Skip to content

Available now

Troubleshooting ​

Credentials ​

SymptomCauseFix
The token request answers invalid_clientWrong client id or secret, a previous secret after its overlap, a revoked connection, or credentials for the other environmentCheck the token URL matches the environment; check the connection on Apps and credentials; rotate if the secret is lost
401 producer.unauthenticated with a fresh tokenSent to the other environment's API, or the header isn't Authorization: Bearer <token>Match the environments; check the header
401 after working fineThe token expired, or the secret was rotated: every earlier token stops within about 30 secondsGet a new token; refresh before expires_in runs out
403 producer.not_registeredThe connection was revoked, an identity-provider client isn't bound, or an AWS role isn't registered for this workspaceCheck Sign-in methods on the connection; connect the app again if it was revoked
403 principal.not_verifiedYour AWS role is registered but hasn't run the verify commandRun the command the portal shows, signed with the role; press New challenge if it expired
403 tenant.mismatch{t} in the URL isn't your connection's workspaceUse the tenant claim of your token
429 rate.limited or quota.exceededToo many requests, or a token fetched per message. Requests signed with an AWS role share one limit with every other AWS signerReuse tokens for their hour; back off, honouring Retry-After. See Limits
403 request.blockedThe bus's firewall refused the requestCheck what your client sends; ask RND if it's a normal message
403 {"message":"…"} on a signed routeThe request is unsigned, badly signed or signed with expired AWS credentials, or your own policy doesn't let the role call the APICheck the signing and your AWS credentials; allow Invoke on the bus API
403 {"message":"Missing Authentication Token"}A path the API doesn't have: check /v1/ and the routeCheck the URL

An app RND manages in the bus configuration gets its tokens from the token URL RND sent it, with scope sombus/publish; invalid_scope there means the scope is missing or misspelt.

Messages refused ​

SymptomCauseFix
400 envelope.format.uuid though your ids look like UUIDsBraces, a prefix, or a custom id formatThe plain form: 0199a1c4-7a2e-7b31-8c55-4d2f9e6a1b07
400 envelope.format.date-timeNo time zone, a space instead of T, or a local format2026-09-24T14:00:00Z
400 envelope.enum at /originating_system/system_typeYour tool's own type (playout, cms, mam…)A SOM value; custom if nothing fits
400 envelope.additionalProperties at /extensionsExtension keys not under com.<vendor>."com.acme.rundown_slot": 3
Many envelope.required and envelope.additionalProperties errors at onceYou sent a bare payload, not an envelopeWrap the payload in an envelope
Passes your validator, refused by the busFormat assertion off, another schema version, or the payload checked against the wrong schemaSee Validate in your own tests
409 sequence_number.not_increasing on your first messageThat story_id already exists in your workspace, from an earlier runA new story_id per run, with your prefix
409 sequence_number.not_increasing in the middle of a storyTwo writers, parallel sends for one story, or your product lost its counterOne writer; wait for each answer; store the sequence with the story
409 snapshot.members_missingYour product sends only what changedSend the whole story every time
409 message_id.reused on a retryYour retry rebuilt the message (a new timestamp) and kept the idKeep and resend the exact original
413 message.too_largeMedia, transcripts or long text in the messageReferences only

Every rule id: the rule catalogue.

Consuming ​

SymptomCauseFix
503 consumer.queue_unavailableThe connection's queue is still being set upWait until Consumer connections shows Ready; retry after Retry-After
403 producer.not_registered on the pull APIA producer's token, or a revoked or removed consumer connectionUse the consumer connection's own credentials; restore it if it was revoked
403 consumer.not_owner{c} in the URL isn't your connectionUse your client id as {c}
AccessDenied from SQSYour reader role is still Awaiting proof, was verified less than a few minutes ago, or your role's own policy lacks the SQS actions; or you called GetQueueUrl, which a reader role isn't grantedRun the verify command, wait for Verified, allow the four actions on both queue ARNs, and use the queue URL from the portal; see Consumer connections
Nothing arrivesNo matching message types, topic prefix or source; the message was refused at the gateway; or it was published before the connection was readyCheck the message on the portal's timeline; check the connection's filter, including its source
Other apps' messages arriveYour connection receives every matching message in the workspace, from every app in itNarrow the message types, use a topic prefix, or filter on your own correlation_ids
One story stops, the others flowA message of that story keeps failing in your handlerFix the handler. At the attempt limit it moves to your dead-letter queue
The same message twiceAt-least-once delivery, a replay or a redriveBe idempotent on message_id
An old snapshot after a newer oneA redrive or a replayKeep the highest sequence_number per story

Portal ​

SymptomCauseFix
Your story isn't on the Story timelineYou're looking at another workspace; nothing was accepted for it yet; it's older than 7 days; or the app is one RND manages in the bus configurationCheck the Workspace menu and Activity; for an app RND manages, ask RND
A refusal isn't on the story's timelineThe bus couldn't read a story id from it (not JSON, or the envelope failed)Look in Activity
The Playground accepts a message that publishing refuses with 403The Playground doesn't check your app's grantsDry-run on your workspace's validate route, or compare with the connection's grants
No invitation shows when you sign inIt expired after 14 days, or was sent to another addressAsk RND for a new one
Sign-in asks for a code you don't haveMulti-factor sign-in is required, and your authenticator is on another deviceAsk your RND contact to reset it: you can't use Ask RND until you're signed in

Still stuck ​

Ask RND, with the environment, the time window, message_ids and rule ids. Never secrets or real content.

SOM is an open standard maintained by the SOM working group. This service is not endorsed by it.