200 | OK | Successful read or idempotent write |
201 | Created | New resource created (key, request, sync run) |
202 | Accepted | Async work queued (sync run) |
204 | No Content | Successful CORS preflight |
302 | Found | OAuth redirect to provider |
400 | Bad Request | Validation failed, missing params, malformed OAuth state |
401 | Unauthorized | Missing or invalid bearer token |
402 | Payment Required | No active subscription (paywalled tiers only) |
403 | Forbidden | Authenticated but lacking the required scope, role, or tier limit |
404 | Not Found | Resource doesn’t exist or you don’t have access to see it |
409 | Conflict | e.g. revoking the key currently in use |
429 | Too Many Requests | Rate limit OR credit budget exceeded |
500 | Internal Server Error | Repo bug or DB failure — file a report |
502 | Bad Gateway | Upstream OAuth provider or LLM error |
503 | Service Unavailable | A required service isn’t configured (e.g. Stripe in dev) |