code and param in your code; message is for humans and may change.
The envelope uses
type: "server_error" for 5xx and type: "invalid_request_error" for client errors. param can identify an invalid request field; do not parse English messages as stable machine codes. Framework-level errors are normalized to the same envelope but may use generic codes. Other HTTP failures can occur; inspect the actual status and body. Do not automatically retry a validation error. For uncertain mutation outcomes, use an Idempotency-Key (one nonempty value, at most 512 bytes) and retry with the same request; the server supports idempotency on mutations, including session event submission. A mismatched replay can conflict.
An established SSE stream can carry an error event instead of a new HTTP error response. Observe terminal session/turn events and retrieve the turn if you need a durable outcome. Interrupted turns are marked failed rather than replaying external actions on restart; sending new input creates a subsequent turn.
Turn errors
A turn that fails carrieserror.code and error.message, and, when credit ran out, error.param naming whose:
Nothing switches who pays on its own. A message refused at admission for lack of credit is HTTP 429
insufficient_quota: “Out of Orca credit: add credit, then continue the session”. See when credit runs low.