Gaps — GW2 auth-failure status (spec 016's claim is wrong)
Raw observation recorded where it was noticed and deliberately left unprocessed. Nothing here is a proposal, a decision, or a plan, and 016's merged artifacts are not rewritten — a finding about a prior spec belongs here, as a record, not as a retroactive edit to that spec.
From spec 018 — holdings & prices (2026-08-16)
Found by live-probing the GW2 API while resolving 018's [NEEDS VERIFICATION: V1]. research.md F1.
016 documented "bad key → 403"; live GW2 returns 401
Spec 016's spec.md (R2/SC1) and research.md (V2, and its graduation notes) state that GW2 returns 403 for a rejected key, with "no documented 401, no error-body shape," and that the mapping must switch "on status, not body."
Live probing on 2026-08-16 shows the opposite. A malformed key (deadbeef-0000) and a well-formed-but-fake GUID key, on /v2/account, /v2/account/materials, and /v2/account/wallet, each returned:
HTTP 401
{ "text": "Invalid access token" }A missing Authorization header returned the same 401. So a rejected key is 401 with a JSON body, not a body-less 403.
| Case | 016 documented | Live 2026-08-16 |
|---|---|---|
| Invalid / expired key | 403, no body | 401 { "text": "Invalid access token" } |
| Missing scope | 403 (indistinguishable) | 403 { "text": "requires scope <name>" } (documented) |
| Distinguishable? | no | yes — by status |
What this means, stated without deciding anything
016's code is unaffected: Gw2Client.account() maps both 401 and 403 to Gw2UnauthorizedError, so a bad key still becomes a browser-facing 401 whichever status GW2 sends. Only 016's documented rationale — "GW2 returns 403, no body, map on status not body" — is wrong.
The corrected fact is now graduated to docs/architecture/gw2-api.md (Authentication & scoped reads): invalid key → 401, missing scope → 403, the two distinguishable by status. Spec 018 relied on that distinction for its 401/403 split, which is why the discrepancy surfaced. 016's own spec.md and research.md are left as-merged — this record is the correction, not an edit to history.