Repository navigation
Anthropic chat client retries and crashes agent threads on 401 PermissionDenied (rejected provider credentials) #4954
Description
Activity
systemorph-com commented
on Sep 20, 2026 ContributorAuthorMore actionsStill occurring: 1 more since the last update (39 total).
- Last seen: 2026-09-20 07:25:32Z
- Pods:
memex-portal-deployment-65f8c68995-c7z8l,memex-portal-deployment-c96b8bff8-jx7bd,memex-portal-deployment-7969b8cfff-fqnk9,memex-portal-deployment-57b689f955-wrstj,memex-portal-deployment-7969b8cfff-gtmlb,memex-portal-deployment-57b689f955-h6d47,memex-portal-deployment-7cfbf545d9-gtlhr,memex-portal-deployment-58c7bb4b9d-z2xcv,memex-portal-deployment-86779d495b-ksxqq,memex-portal-deployment-5d4bfc98b7-ff447,memex-portal-deployment-54cc8d6b4d-cjnqn,memex-portal-deployment-66f4b5c9b6-mcm2z,memex-portal-deployment-77898c4947-6mffn,memex-portal-deployment-79ddd44d77-k8qlc,memex-portal-deployment-7bff7d8b54-5rrkx,memex-portal-deployment-84d966d9bd-nlv6z,memex-portal-deployment-7fd85c4468-gwghs,memex-portal-deployment-78c786fcf6-bs4fn
Recent log lines
2026-09-08 09:29:52Z memex-portal-deployment-7fd85c4468-gwghs fail: MeshWeaver.AI.AgentChatClient[0] [ThreadExec] ERROR: 09:29:52.196 threadPath=Admin/_LogIncident/d2249f800ffc2577/_Thread/triage-the-log-incident-at-admin-loginci-b884 System.Net.Http.HttpRequestException: Response status code does not indicate success: 401 (PermissionDenied). at System.Net.Http.HttpResponseMessage.EnsureSuccessStatusCode() at MeshWeaver.AI.Anthropic.AnthropicChatClient.SendWithRetryAsync(ClaudeRequest request, HttpCompletionOption completionOption, CancellationToken cancellationToken) in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 545 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 116 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at System.Threading.Tasks.ValueTask`1.ValueTaskSourceAsTask.<>c.<.cctor>b__4_0(Object state) --- End of stack trace from previous location --- at MeshWeaver.AI.StreamStallGuardChatClient.Swallow(Task task) in /repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 148 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 139 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at Microsoft.Extensions.AI.FunctionInvokingChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options,…[truncated] 2026-09-20 06:53:26Z memex-portal-deployment-65f8c68995-c7z8l fail: MeshWeaver.AI.AgentChatClient[0] [ThreadExec] ERROR: 06:53:26.722 threadPath=Admin/_LogIncident/48aa520ad7e4b1b6/_Thread/triage-the-log-incident-at-admin-loginci-8c45 System.Net.Http.HttpRequestException: Response status code does not indicate success: 401 (PermissionDenied). at System.Net.Http.HttpResponseMessage.EnsureSuccessStatusCode() at MeshWeaver.AI.Anthropic.AnthropicChatClient.SendWithRetryAsync(ClaudeRequest request, HttpCompletionOption completionOption, CancellationToken cancellationToken) in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 546 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 117 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at System.Threading.Tasks.ValueTask`1.ValueTaskSourceAsTask.<>c.<.cctor>b__4_0(Object state) --- End of stack trace from previous location --- at MeshWeaver.AI.StreamStallGuardChatClient.Swallow(Task task) in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 149 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 140 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at MeshWeaver.AI.ProviderCallT…[truncated] 2026-09-20 07:25:32Z memex-portal-deployment-78c786fcf6-bs4fn fail: MeshWeaver.AI.AgentChatClient[0] [ThreadExec] ERROR: 07:25:32.088 threadPath=Admin/_LogIncident/69fc2c77c29dfcb3/_Thread/triage-the-log-incident-at-admin-loginci-e608 System.Net.Http.HttpRequestException: Response status code does not indicate success: 401 (PermissionDenied). at System.Net.Http.HttpResponseMessage.EnsureSuccessStatusCode() at MeshWeaver.AI.Anthropic.AnthropicChatClient.SendWithRetryAsync(ClaudeRequest request, HttpCompletionOption completionOption, CancellationToken cancellationToken) in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 546 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 117 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at System.Threading.Tasks.ValueTask`1.ValueTaskSourceAsTask.<>c.<.cctor>b__4_0(Object state) --- End of stack trace from previous location --- at MeshWeaver.AI.StreamStallGuardChatClient.Swallow(Task task) in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 221 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 188 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at MeshWeaver.AI.ProviderCallT…[truncated]Re-addressed by the current identity function: this incident inherited
4b96796426410a46(Systemorph/MeshWeaver.Plugins#1796). Those nodes are superseded and will not fold, file or comment again.- addedarea:aiCore subsystem: the AI engine and model providersCore subsystem: the AI engine and model providersfeature:provider-credentialsFeature: provider credentialsFeature: provider credentialssev:MMedium - secondary path broken, or easy workaroundMedium - secondary path broken, or easy workaround
on Sep 20, 2026 systemorph-com commented
on Sep 20, 2026 ContributorAuthorMore actionsStill occurring: 2 more since the last update (41 total).
- Last seen: 2026-09-20 21:55:32Z
- Pods:
memex-portal-deployment-65f8c68995-c7z8l,memex-portal-deployment-c96b8bff8-jx7bd,memex-portal-deployment-7969b8cfff-fqnk9,memex-portal-deployment-57b689f955-wrstj,memex-portal-deployment-7969b8cfff-gtmlb,memex-portal-deployment-57b689f955-h6d47,memex-portal-deployment-7cfbf545d9-gtlhr,memex-portal-deployment-58c7bb4b9d-z2xcv,memex-portal-deployment-86779d495b-ksxqq,memex-portal-deployment-5d4bfc98b7-ff447,memex-portal-deployment-54cc8d6b4d-cjnqn,memex-portal-deployment-66f4b5c9b6-mcm2z,memex-portal-deployment-77898c4947-6mffn,memex-portal-deployment-79ddd44d77-k8qlc,memex-portal-deployment-7bff7d8b54-5rrkx,memex-portal-deployment-84d966d9bd-nlv6z,memex-portal-deployment-7fd85c4468-gwghs,memex-portal-deployment-78c786fcf6-bs4fn,memex-portal-deployment-5f69f6b6bd-z7tb6,memex-portal-deployment-6b7c4f94db-zzvfq
Recent log lines
2026-09-20 07:25:32Z memex-portal-deployment-78c786fcf6-bs4fn fail: MeshWeaver.AI.AgentChatClient[0] [ThreadExec] ERROR: 07:25:32.088 threadPath=Admin/_LogIncident/69fc2c77c29dfcb3/_Thread/triage-the-log-incident-at-admin-loginci-e608 System.Net.Http.HttpRequestException: Response status code does not indicate success: 401 (PermissionDenied). at System.Net.Http.HttpResponseMessage.EnsureSuccessStatusCode() at MeshWeaver.AI.Anthropic.AnthropicChatClient.SendWithRetryAsync(ClaudeRequest request, HttpCompletionOption completionOption, CancellationToken cancellationToken) in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 546 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 117 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at System.Threading.Tasks.ValueTask`1.ValueTaskSourceAsTask.<>c.<.cctor>b__4_0(Object state) --- End of stack trace from previous location --- at MeshWeaver.AI.StreamStallGuardChatClient.Swallow(Task task) in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 221 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 188 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at MeshWeaver.AI.ProviderCallT…[truncated] 2026-09-20 07:27:26Z memex-portal-deployment-5f69f6b6bd-z7tb6 fail: MeshWeaver.AI.AgentChatClient[0] [ThreadExec] ERROR: 07:27:26.976 threadPath=Admin/_LogIncident/4bcb8bae7f327bc2/_Thread/triage-the-log-incident-at-admin-loginci-1983 System.Net.Http.HttpRequestException: Response status code does not indicate success: 401 (PermissionDenied). at System.Net.Http.HttpResponseMessage.EnsureSuccessStatusCode() at MeshWeaver.AI.Anthropic.AnthropicChatClient.SendWithRetryAsync(ClaudeRequest request, HttpCompletionOption completionOption, CancellationToken cancellationToken) in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 546 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 117 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at System.Threading.Tasks.ValueTask`1.ValueTaskSourceAsTask.<>c.<.cctor>b__4_0(Object state) --- End of stack trace from previous location --- at MeshWeaver.AI.StreamStallGuardChatClient.Swallow(Task task) in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 221 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 188 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at MeshWeaver.AI.ProviderCallT…[truncated] 2026-09-20 21:55:32Z memex-portal-deployment-6b7c4f94db-zzvfq fail: MeshWeaver.AI.AgentChatClient[0] [ThreadExec] ERROR: 21:55:32.837 threadPath=Admin/_LogIncident/03e5e31ad393af55/_Thread/triage-the-log-incident-at-admin-loginci-09b2 System.Net.Http.HttpRequestException: Response status code does not indicate success: 401 (PermissionDenied). at System.Net.Http.HttpResponseMessage.EnsureSuccessStatusCode() at MeshWeaver.AI.Anthropic.AnthropicChatClient.SendWithRetryAsync(ClaudeRequest request, HttpCompletionOption completionOption, CancellationToken cancellationToken) in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 546 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 117 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at System.Threading.Tasks.ValueTask`1.ValueTaskSourceAsTask.<>c.<.cctor>b__4_0(Object state) --- End of stack trace from previous location --- at MeshWeaver.AI.StreamStallGuardChatClient.Swallow(Task task) in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 221 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 188 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at MeshWeaver.AI.ProviderCallT…[truncated]Re-addressed by the current identity function: this incident inherited
4b96796426410a46(Systemorph/MeshWeaver.Plugins#1796). Those nodes are superseded and will not fold, file or comment again.systemorph-com commented
on Sep 21, 2026 ContributorAuthorMore actionsStill occurring: 1 more since the last update (42 total).
- Last seen: 2026-09-20 22:21:31Z
- Pods:
memex-portal-deployment-65f8c68995-c7z8l,memex-portal-deployment-c96b8bff8-jx7bd,memex-portal-deployment-7969b8cfff-fqnk9,memex-portal-deployment-57b689f955-wrstj,memex-portal-deployment-7969b8cfff-gtmlb,memex-portal-deployment-57b689f955-h6d47,memex-portal-deployment-7cfbf545d9-gtlhr,memex-portal-deployment-58c7bb4b9d-z2xcv,memex-portal-deployment-86779d495b-ksxqq,memex-portal-deployment-5d4bfc98b7-ff447,memex-portal-deployment-54cc8d6b4d-cjnqn,memex-portal-deployment-66f4b5c9b6-mcm2z,memex-portal-deployment-77898c4947-6mffn,memex-portal-deployment-79ddd44d77-k8qlc,memex-portal-deployment-7bff7d8b54-5rrkx,memex-portal-deployment-84d966d9bd-nlv6z,memex-portal-deployment-7fd85c4468-gwghs,memex-portal-deployment-78c786fcf6-bs4fn,memex-portal-deployment-5f69f6b6bd-z7tb6,memex-portal-deployment-6b7c4f94db-zzvfq,memex-portal-deployment-75b545bbd-gwrc6
Recent log lines
2026-09-20 07:27:26Z memex-portal-deployment-5f69f6b6bd-z7tb6 fail: MeshWeaver.AI.AgentChatClient[0] [ThreadExec] ERROR: 07:27:26.976 threadPath=Admin/_LogIncident/4bcb8bae7f327bc2/_Thread/triage-the-log-incident-at-admin-loginci-1983 System.Net.Http.HttpRequestException: Response status code does not indicate success: 401 (PermissionDenied). at System.Net.Http.HttpResponseMessage.EnsureSuccessStatusCode() at MeshWeaver.AI.Anthropic.AnthropicChatClient.SendWithRetryAsync(ClaudeRequest request, HttpCompletionOption completionOption, CancellationToken cancellationToken) in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 546 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 117 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at System.Threading.Tasks.ValueTask`1.ValueTaskSourceAsTask.<>c.<.cctor>b__4_0(Object state) --- End of stack trace from previous location --- at MeshWeaver.AI.StreamStallGuardChatClient.Swallow(Task task) in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 221 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 188 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at MeshWeaver.AI.ProviderCallT…[truncated] 2026-09-20 21:55:32Z memex-portal-deployment-6b7c4f94db-zzvfq fail: MeshWeaver.AI.AgentChatClient[0] [ThreadExec] ERROR: 21:55:32.837 threadPath=Admin/_LogIncident/03e5e31ad393af55/_Thread/triage-the-log-incident-at-admin-loginci-09b2 System.Net.Http.HttpRequestException: Response status code does not indicate success: 401 (PermissionDenied). at System.Net.Http.HttpResponseMessage.EnsureSuccessStatusCode() at MeshWeaver.AI.Anthropic.AnthropicChatClient.SendWithRetryAsync(ClaudeRequest request, HttpCompletionOption completionOption, CancellationToken cancellationToken) in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 546 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 117 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at System.Threading.Tasks.ValueTask`1.ValueTaskSourceAsTask.<>c.<.cctor>b__4_0(Object state) --- End of stack trace from previous location --- at MeshWeaver.AI.StreamStallGuardChatClient.Swallow(Task task) in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 221 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /home/runner/work/MeshWeaver/MeshWeaver/plugins-repo/src/MeshWeaver.AI/StreamStallGuardChatClient.cs:line 188 at MeshWeaver.AI.StreamStallGuardChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult() at MeshWeaver.AI.ProviderCallT…[truncated] 2026-09-20 22:21:31Z memex-portal-deployment-75b545bbd-gwrc6 fail: MeshWeaver.AI.AgentChatClient[0] [ThreadExec] ERROR: 22:21:31.384 threadPath=Admin/_LogIncident/55a9ce7bfc40ee71/_Thread/triage-the-log-incident-at-admin-loginci-fc0b System.Net.Http.HttpRequestException: Response status code does not indicate success: 401 (PermissionDenied). at System.Net.Http.HttpResponseMessage.EnsureSuccessStatusCode() at MeshWeaver.AI.Anthropic.AnthropicChatClient.SendWithRetryAsync(ClaudeRequest request, HttpCompletionOption completionOption, CancellationToken cancellationToken) in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 546 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+MoveNext() in /repo/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 117 at MeshWeaver.AI.Anthropic.AnthropicChatClient.GetStreamingResponseAsync(IEnumerable`1 messages, ChatOptions options, CancellationToken cancellationToken)+System.Threading.Tasks.Sources.IValueTaskSource<System.Boolean>.GetResult()Re-addressed by the current identity function: this incident inherited
4b96796426410a46(Systemorph/MeshWeaver.Plugins#1796). Those nodes are superseded and will not fold, file or comment again.Re-routed to
MeshWeaver.Plugins— and the title's premise does not survive measurement, but a real defect is underneath itWhere the subject is
AnthropicChatClient.SendWithRetryAsyncis inSystemorph/MeshWeaver.Pluginsat
src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs. This issue's own evidence table says so twice
and I should have been reading it: the stack frames carry the literal build path
/home/runner/work/MeshWeaver.Plugins/MeshWeaver.Plugins/src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs:line 545,
and the table'sRoutingrow already warns "the category names the LOGGER, which may not be the
subject". The categoryMeshWeaver.AI.AgentChatClientis the logger; the subject is the Anthropic
client, one repository over.Denominator searched (this repo at
origin/main— 1401.csundersrc/, 111 undermemex/,
1328 undertest/, 934 files undersamples/, 66 projects inMeshWeaver.slnx): zero declarations
and zero call sites forAnthropicChatClient,SendWithRetryAsyncorAgentChatClient— the only
hits anywhere are comments and XML-doc cross-references.src/MeshWeaver.AI*does not exist here;
MeshWeaver.slnxdeclares noMeshWeaver.AIproject. (In-mesh.cscompiles at runtime and is
invisible to a grep oversrc/— this is a claim about the compiled repositories only.)The retry premise is false
Measured on
MeshWeaver.Plugins@main,AnthropicChatClient.cs:533:var retryable = status is 500 or 502 or 503 or 429;
401 is not in that set. A 401 takes the
// Non-retryable, or the last attempt failed → surface the error (throws)branch straight toEnsureSuccessStatusCode()on the first attempt. So the
client already treats a rejected credential as the permanent verdict it is, and the title's "retries
and crashes" does not hold. I would flag the corollary as well: adding a retry here would be wrong
twice over — a band-aid, and a contradiction of what the status means.But there is a real defect, and it is the legibility half
A 401 is classified by nothing, so the user gets the raw SDK sentence. Enumerated exhaustively on
MeshWeaver.Plugins@main, because absence of one marker is not absence of the event — every path by
which a 401 could become legible, and why each does not fire:Path Covers 401? ProviderFailureClassifierpredicatesIsQuotaExhausted402,IsModelNotFound404,IsRateLimited429,IsProviderUnavailable5xxno predicate providerStatus switchinThreadExecutioncases 402,404,429,>= 500 and < 600, then_ => nullfalls to _ => nullAnthropicChatClientno AuthRequiredException/Unauthorized/PermissionDenied/401mapping anywhere in the fileno FindStreamFaultstream stalled / unrepresentable payload only no FindHarnessProcessFault/AuthRequiredExceptionCLI harnesses (Claude Code, Copilot) — see #4988 no, not an HTTP provider HasNoUsableModel/chat.noUsableModela credential that cannot be resolved locally no — this is a credential the provider rejects The only mention of
401anywhere inThreadExecution.cson main is a comment about the CLI-harness
path. SoproviderMessageisnull, and the cell's text becomesex.Messageverbatim:Response status code does not indicate success: 401 (PermissionDenied).Raw, English-only whatever the viewer's locale, naming no model and no remedy — which is precisely
the defect class #476 and #2233 exist to kill, still live for the one condition an operator is most
able to act on. 38 occurrences across 17 pods, most recent 2026-09-20, so it is not theoretical.The platform half is merged here; the engine half is yours
Core owns the localization catalog, so the platform string lands first (this is the inverted ordering
the engine already expects — it checksLocalizationCatalog.Keys.Contains(key)before resolving and
falls back to its own English, so a key can lead a branch but never the other way round):chat.modelCredentialRejected, en + de, in
src/MeshWeaver.Messaging.Hub/Localization/strings.{en,de}.json.{0}= the model that actually
served,{1}= the status. The prose deliberately says "Submitting again will not help until the
key is replaced" — a permanent verdict must not read as "submit again later".Doc/AI/ProviderConfigurationnow carries the full condition→key table (it had gone stale at 429
and 5xx and did not mention 402/404), this gap with its measurement, and the boundary rule: "keeps
its own message verbatim" is right for a fault carrying no transport status and wrong for one that
does.
The counterpart in
MeshWeaver.Pluginsis anIsCredentialRejectedpredicate (401) on
ProviderFailureClassifierplus a401 => LocalizationCatalog.Get("chat.modelCredentialRejected", …)
case in theproviderStatusswitch, keeping the provider's own text on theLogErroras the other
branches do.Disposition
Leaving open and re-routed: the remaining work is in
MeshWeaver.Plugins.What this does not establish. Only 401 is measured. I deliberately did not fold 403 in: it
means different things at different providers (permission, region, content policy) and a confidently
wrong name is worse for a reader than a generic one — but note 403 also currently falls to
_ => null, so it is unaddressed rather than handled. Whether to widen the default for other 4xx is a
wording decision (chat.modelProviderErrorinterpolates its status but ends in "Submit again later",
true of a 5xx and false of most 4xx), and I did not make it. I also did not identify which tenant
or provider config carries the rejected key — this issue's second question — and no credential value
was read; that half is operational.
Platform half merged in #5167 (this repository):
chat.modelCredentialRejected, en + de, plus the condition→key table inDoc/AI/ProviderConfigurationbrought current and this gap written up with its measurement. The engine-side counterpart is the remaining work and is inMeshWeaver.Plugins.Platform half MERGED — the engine-side counterpart is what remains
#5167 merged to
mainate68b5be8, and I verified the result rather than the tick: the key reads back
frommainin both catalogs (strings.en.jsonandstrings.de.json, one occurrence each).chat.modelCredentialRejected- en: "The language model '{0}' could not serve this round: the provider rejected the configured
credential (HTTP {1}). Replace the provider key in Settings → Language Models, or pick a model on
another provider. Submitting again will not help until the credential is replaced." - de: the same, using the terms the
chat.*siblings already use — Zugangsdaten for what the provider
rejected, Provider-Schlüssel for what has to be replaced.
{0}is the model that actually served,{1}the status. The closing sentence is deliberate: a rejected
credential is a permanent verdict, so the prose must not read as "submit again later", which is what
rules out folding it intochat.modelRateLimitedorchat.modelProviderError.Doc/AI/ProviderConfigurationwent in with it, and carries three things beyond this key: the full
condition→key table (it had gone stale at 429 and 5xx, with no mention of 402/404, the stream faults or
historyLoadFailed); the fact that the engine is inMeshWeaver.Pluginsso a search of core can neither
confirm nor refute anything about provider-failure handling; and the boundary rule — "keeps its own
message verbatim" is right for a fault carrying no transport status and wrong for one that does.What remains, and it is small
In
MeshWeaver.Plugins:ProviderFailureClassifier— anIsCredentialRejectedpredicate for 401, beside the existing
IsQuotaExhausted/IsModelNotFound/IsRateLimited/IsProviderUnavailable.ThreadExecution'sproviderStatusswitch — a401 =>arm resolving
chat.modelCredentialRejected, keeping the provider's own text on the precedingLogErrorexactly as
every other arm does.
The ordering was deliberately platform-first, and that direction is the safe one: the engine checks
LocalizationCatalog.Keys.Contains(key)before resolving and falls back to its own purpose-written
English, so a platform key can lead an engine branch but an engine branch cannot lead a platform key.
The key is now onmain, so the branch will resolve it as soon as the image carrying this commit is what
the portal runs.Filed into bug triage so the Plugins half gets an owner, since a comment on a core issue cannot
create work in another repository.Unchanged from my earlier comment, and worth keeping in view: the retry premise in this issue's title
does not survive readingSendWithRetryAsync:533(retryable = status is 500 or 502 or 503 or 429— 401
is already terminal), and adding a retry would be both a band-aid and a contradiction of what the status
means. 403 is deliberately still unaddressed rather than handled: it means different things at different
providers, and a confidently wrong name is worse for a reader than a generic one. I also did not identify
which tenant or provider configuration carries the rejected key — that half is operational, and no
credential value was read at any point.- en: "The language model '{0}' could not serve this round: the provider rejected the configured
Engine half opened — Systemorph/MeshWeaver.Plugins#2270
ProviderFailureClassifier.IsCredentialRejected(401) and a401 =>arm inThreadExecution'sproviderStatusswitch resolvingchat.modelCredentialRejected(the key #5167 landed here; the set the PR resolves already carriese68b5be8), the provider's own text staying on the precedingLogErroras every other arm does. 403 deliberately still unclassified.Two-sided control (
CredentialRejectedRoundTest, real mesh, a scripted provider throwing the production-shaped typedHttpRequestException { StatusCode = 401 }with the SDK's exact message): without the arm the cell read*Error: Response status code does not indicate success: 401 (PermissionDenied).*—Total: 1, Failed: 1; with it,Status = Error, the localized condition in cell and summary, neither SDK fragment present, threadIdlewith exactly one response cell —Failed: 0.The retry premise stays refuted, and is now pinned:
AnthropicRetryTestgained two cases (streaming and non-streaming) proving a 401 makes exactly ONE request and escapes as the typedUnauthorized— so a future "resilience" change that added 401 toretryablegoes red. A retry on a rejected secret would be the band-aid.Not established, unchanged from above: which tenant/provider configuration carries the rejected key. The react mirror's pin bump (
npm run sync:i18n -- --ref e68b5be8) is still owed as its own small PR.Stays open until the Plugins half is merged and verified on a rolled portal.
Closing as completed: both code halves are merged and test-verified, and the fault has not recurred for 3½ days while the watcher was folding other incidents.
- Platform half: i18n(chat): name a REJECTED provider credential instead of pasting the SDK's 401 banner #5167 (merged 2026-09-22T04:03Z) — catalog key
chat.modelCredentialRejectedin both languages. - Engine half: Systemorph/MeshWeaver.Plugins#2270 (merged 2026-09-22T11:26:01Z,
e4474cf2a5) —ProviderFailureClassifier.IsCredentialRejected(401) and a401 =>arm inThreadExecution, so a rejected credential ends the round with the localized condition instead of the SDK's banner.CredentialRejectedRoundTestwas red without the arm and green with it.AnthropicRetryTestnow pins that a 401 makes exactly ONE request, so the title's "retries" premise stays refuted and a later "resilience" change that adds 401 toretryablegoes red. The react mirror sync is Plugins#2271 (merged). - Recurrence: the last fold here is 2026-09-20 22:21:31Z (42 total). The same bot kept folding other fingerprints after that (e.g. Prebuilt bundle seeding leaf (ShippedPrebuiltBundles.SeedBundles) ignores cancellation token and stalls the silo I/O drain for its full budget #5223 on 2026-09-22 16:58Z and 17:48Z), so the silence is not a dead watcher.
Not established, and why it does not keep this open: which provider configuration carried the rejected key. Every sample thread was a log-triage thread (
Admin/_LogIncident/*/_Thread/triage-…), so it was the triage agent's model configuration on namespacememex. The engine'sLogErrorstill carries the provider's own text, so a rejected credential will fold here again — and the recurrence bot reopens this issue — if the key is still bad; the silence since 2026-09-20 22:21Z suggests it was replaced or the triage agent moved model, but I did not read the provider configuration. I also did not confirm which Plugins AI module version thememexportal runs.- Platform half: i18n(chat): name a REJECTED provider credential instead of pasting the SDK's 401 banner #5167 (merged 2026-09-22T04:03Z) — catalog key
What is failing
MeshWeaver.AI.Anthropic.AnthropicChatClient.SendWithRetryAsyncgets a 401 PermissionDenied from the Anthropic API and the streaming round for the agent thread faults with a rawHttpRequestException(viaEnsureSuccessStatusCode()). Affected threads include real user agent threads across several tenants, including log-triage agent threads (which effectively kills the triage agent mid-run).Probable cause
Moderate-to-high confidence: an invalid, expired, or missing Anthropic API key / credential for some tenant or model-provider configuration. A 401 PermissionDenied from the Anthropic endpoint is an authentication rejection, not a transient transport failure — yet the failure surfaces through
SendWithRetryAsync, which suggests the retry path treats (or at least logs) a non-retryable auth error like a generic request failure instead of failing fast with a clear "provider credentials rejected" error. Two defects to consider:SendWithRetryAsyncshould not retry (or should special-case) 401 responses; it should surface a typed, actionable auth error.Impact
38 occurrences over ~1 month across 17 pods — low volume, not an outage, but each occurrence kills an agent thread execution outright and is confusing to users (raw
HttpRequestExceptionwith no indication that a provider key is bad). At least four of the samples are log-triage agent threads, so the triage pipeline itself intermittently fails.Where to look
src/MeshWeaver.AI.Anthropic/AnthropicChatClient.cs—SendWithRetryAsync(theEnsureSuccessStatusCode()call, ~line 545/546) andGetStreamingResponseAsync(~line 116/117). Also review the model-provider credential resolution for the Anthropic provider to identify which tenant config produces the rejected key.Note on prior triage
This incident supersedes
Admin/_LogIncident/4b96796426410a46, which was previously suppressed as a one-off OpenRouter key smoke test. The full history (38 occurrences since 2026-08-21, 17 pods, real user threads) shows that assessment was based on a single sample and is not valid — this is a recurring fault, not routine noise.Evidence
72940baad6728a13MeshWeaver.AI.AgentChatClientSystem.Net.Http.HttpRequestExceptionMeshWeaver.AI.Anthropic.AnthropicChatClient.SendWithRetryAsync(ClaudeRequest request, HttpCompletionOption completionOption, CancellationToken cancellationToken)memexmemex-portal-deployment-65f8c68995-c7z8l,memex-portal-deployment-c96b8bff8-jx7bd,memex-portal-deployment-7969b8cfff-fqnk9,memex-portal-deployment-57b689f955-wrstj,memex-portal-deployment-7969b8cfff-gtmlb,memex-portal-deployment-57b689f955-h6d47,memex-portal-deployment-7cfbf545d9-gtlhr,memex-portal-deployment-58c7bb4b9d-z2xcv,memex-portal-deployment-86779d495b-ksxqq,memex-portal-deployment-5d4bfc98b7-ff447,memex-portal-deployment-54cc8d6b4d-cjnqn,memex-portal-deployment-66f4b5c9b6-mcm2z,memex-portal-deployment-77898c4947-6mffn,memex-portal-deployment-79ddd44d77-k8qlc,memex-portal-deployment-7bff7d8b54-5rrkx,memex-portal-deployment-84d966d9bd-nlv6z,memex-portal-deployment-7fd85c4468-gwghsMeshWeaver.AI.AgentChatClient. This repository is the configured fallback, not a finding about who owns the fault; the category names the LOGGER, which may not be the subject.Recent log lines
Re-addressed by the current identity function: this incident inherited
4b96796426410a46(Systemorph/MeshWeaver.Plugins#1796). Those nodes are superseded and will not fold, file or comment again.Opened automatically from
Admin/_LogIncident/72940baad6728a13. Recurrences are folded into this issue rather than opening new ones.