arkushHelp

Reference

Error messages

How to read an entry

Each error message in arkush has a short code, for example not-shared. The link under the message opens its entry on this page. An agent gets the same code in the reason field of a refusal. An entry says what happened, who can fix it, and what to do.

Who can fix it is one of these people or programs:

If you tell an operator about an error, give the code and the time it happened. The server's log records the code, so the operator can find the line.

Sign-in and sessions

You are not signed in

not-signed-in · Who can fix it: You

The request arrived with no signed-in session. The session ended, or nobody signed in.

What to do: Sign in, then repeat the act. Work kept in this browser saves once you are signed in.

This account may not sign in here

signin-not-allowed · Who can fix it: The operator of this site

This site admits only the accounts on its sign-in list, and this account is not on it.

What to do: Sign in with an account on the list, or ask the operator of this site to add this one.

The account has no verified address

signin-no-verified-address · Who can fix it: You

The sign-in provider confirmed the account, but it lists no verified email address for it, and this site signs people in by a verified address.

What to do: Verify an address in the account's settings at the provider, then sign in again.

The provider does not vouch for this address

signin-address-unvouched · Who can fix it: You

The account uses an address that the sign-in provider does not run, such as a Google account made on a company address. The provider checked the address once, when the account was made. This site confirms such an address with an email code, and this site sends no email codes.

What to do: Sign in with an account whose address the provider runs, such as a Gmail address or a company Google account, or sign in another way the sign-in page offers.

The account is not in a listed organization

signin-not-member · Who can fix it: You

This site admits GitHub accounts only from the GitHub organizations it lists, and this account is no active member of one.

What to do: Sign in with a different account, or ask an owner of the organization to add this one. A pending invitation counts once it is accepted.

The organization has not approved this site

signin-org-approval · Who can fix it: You

This site admits GitHub accounts only from the GitHub organizations it lists, and an organization blocks apps it has not approved from reading its members.

What to do: Ask an owner of the organization to approve this site's app under the organization's third-party access settings, then sign in again.

The sign-in or consent page expired

signin-expired · Who can fix it: You

A sign-in or an agent's consent page was opened too long ago, or it started on another site.

What to do: Start again where you began: the app's sign-in, or the connection step in your agent.

Sign-in or connection was cancelled

signin-cancelled · Who can fix it: You

The sign-in at the provider, or the consent for an agent, stopped before it finished.

What to do: Start the sign-in or the agent connection again and complete it.

The sign-in provider did not confirm you

signin-provider-failed · Who can fix it: You

The sign-in provider answered, but it did not confirm the sign-in.

What to do: Try again. If it fails again, tell the operator of this site, who checks the provider setup.

The sign-in code no longer works

signin-code-spent · Who can fix it: You

A sign-in code works once, for 10 minutes, for 5 tries, and only in the browser that asked for it. This code was used, ran out, or was typed in another browser.

What to do: On the sign-in page, type your address again to get a new code, then type the newest code in the same browser.

The sign-in code could not be sent

signin-code-not-sent · Who can fix it: The operator of this site

The mail relay this site sends codes through did not accept the message.

What to do: Try again in a minute. If it fails again, sign in another way, and tell the operator of this site, who checks the relay settings.

Too many sign-in attempts

signin-too-many · Who can fix it: You

This site sends one address 3 codes in an hour, and counts an address with a +tag as the same address. It also limits how many sign-in attempts come from one network, and how many codes the whole site sends in an hour.

What to do: Wait for the time the page names, then try again, or sign in another way. A code you already received keeps working for 10 minutes in the browser that asked for it.

The passkey step did not finish

signin-passkey-failed · Who can fix it: You

The device offered a passkey this site does not hold, the passkey step stopped before it finished, or an answer from the device came a second time. A passkey ends when an admin uses Revoke all on the account or the person removes it.

What to do: To sign in, sign in another way, then add a passkey again from the Passkeys entry of the account menu. To add a passkey, start the step again from that entry.

Adding a passkey needs a recent sign-in

passkey-needs-fresh-signin · Who can fix it: You

A passkey is added only within 10 minutes of a sign-in that did not use a passkey, so a session someone else took over cannot add one.

What to do: Sign out, sign in again without a passkey, then add the passkey.

Agents

Agents are limited on this site

agents-not-allowed · Who can fix it: An admin of this site

An admin limited who may connect an agent, and this account is not on that list.

What to do: Work on your dashboards in the app, or ask an admin of this site to add you in the access settings.

The agent has no working connection

agent-not-connected · Who can fix it: Your agent's software

The agent sent no token, or a token, code or refresh token that expired or was revoked.

What to do: The agent's software starts sign-in again on its own. If it does not, remove the connection in the agent and add it again.

This site does not recognize the agent

agent-unrecognized · Who can fix it: You

The request names an agent client that this site cannot match to its registration.

What to do: Remove the connection in the agent and set it up again.

The agent's request broke the protocol

agent-protocol-error · Who can fix it: Your agent's software

The agent's OAuth or MCP request is missing a required part, or asks for something this site does not support.

What to do: Update the agent's software, or send the error text to its maker.

Too many requests at once

rate-limited · Who can fix it: You

This site got more requests or live connections than it serves at one time.

What to do: Wait a minute, then try again. Close the tabs of this site that you do not need.

Access

Not shared with you

not-shared · Who can fix it: The owner of the item

The dashboard, shared datasource or uploaded file is not shared with this account, or its share was removed.

What to do: Ask its owner to share it with you.

You can view but not edit

no-edit-access · Who can fix it: The owner of the item

This account can view the item but cannot change it.

What to do: Ask the item's owner for edit access. Changes made in the app stay in this browser: export a copy to keep them. An agent builds its chart in the person's sandbox instead, with get_sandbox.

This belongs to another person

not-yours · Who can fix it: The owner of the item

Only the item's owner takes this act: a comment's author deletes it, a sandbox's owner opens it, a dashboard's owner hands it over or publishes it.

What to do: Ask the owner to take the act. An admin can reassign a dashboard's owner.

This needs the admin right

not-admin · Who can fix it: The operator of this site

The act is administration, and this account is not on this site's admin list.

What to do: Ask an admin to take the act, or ask the operator of this site to add you to the admin list.

This needs the analyst right

not-analyst · Who can fix it: The operator of this site

The act needs the analyst right, which this account does not have. The analyst right covers the libraries, the official stamp, sending a delivery, and reading a private address with this site's Google credential.

What to do: Ask a person with the analyst right to take the act, or ask the operator of this site to add you to the analyst list.

Only admins may widen access or hand over ownership here

sharing-limited · Who can fix it: An admin of this site

On this site, only admins share a dashboard beyond its owner, open it to everyone signed in, publish it, or hand it to a new owner.

What to do: Share it with named people where the message allows it, or ask an admin of this site to take the act.

No share of yours to leave

nothing-to-leave · Who can fix it: You

Leave removes a share that names your own address. You own this item, or you reach it through a group or because it is open to everyone signed in, and neither is a share of yours.

What to do: If you own it and no longer need it, move it to the trash or delete it. If you reach it through a group or everyone signed in, it stays in your list, and its editors decide who can view it.

This site does not publish to the internet

publishing-off · Who can fix it: The operator of this site

Publishing to the internet is off on this site.

What to do: Share the dashboard with the people who need it. The operator of this site decides if publishing is on.

That change has its own act

not-a-save · Who can fix it: You

A save or an agent's patch tried to change a field that only its own act changes: access, the official stamp, publishing, the trash marker, or delivery approvals.

What to do: Make the change with its own control in the app, for example the Share panel. An agent asks the person it works for to make it there.

The dashboard is in the trash

in-trash · Who can fix it: You

The dashboard is in the trash. It deletes permanently on the date the message shows.

What to do: Restore it from the Trash section of your dashboards, or with restore_dashboard, then continue.

Nothing by that name or id

not-found · Who can fix it: You

The dashboard, datasource, block, file, version, guide part or other item the request names does not exist, or it was deleted.

What to do: Check the link or the name, then open the item from its list.

Nothing is published at this address

not-published · Who can fix it: The owner of the item

No dashboard is published at this address. It was unpublished, or the address is wrong.

What to do: Check the address with the person who gave it to you. Only the dashboard's owner can publish it again.

Sandboxes

Sandboxes are off on this dashboard

sandboxes-off · Who can fix it: The owner of the item

The dashboard's editors turned off sandboxes. The sandbox is kept and readable, and nothing can be added to it.

What to do: Ask the dashboard's owner to add the chart, or to turn sandboxes on again.

Editors work on the dashboard itself

editor-no-sandbox · Who can fix it: You

This account can edit the dashboard, so it gets no sandbox.

What to do: Add the chart to the dashboard directly.

Requests and content

The request has the wrong shape

bad-request · Who can fix it: The software that sent the request

The software that sent the request left out a required part, sent a body of the wrong shape, used an unknown route or method, or left out the version a save needs.

What to do: In the app, reload the page to get its current version. A script or an agent corrects the request as the message says.

A value was not accepted

bad-value · Who can fix it: You

A value entered for a name, an address, a schedule, a setting or a comment breaks the rule the message states, or the name is taken.

What to do: Change the value the message names, then try again.

The dashboard breaks the format

invalid-doc · Who can fix it: You

The document, or the result of a patch, does not follow the dashboard format or a sandbox's own rules.

What to do: Fix the part the message names. To open a file, choose a dashboard file this app saved.

The patch could not be applied

bad-patch · Who can fix it: You

A JSON Patch operation names a path that does not exist, or its test operation failed.

What to do: Read the dashboard outline again with get_dashboard, then build each path from the block index i it gives.

Someone changed it first

conflict · Who can fix it: You

The item changed after you loaded it, and your change overlaps that change.

What to do: Reload the item, then make your change again.

Too large for this site

too-large · Who can fix it: You

A file, a request, a fetched source, a database result or a rendered image is over the size this site accepts.

What to do: Send a smaller file or less data. For a database result, select fewer or narrower columns. For a chart image, draw fewer marks or use a smaller block.

A request from another site was refused

cross-site-refused · Who can fix it: The software that sent the request

A write came to this site from another site's page, with no token.

What to do: Make the change from this site's own pages. A script sends a bearer token.

Upload storage is full

storage-quota · Who can fix it: The owner of the item

The uploaded files of the account the file counts against fill its whole storage allowance.

What to do: The file's owner deletes the uploaded files they no longer use, then uploads again.

The file cannot be read

file-not-readable · Who can fix it: You

The file or the fetched source is empty, or it is in a format this site does not read.

What to do: Choose a file with data, in a format the message names.

The uploaded file is gone

file-missing · Who can fix it: The owner of the item

The uploaded file a datasource reads was deleted, or its stored bytes or record are lost.

What to do: The file's owner uploads it again, or an editor points the datasource at another file. The snapshot keeps its last data.

Runs

The server is busy

server-busy · Who can fix it: You

Other queries and chart renders were using all the memory this site gives to heavy work, and no room opened within 10 seconds.

What to do: Wait a minute, then try again.

The data is not loaded yet

no-snapshot · Who can fix it: You

A datasource this act needs has no snapshot yet, or its stored rows could not be loaded.

What to do: An editor refreshes the datasources the message names, then saves. A viewer asks the owner of the dashboard to refresh them. On a published page, reload the page.

The datasource has no query

no-sql · Who can fix it: You

The datasource has no SQL to run.

What to do: Write its query, then run it.

Imported data has nothing to run

imported-data · Who can fix it: You

The datasource holds imported rows. Its rows are its snapshot, so there is no query to run.

What to do: Edit the data in the app, or give the datasource a source with a query.

This source does not run here

wrong-source · Who can fix it: You

The datasource's source cannot do this act on this surface. It runs in a person's browser, names no file, address or database, or reads other datasources.

What to do: Refresh it in the app as the message says, or change its source.

Save the dashboard to the server first

needs-server-copy · Who can fix it: You

The datasource runs on the server, and this dashboard exists only in this browser.

What to do: Sign in if needed, save the dashboard to the server, then refresh the datasource.

The query failed

sql-error · Who can fix it: You

BigQuery, the DuckDB engine or a registered database refused the SQL, or a table it names does not exist.

What to do: Fix the SQL where the message points, then run it again.

The result has too many rows

row-cap · Who can fix it: You

The result has more rows than a snapshot holds.

What to do: Reduce the rows in SQL: aggregate, filter or limit.

The query would scan too much

bytes-billed · Who can fix it: You

BigQuery estimated a scan larger than this site's cost ceiling.

What to do: Scan less: filter on a partition column and select fewer columns. The operator of this site sets the ceiling.

The run took too long

run-timeout · Who can fix it: You

A query, a sheet read or a chart render ran past its time or memory limit.

What to do: Make the work smaller, with a tighter query, fewer rows or fewer facets. Then try again.

The chart could not be drawn

render-failed · Who can fix it: You

The block's spec is empty, the block type draws no image, or the spec and its data drew nothing.

What to do: Fix the spec or its data so it draws, then render it again.

Warehouse credentials

No service account is named

no-service-account · Who can fix it: You

A server-side BigQuery run or a database run names no service account, and every server-side run must name one.

What to do: Pick an account in the datasource's "Runs as" picker. A BigQuery datasource can also run as your own Google account. A database datasource cannot.

Google does not let you use this account

service-account-denied · Who can fix it: An admin of this site

Google's policy on the service account does not give you the Service Account User role, or it gives the role through a group this site cannot read.

What to do: Pick another account in "Runs as", or ask an admin of this site to grant you the role on that account.

This site cannot use the service account

service-account-setup · Who can fix it: An admin of this site

This site cannot read the account's IAM policy, or cannot get a token for the account.

What to do: An admin fixes the Google Cloud setup that the message names. That is a role for this site's own identity on that account, an API to enable, or the access scopes of this site's credential. Admins see the command where one fixes it.

The service account is not registered

unregistered-service-account · Who can fix it: An admin of this site

The datasource names a service account that this site has not registered.

What to do: Pick a registered account in "Runs as", or ask an admin to register this one under Credentials in Administration.

The account cannot read that data

warehouse-permission · Who can fix it: An admin of this site

BigQuery refused because the account the run used cannot read a table in the query.

What to do: Ask an admin to give that account read access to the dataset in Google Cloud, or pick another account.

Sources (sheets and addresses)

This site does not fetch from that host

address-not-allowed · Who can fix it: The operator of this site

The address is on a host that this site is not set to fetch from.

What to do: Read the sheet with your own Google account, or ask the operator of this site to add the host.

This address is refused

address-refused · Who can fix it: You

The address points into a private network, or it redirects to an address without https. This site never reads either.

What to do: Use a public https address.

The source refused access

source-not-readable · Who can fix it: You

The sheet or the address refused the account that read it.

What to do: Share the sheet with the account the message names, or pick a source that account can read.

The source is not there

source-not-found · Who can fix it: You

The sheet, the tab or the address the datasource reads no longer exists.

What to do: Correct the address, or pick the tab again.

An outside service did not answer

upstream-unreachable · Who can fix it: The software that sent the request

BigQuery, Google Sheets, Google's token service, the fetched host or a registered database did not answer, or it answered with an error.

What to do: Try again in a few minutes. If it fails again, the operator of this site can check the logs for this code.

Databases

The database is not registered

unregistered-database · Who can fix it: You

The datasource names a database that this site has not registered.

What to do: Pick a registered database in the datasource editor. The operator of this site registers databases.

This site cannot connect to the database

database-setup · Who can fix it: The operator of this site

The database refused the service account’s sign-in, or its certificate did not match what this site registered for it.

What to do: The operator of this site makes the account an IAM user of the database and checks the registered certificate. The message says which of the two failed.

The account cannot read that table

database-permission · Who can fix it: The operator of this site

The service account signed in to the database, and the database refused it read access to a table the query names.

What to do: Tell the operator of this site. The operator asks the owner of the database to give that account read access to the table. Until then, pick another account.

Google in the browser

Connect Google again

google-not-connected · Who can fix it: You

Google refused the token this browser holds, the token expired, or no Google account is connected.

What to do: Connect Google again in the datasource editor, then refresh.

Google sign-in did not finish

google-signin-failed · Who can fix it: You

Google sign-in did not load, its popup was blocked or closed, a permission was not given, or Google could not return the account.

What to do: Allow popups for this site and check the connection and any ad blocker. Then connect again and allow each permission Google asks for.

Deliveries and subscriptions

The delivery waits for approval

delivery-not-approved · Who can fix it: A person with the analyst right

A delivery sends on schedule only after a person with the analyst right sent it once. It was never sent, it changed after that send, or the person who sent it can no longer send it.

What to do: A person with the analyst right presses Send now once.

The delivery cannot be composed

delivery-content · Who can fix it: You

The delivery names an unregistered destination or has no text and no blocks, or its text and queries do not produce the values it needs.

What to do: Fix the delivery as the message says, then send it again.

Slack refused the message

slack-failed · Who can fix it: An admin of this site

Slack refused the send or did not answer, for example for a missing bot permission or a channel the bot is not in.

What to do: An admin checks the destination and its bot under Deliveries in Administration. For a channel, invite the bot to it.

Slack does not know your address

slack-member-unknown · Who can fix it: You

The Slack workspace has no member with your email address.

What to do: Paste your Slack member ID in the subscription form.

You have the most subscriptions allowed

subscription-cap · Who can fix it: You

You already hold the most subscriptions one person may hold.

What to do: Unsubscribe from one, then add the new one.

The data was not refreshed by an approved run

rows-unsealed · Who can fix it: The owner of the item

The dashboard's stored rows are not the rows its last authorized run wrote, so scheduled messages with rows pause. Or a scheduled refresh has no person left who may still run it.

What to do: The dashboard's owner or an editor who may run the datasource refreshes it once, and the schedule resumes.

This browser

This browser did not store the work

browser-storage-refused · Who can fix it: You

The browser refused to save the dashboard: site storage is off, or the disk is full.

What to do: Export a copy to a file. Then allow site storage, or free disk space.

The copy did not work

clipboard-refused · Who can fix it: You

The browser did not let the page copy to the clipboard.

What to do: Select the text and copy it by hand.

The download did not finish

download-failed · Who can fix it: You

A chart was not drawn yet, or the browser could not write the file.

What to do: For a chart, wait until it draws. For a file, check that the browser may save downloads and that the disk has room. Then try again.

The data engine did not load

engine-unavailable · Who can fix it: You

The in-browser data engine did not load.

What to do: Reload the page. If it fails again, use a current desktop browser.

The server did not answer

server-unreachable · Who can fix it: You

The app could not reach this site's server.

What to do: Check your connection and reload the page. Your work stays in this browser.

This site

This site has not set that up

not-configured · Who can fix it: The operator of this site

The act needs a part that this site did not set up: its own BigQuery, a service-account registry, the uploaded-file store, fetch hosts, a Google credential of its own, sandboxes, a groups source, a Slack bot for direct messages, a destination registry, a database registry, the datasource library, the manual refresh route, or a waitlist.

What to do: Use the other path the message names. The operator of this site decides whether to set up the part.

This site's setup has a fault

server-misconfigured · Who can fix it: The operator of this site

A setting of this site is broken. Examples: a page file it cannot write, a Google client setup that fails, a key file of its own that Google refuses.

What to do: Tell the operator of this site. The message names the setting.

The stored copy is damaged

stored-copy-unreadable · Who can fix it: The operator of this site

The stored content of the dashboard does not parse, so the app cannot open it or change its access.

What to do: Ask the operator of this site to repair the stored copy or restore it from a backup.

Unexpected server error

internal · Who can fix it: The operator of this site

The server failed in a way that no other code describes.

What to do: Try again. If it fails again, tell the operator of this site when it happened. The log line carries this code.