Error codes

Reference · policy gate

Every denial, in plain language.

When the Aarmos gate refuses a tool call, the receipt carries asource code identifying the exact rule that fired. Each page below explains what the code means, the common causes, and how to fix it — offline, on-device.

Looking for process exit codes?

The codes above describe policy denials inside a receipt. When the runtime itself refuses to start — an unavailable port, a read-only workspace, evidence it could not durably commit — it exits with a declared code instead. See exit codes in the CLI reference.