investigation_empty, markdown_empty400The request has no Zabbix API call, alert cluster, investigation or body text
body_not_object400The request body is not a JSON object

Outbound channels

CodeHTTPMeaningRemedy
push_failed500Delivery failed (params.reason)Check the delivery log
delivery_not_retryable409The delivery does not exist, or is queued or in flightNone
notify_target_not_found404The target does not existNone
webhook_url_required, webhook_must_be_https, webhook_host_invalid, feishu_url_must_be_https, feishu_host_not_allowed, feishu_path_invalid, dingtalk_path_invalid, wecom_key_missing, slack_path_invalid400The bot address is empty or malformedCopy it unchanged from the group bot settings
smtp_host_required, smtp_port_not_int, smtp_port_out_of_range, smtp_security_invalid, smtp_from_invalid400Mail server settings are malformedFix the settings
recipients_required, recipient_invalid400No recipients, or a malformed addressFix the settings
unknown_channel, unknown_period, periods_not_array, hour_not_int, hour_out_of_range, severity_threshold_invalid, name_required400Invalid channel, schedule or nameFix the settings
egress_metadata_refused400params.value is a cloud metadata address; no channel may post thereUse another address
egress_entry_invalid, egress_too_many400An extra address is not a valid host name, IP or CIDR; at most params.limit per channelFix the settings

Content packs and online update

CodeHTTPMeaningRemedy
content_token_required400No content pack token in the requestPaste the signed content pack token
content_pack_rejected400Bad signature, older than the active version, or incompatible (params.reason)Check where the token came from and its version
content_pack_apply_failed500Server error while applying the packCheck the gateway log
no_release_to_download400There is no new version to downloadChoose Check now first
release_download_failed400Download or staging failed: bad signature, not enough disk, or an updater that is too old (params.reason)Act on the reason
release_download_server_error500Server error during downloadCheck the gateway log
rollback_failed, rollback_server_error400, 500Content pack rollback failedAct on the reason

Messages without a code

These messages have no code and only a Chinese text, so the English UI shows them in Chinese.

Message (meaning)HTTPRemedy
请先登录。 (sign in first)401Sign in again
用户名或密码错误。 (wrong username or password)401None
登录失败次数过多,请稍后再试。 (too many failed sign-ins)429Retry after 5 minutes
该账号仍在使用出厂默认密码,禁止远程登录。 (factory password, remote sign-in refused)403Set RST_ADMIN_PASSWORD_HASH, or sign in on the host and change the password
跨站请求被拒绝(Origin 与本站不一致)。 (cross-site request refused)403Act from the product page itself
License 激活失败:… (activation failed)400The reason follows the colon; see the FAQ
License 激活异常:… (activation error)500Check the gateway log

On this page