Skip to content

Gaps — GW2 auth-failure status (spec 016's claim is wrong) ​

Raw observation recorded where it was noticed and deliberately left unprocessed. Nothing here is a proposal, a decision, or a plan, and 016's merged artifacts are not rewritten — a finding about a prior spec belongs here, as a record, not as a retroactive edit to that spec.


From spec 018 — holdings & prices (2026-08-16) ​

Found by live-probing the GW2 API while resolving 018's [NEEDS VERIFICATION: V1]. research.md F1.

016 documented "bad key → 403"; live GW2 returns 401 ​

Spec 016's spec.md (R2/SC1) and research.md (V2, and its graduation notes) state that GW2 returns 403 for a rejected key, with "no documented 401, no error-body shape," and that the mapping must switch "on status, not body."

Live probing on 2026-08-16 shows the opposite. A malformed key (deadbeef-0000) and a well-formed-but-fake GUID key, on /v2/account, /v2/account/materials, and /v2/account/wallet, each returned:

HTTP 401
{ "text": "Invalid access token" }

A missing Authorization header returned the same 401. So a rejected key is 401 with a JSON body, not a body-less 403.

Case016 documentedLive 2026-08-16
Invalid / expired key403, no body401 { "text": "Invalid access token" }
Missing scope403 (indistinguishable)403 { "text": "requires scope <name>" } (documented)
Distinguishable?noyes — by status

What this means, stated without deciding anything ​

016's code is unaffected: Gw2Client.account() maps both 401 and 403 to Gw2UnauthorizedError, so a bad key still becomes a browser-facing 401 whichever status GW2 sends. Only 016's documented rationale — "GW2 returns 403, no body, map on status not body" — is wrong.

The corrected fact is now graduated to docs/architecture/gw2-api.md (Authentication & scoped reads): invalid key → 401, missing scope → 403, the two distinguishable by status. Spec 018 relied on that distinction for its 401/403 split, which is why the discrepancy surfaced. 016's own spec.md and research.md are left as-merged — this record is the correction, not an edit to history.