{"record":{"id":"bce78a28de9b9792","repo":"Hmbown/CodeWhale","slug":"the-codewhale-service-returned-http-status","errorCode":null,"errorMessage":"The Codewhale service returned HTTP {status}.","messagePattern":"The Codewhale service returned HTTP (.+?)\\.","errorType":"http","errorClass":"MachineError","httpStatus":null,"severity":"error","filePath":"crates/cli/src/cloud/machine.rs","lineNumber":916,"sourceCode":"            let body = serde_json::to_vec(&ApiKeyCreateRequest {\n                name,\n                expires_in_days: create.expires_in_days,\n                scopes,\n            })\n            .context(\"failed to encode the Codewhale API key request\")?;\n            // `Retry::Never` is the whole point of the enum here: a POST that\n            // actually succeeded server-side would mint a second key whose\n            // one-time secret the caller never saw, and therefore can never\n            // revoke by id from the output they hold.\n            let response = client.execute_authenticated_with_retry(\n                HttpMethod::Post,\n                \"/api/account/api-keys\",\n                Some(body),\n                Retry::Never,\n                sleeper,\n            )?;\n            if !(200..300).contains(&response.status) {\n                return Err(anyhow::Error::new(classify(&response)));\n            }\n            let created: ApiKeyCreateResponse = decode_json(response)?;\n            write_created_key(out, &created)?;\n            if create.use_locally {\n                save_key_as_local_codewhale_credential(provider_secrets, &created.secret, out)?;\n            }\n            Ok(())\n        }\n        ApiKeysCommand::List => {\n            let response = client.execute_authenticated_with_retry(\n                HttpMethod::Get,\n                \"/api/account/api-keys\",\n                None,\n                Retry::Idempotent,\n                sleeper,\n            )?;\n            if !(200..300).contains(&response.status) {\n                return Err(anyhow::Error::new(classify(&response)));","sourceCodeStart":898,"sourceCodeEnd":934,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/433685b2024e7bc4c99e1e2e326bcad39b4d9d65/crates/cli/src/cloud/machine.rs#L898-L934","documentation":"The api-keys Create command POSTs to /api/account/api-keys with Retry::Never. If the HTTP status is outside 2xx, the response is classified into a MachineError and returned as an anyhow error worded \"The Codewhale service returned HTTP {status}.\" The key is not created locally.","triggerScenarios":"Running codewhale account api-keys create when the session credential is missing/expired (401), the account lacks permission (403), the request body is rejected (400/422), or the server errors (5xx).","commonSituations":"Expired Codewhale session cookie; creating keys on an account without the api-key scope; server-side validation rejecting expires_in_days or scopes; transient 502/503 from the service.","solutions":["Re-authenticate the Codewhale session if the status is 401","Check account permissions/scopes for api-key creation on 403","Fix the create arguments (expires_in_days, scopes) on 400/422","Retry on 5xx; the create call is deliberately never auto-retried","Run whoami to confirm the session is valid before creating keys"],"exampleFix":"# confirm the session first, then create\n# before\ncodewhale account api-keys create --use-locally\n\n# after\ncodewhale account api-keys whoami && codewhale account api-keys create --use-locally","handlingStrategy":"try-catch","validationCode":"// verify the session before creating keys\nlet who = client.whoami(&mut sleeper)?;","typeGuard":null,"tryCatchPattern":"match create_key(&client, &body, &mut sleeper) {\n    Ok(created) => store(created),\n    Err(err) if err.to_string().contains(\"returned HTTP 401\") => {\n        eprintln!(\"Session expired; run `codewhale login` and retry\");\n    }\n    Err(err) => return Err(err),\n}","preventionTips":["Run whoami before api-keys create to catch expired sessions","Confirm account scope/permissions for machine-token management","Validate expires_in_days and scopes client-side before the POST","Remember create is Retry::Never: retry manually only after diagnosing the status"],"tags":["http","cloud","api-keys"],"backgroundTag":"http-error-response","analyzedSha":"433685b2024e7bc4c99e1e2e326bcad39b4d9d65","analyzedAt":"2026-09-15T12:24:24.634Z","contentChangedAt":"2026-09-15T12:24:24.634Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}