Skip to content
downpipes docs

Look up a console error message

When a read or an action fails outright, the console shows a heading and a sentence as a block error, and this page lists every one of those eighteen headings exactly as it appears on screen, so searching the words in front of you finds the explanation. A drill, restore or prune result that completed without fully succeeding is a separate, deliberately non-error channel (an expected in-flow outcome, never an error toast). That channel’s own headings are documented where that action is, not here.

The headings below are grouped by what you should do about them, because that is the only grouping that helps at the moment you are reading one. One heading, Verify your identity, carries seven different sentences depending on how the identity check ended, and they are listed under it verbatim as well, so a search of the sentence finds this page just as a search of the heading does.

It is about your permission or an approval

Not permitted

Your role does not permit this action. The control should have been gated before you could reach it, so seeing this heading means the engine refused a direct request rather than a click. Check the capability your role holds in roles and capabilities.

Verify your identity

The action needs a fresh identity check that was not completed. Your session is still active, so you have not been signed out, and nothing was changed: the check runs before the engine dispatches the action.

This heading is the one on the page whose sentence underneath it varies, so the words you search may be the sentence rather than the heading. There are seven, and they are not interchangeable.

The sentence you were shownWhat happenedWhat to do
“This action needs a fresh identity check that was not completed. Your session is still active. Try again, and approve the passkey prompt when it appears.”No ceremony outcome was attached to this refusal. The console clears its record when a ceremony starts and consumes it when it is read, so this generic sentence is what you get when the refusal did not come from a ceremony the console had just runRetry. This is the only one of the seven that carries no specific diagnosis
“The engine would not start the identity check, so nothing was changed.”The engine refused to open the ceremony, so no prompt was ever raisedRetry once. If it does not clear, and it does not clear for anybody else either, the deployment is very likely missing its CONSOLE_ORIGIN, which no retry will fix. See step-up re-authentication
“That passkey was not accepted for the identity check, so nothing was changed.”A prompt opened, you answered it, and the engine rejected the assertionRetry with a passkey enrolled for this account. A credential the engine does not hold for you fails at this exact step
“This action needs a passkey assertion and no passkey is enrolled for your account, so nothing was changed.”The engine holds no passkey for your account, so it has nothing to check withEnrol a passkey from the sign-in screen, then retry. A retry alone cannot succeed
“Your browser refused the identity check, so nothing was changed.”The browser refused the ceremony before it opened a prompt. The engine was reached and answeredTry another browser or device. If it repeats, quote the message to support
“The identity check could not be completed because the console did not get a usable answer from the engine, so nothing was changed.”The request that starts or finishes the ceremony got no usable answer from the engineTry again in a moment
“The passkey check was not completed, so nothing was changed.”The prompt was dismissed, or it timed out, or this device holds no passkey enrolled for you. Those cannot be told apart, by design, so that no site can test whether you hold oneIf you saw a prompt, retry and approve it. If no prompt appeared, you have no passkey on this device, and the remedy is enrolment rather than another attempt

That last row is the one to read twice, because enrolment is not on the Access and security tab. The tab lists the passkeys you already hold and revokes one; it has no control that enrols a new one. Enrolment is on the sign-in screen, as the sentence says. You reach the screen either by signing in with a banked recovery code (which takes you straight to it) or through an invite link an owner issues for your address. The console has no control that enrols a passkey from inside an ordinary signed-in session.

The engine refused this on authority

The engine refused this and did not say which permission was missing. The cause is not always your own role. The engine also refuses an action that somebody else proposed when their authority changed before it ran. Nothing was changed. Ask an Owner if you expected the action to be allowed.

Awaiting approval

The apply needs a second authorised identity to approve this exact plan, and the approver must differ from you. Raise or open the approval, then apply once it is approved. See dual control for restores.

Your session is not valid

Your sign-in session is not valid. Sign in again to continue.

It is a setup step, not an outage

These four usually mean the engine and console are not wired to each other correctly. None of them is a fault in your data. Retrying does not fix a wiring fault.

Engine CONSOLE_ORIGIN is not set to this console

The engine is reachable but does not allow this console’s origin, so the browser blocks the response. Set the engine’s CONSOLE_ORIGIN to this console’s URL.

The engine’s cross-site request check refused this

The engine refused the request at its cross-site request check, before the request reached the action. The cause is not your role or your permissions. Nothing was changed. If the engine’s CONSOLE_ORIGIN does not match this console’s address, the engine refuses every save from this console the same way. Set CONSOLE_ORIGIN to this console’s address and redeploy the engine. If it matches, reload the console and try again.

This console was deployed without its engine binding

The console proxies the engine on its own hostname through a service binding, and this deploy has none, so the engine is receiving nothing at all. The engine URL is not the problem and may be perfectly healthy: restore the ENGINE service binding in the console’s deploy and redeploy the console. Changing the engine URL does not fix it.

A Prometheus or OpenTelemetry scraper pointed at this hostname is being refused at the same time and for the same reason, so treat a metrics endpoint that went quiet alongside this error as one fault rather than two.

That address answered with a web page, not engine data

Something served a web page where the engine’s data was expected. Check the engine URL, and that the engine is deployed and healthy. A proxy or a hosting placeholder in front of the engine answers this way too.

It is the engine, or the path to it

Could not reach the engine

The request did not complete at all. Check that this browser can reach the engine address, then try again.

The console answered for the engine, and the engine did not

The proxied call failed inside the console itself, so the engine never received it. Check that the engine Worker is deployed, is not throwing on start-up and is within its resource limits. This is distinct from the engine returning an error: there is nothing in the engine’s own logs to find, because the request never arrived.

Something in front of the engine refused this

The refusal did not arrive in the engine’s own form. Something between your browser and the engine made it, such as a firewall rule or a proxy. The engine may never have seen the request, so its logs may hold no record of it. Nothing was changed. Retry, and if it persists, check the rules in front of the engine address.

The console could not handle this

The request carries no engine status and does not read as a network failure. The console’s own code failed on the answer, most often because the console and engine builds do not match. This is not a reachability problem, so checking the engine’s address will not help. Retry, and if it persists, check that the console and engine are on compatible versions.

The engine returned an error

The request reached the engine and it failed. Retry, and if it persists check the engine logs, which will have the refusal.

The engine answered, but the response could not be read

The request reached the engine and completed, but the response could not be understood. This is not a reachability problem, so checking the network will not help: it usually means a version mismatch between the console and the engine. Update them to matching versions.

The request must wait

A limit refused this request for now. Too many requests arrived in a short time, or an approval came too soon after its request was raised. Nothing was changed. Wait a moment and try again; where the engine tells the console how long to wait, the message says. Bulk actions pace themselves, so a flood of requests is more likely from several people or several tabs acting at once than from one fleet action.

It is Cloudflare Access

Your Cloudflare Access session needs refreshing

Cloudflare Access answered with its own page where engine data was expected. Re-authenticate through Access and try again.

Sign in to Cloudflare Access again for this action

This action needs a Cloudflare Access sign-in within the last five minutes, and yours is older. Nothing was changed. Sign out of Access by opening /cdn-cgi/access/logout on this console’s address. Sign back in, then retry.

When a message says nothing was changed

Where a message says nothing was changed, for almost all of them nothing was: the refusal happened before the write. One class of route is the exception: the update-apply and gradual-ramp start routes can catch a fault after they have already started a deploy, and still report “nothing was changed”. That sentence comes from the route’s outer catch, which returns a fixed string and discards the exception, whatever stage the route reached. The engine records the last stage the route passed (recordAdminRouteError, engine/src/admin/diag-counters.ts) because that sentence can be wrong there, so a fault during or after an update should be checked against the diagnostics rather than taken as proof nothing moved.

The licence activation route has the same gap. A fault while it stores the licence still reports “nothing was changed”, although the engine may already hold the licence. Every other refusal on this page is a genuine pre-write gate.

Last updated .