> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# A: Account and sign-in

> Every A error code: what it means, when it happens and how to fix it.

32 codes. Each one is part of an error answer as `code`; `type` is the stable name that scripts branch on. The CLI shows the code at the end of its message, for example `(code: A01)`. Words in braces, such as `{name}`, are filled in with the actual value.

## A01

`authentication_required` · HTTP 401

> Please sign in to continue. (code: A01)

**When it happens.** The request carried no valid sign-in: none at all, an expired or revoked one, or one for a deleted account.

**How to fix it.** Sign in at kiste.run.

**In the CLI.** Run `kiste login`, or set KISTE_TOKEN for this process.

**Retry.** No. Retrying the same request gives the same answer.

## A02

`invalid_credentials` · HTTP 401

> The email address or password is wrong. (code: A02)

**When it happens.** A sign-in used a wrong email address or password.

**How to fix it.** Check both and try again.

**Retry.** No. Retrying the same request gives the same answer.

## A03

`too_many_attempts` · HTTP 429

> Too many sign-in attempts. Please wait {seconds} seconds and try again. (code: A03)

**When it happens.** Too many sign-ins were tried from this address or for this account in a short time.

**How to fix it.** Wait, then try again.

**Retry.** Yes, after 60 seconds. The answer carries `Retry-After`.

## A04

`account_locked` · HTTP 429

> This account is locked for {seconds} seconds after failed sign-ins. (code: A04)

**When it happens.** Repeated failed sign-ins locked the account for a while.

**How to fix it.** Wait, then sign in again.

**Retry.** Yes, after 900 seconds. The answer carries `Retry-After`.

## A05

`signup_disabled` · HTTP 404

> Signing up isn't open. (code: A05)

**When it happens.** Self-service sign-up is closed.

**How to fix it.** Ask for an invitation.

**Retry.** No. Retrying the same request gives the same answer.

## A06

`email_taken` · HTTP 409

> An account with this email address already exists. (code: A06)

**When it happens.** A sign-up used an email address that already has an account.

**How to fix it.** Sign in instead.

**Retry.** No. Retrying the same request gives the same answer.

## A07

`invalid_signup` · HTTP 400

> That sign-up isn't valid: {detail}. (code: A07)

**When it happens.** A sign-up had an invalid email address or a password of the wrong length.

**How to fix it.** Correct it and try again.

**Retry.** No. Retrying the same request gives the same answer.

## A08

`api_token_not_found` · HTTP 404

> There is no API key {token} in your account. (code: A08)

**When it happens.** A request named an API key that does not exist or was revoked.

**How to fix it.** Check your list of API keys.

**Retry.** No. Retrying the same request gives the same answer.

## A09

`api_token_name_taken` · HTTP 409

> You already have an active API key named {label}. (code: A09)

**When it happens.** A new API key used the name of an active one.

**How to fix it.** Choose another name, or revoke the existing key first.

**Retry.** No. Retrying the same request gives the same answer.

## A10

`invalid_api_token_request` · HTTP 400

> That API key request isn't valid: {detail}. (code: A10)

**When it happens.** A new API key had an invalid name or lifetime.

**How to fix it.** Correct it and try again.

**Retry.** No. Retrying the same request gives the same answer.

## A11

`api_token_cannot_mint` · HTTP 403

> An API key can't create other API keys. (code: A11)

**When it happens.** A request authenticated with an API key tried to create an API key.

**How to fix it.** Create API keys in the console or with the kiste command-line tool.

**Retry.** No. Retrying the same request gives the same answer.

## A12

`invalid_origin` · HTTP 403

> This request didn't come from kiste.run. (code: A12)

**When it happens.** A browser request that changes something came from another site (cross-site protection).

**How to fix it.** Reload kiste.run and try again.

**Retry.** No. Retrying the same request gives the same answer.

## A13

`cli_token_required` · HTTP 403

> This needs a sign-in from the command-line tool or an API key. (code: A13)

**When it happens.** A browser session called an action that only the command-line tool or an API key may call.

**How to fix it.** Use the kiste command-line tool or an API key.

**Retry.** No. Retrying the same request gives the same answer.

## A14

`oauth_invalid_request` · HTTP 400

> The sign-in request isn't valid. (code: A14)

**When it happens.** The command-line sign-in sent parameters kiste.run does not accept.

**How to fix it.** Start the sign-in again.

**In the CLI.** Run `kiste login` again.

**Retry.** No. Retrying the same request gives the same answer.

## A15

`oauth_code_invalid` · HTTP 400

> The sign-in code is invalid or has expired. (code: A15)

**When it happens.** The one-time sign-in code was wrong, already used or too old.

**How to fix it.** Start the sign-in again.

**In the CLI.** Run `kiste login` again.

**Retry.** No. Retrying the same request gives the same answer.

## A16

`oauth_user_gone` · HTTP 401

> The account for this sign-in no longer exists. (code: A16)

**When it happens.** The account was deleted while the sign-in was in progress.

**How to fix it.** Sign in with another account.

**Retry.** No. Retrying the same request gives the same answer.

## A17

`operator_only` · HTTP 403

> Only the operator can do this. (code: A17)

**When it happens.** An operator action was called by another account or with an API key.

**How to fix it.** Sign in with the operator account.

**Retry.** No. Retrying the same request gives the same answer.

## A18

`device_key_not_found` · HTTP 404

> There is no computer {id} signed in to your account. (code: A18)

**When it happens.** A request named a device key that is not registered.

**How to fix it.** Check your list of computers.

**In the CLI.** Check computers with `kiste devices`.

**Retry.** No. Retrying the same request gives the same answer.

## A19

`invalid_device_key` · HTTP 400

> That computer key isn't valid: {detail}. (code: A19)

**When it happens.** A device key had an invalid name or public key.

**How to fix it.** Correct it and try again.

**Retry.** No. Retrying the same request gives the same answer.

## A20

`session_not_found` · HTTP 404

> There is no sign-in {id} on your account. (code: A20)

**When it happens.** A request named a sign-in that does not exist or has ended.

**How to fix it.** Refresh your list of sign-ins.

**Retry.** No. Retrying the same request gives the same answer.

## A22

`test_account_exists` · HTTP 409

> The test account {name} already exists. (code: A22)

**When it happens.** A new test account used an existing name.

**How to fix it.** Choose another name.

**Retry.** No. Retrying the same request gives the same answer.

## A23

`invalid_test_account` · HTTP 400

> That test account isn't valid: {detail}. (code: A23)

**When it happens.** A new test account had an invalid name.

**How to fix it.** Correct it and try again.

**Retry.** No. Retrying the same request gives the same answer.

## A24

`webhook_not_found` · HTTP 404

> There is no webhook endpoint {id} in your account. (code: A24)

**When it happens.** A request named a webhook endpoint that does not exist.

**How to fix it.** Check your list of webhooks.

**Retry.** No. Retrying the same request gives the same answer.

## A25

`webhook_name_taken` · HTTP 409

> You already have a webhook endpoint named {name}. (code: A25)

**When it happens.** A webhook endpoint used a name you already use.

**How to fix it.** Choose another name.

**Retry.** No. Retrying the same request gives the same answer.

## A26

`invalid_webhook` · HTTP 400

> That webhook endpoint isn't valid: {detail}. (code: A26)

**When it happens.** A webhook endpoint had an invalid name, URL, host or event list.

**How to fix it.** Correct it and try again.

**Retry.** No. Retrying the same request gives the same answer.

## A27

`alert_not_found` · HTTP 404

> That alert doesn't exist. (code: A27)

**When it happens.** A request named an alert that does not exist.

**How to fix it.** Refresh your alerts.

**Retry.** No. Retrying the same request gives the same answer.

## A28

`invalid_alert` · HTTP 400

> That alert setting isn't valid: {detail}. (code: A28)

**When it happens.** Alert preferences named an unknown alert kind or had no values.

**How to fix it.** Correct it and try again.

**Retry.** No. Retrying the same request gives the same answer.

## A29

`token_rejected` · HTTP 401

> Your sign-in is no longer valid. (code: A29)

**When it happens.** A sign-in was sent but kiste.run did not accept it: it expired, was revoked, or belongs to a deleted account.

**How to fix it.** Sign in again.

**In the CLI.** Run `kiste login` again, or set a valid KISTE_TOKEN.

**Retry.** No. Retrying the same request gives the same answer.

## A30

`account_deletion_requires_sign_in` · HTTP 403

> Deleting your account needs your own sign-in; an API key can't do it. (code: A30)

**When it happens.** An account deletion was requested with an API key instead of a console or CLI sign-in.

**How to fix it.** Delete the account from the console, or with the kiste command after `kiste login`.

**Retry.** No. Retrying the same request gives the same answer.

## A31

`account_deletion_operator` · HTTP 403

> The operator account can't be deleted. (code: A31)

**When it happens.** The operator of this Kiste installation asked to delete their own account, which would lock everyone out of operating it.

**How to fix it.** Contact support if the service itself should be closed.

**Retry.** No. Retrying the same request gives the same answer.

## A32

`account_deletion_unconfirmed` · HTTP 400

> To delete your account, type its e-mail address exactly as confirmation. (code: A32)

**When it happens.** An account deletion was sent without the account's own e-mail address as confirmation, or with a different one.

**How to fix it.** Type the address shown in your account settings, then try again.

**Retry.** No. Retrying the same request gives the same answer.

## A33

`export_link_invalid` · HTTP 403

> This download link has expired or belongs to another account. (code: A33)

**When it happens.** A data export download used a link that expired, was altered, or was issued to a different account than the one signed in.

**How to fix it.** Request a new data export; each link works for ten minutes.

**In the CLI.** Run `kiste account export` again.

**Retry.** No. Retrying the same request gives the same answer.

## Related topics

- [Overview](https://docs.kiste.run/errors.md)
- [K: Kisten (machines, snapshots, images, environments, commands)](https://docs.kiste.run/errors/k.md)
- [N: Network and connections](https://docs.kiste.run/errors/n.md)
- [D: Desktop and browser links](https://docs.kiste.run/errors/d.md)
- [S: Kiste Stream (published apps on kiste.stream)](https://docs.kiste.run/errors/s.md)
- [B: Billing](https://docs.kiste.run/errors/b.md)
- [L: Limits and capacity](https://docs.kiste.run/errors/l.md)
- [C: The kiste command-line tool](https://docs.kiste.run/errors/c.md)
- [P: Platform](https://docs.kiste.run/errors/p.md)
- Previous: [S: Kiste Stream (published apps on kiste.stream)](https://docs.kiste.run/errors/s.md)
- Next: [B: Billing](https://docs.kiste.run/errors/b.md)
