How to use this list
Every code below is quoted exactly as this module raises it — lower-case, underscored, never translated. There are 177 of them, covering every named fault and every explicitly-declared non-fault outcome across the eleven classes that make up this module's failure vocabulary. Paste a code into your browser's find-on-page to land on it, then read the family article named after it for what it means and what to do. If you arrived here from a support ticket or a log line and only have the code, this is the page to search.
Two unrelated classes each independently name a code unreachable — one for the IDrive e2 reseller API (no connection at all), one for the S3 storage gateway (no HTTP response at all). They mean the same kind of thing but about two different endpoints, and both are listed below under their own class so the one you are looking at is unambiguous.
Updating — Update\UpdateError (59 codes) — see "Update and manifest faults"
manifest_unreachable— the update manifest could not be fetched at all; nothing was started.manifest_schema_unknown— the manifest uses a newer format than this build reads.manifest_malformed— the manifest document is damaged or not JSON.manifest_signature_invalid— the manifest's signature does not verify. Do not install.manifest_key_unknown— the manifest is signed with a key this build does not hold.manifest_signature_missing— no detached signature was presented for the manifest. Do not install.manifest_signature_error— the signature could not be checked at all (this build's own key material, not tampering).manifest_field_missing— a required manifest field is absent.artifact_no_match_for_runtime— no published build covers this installation's PHP version.artifact_slot_set_refused— the published build's encoder slot set is not one this module accepts.artifact_sha_disagreement— the manifest disagrees with itself about a file's checksum — a tampering tell. Do not install or re-fetch.loader_too_old— the installed ionCube loader is older than this update requires.loader_version_unknown— this install's ionCube loader version could not be read at all.whmcs_too_old— this billing system is older than this update requires.whmcs_above_maximum— this billing system is newer than this release declares support for.php_above_maximum— this PHP runtime is newer than the published build supports.php_below_minimum— this PHP runtime is older than the published build supports.entry_traversal— an archive member escapes its destination via... Nothing extracted.entry_absolute— an archive member has an absolute path. Nothing extracted.entry_nul_byte— an archive member's name carries a NUL byte. Nothing extracted.entry_symlink— the archive contains a symbolic link. Nothing extracted.entry_not_relative— a member name is absolute in a form this platform does not recognise. Nothing extracted.entry_not_in_module_tree— a member sits outside this product's own two module directories. Nothing extracted.archive_unreadable— the downloaded archive could not be opened at all.archive_unjudgeable— this server's zip library could not judge every member. Nothing extracted; retrying will not help.archive_extract_incomplete— every member passed and the unpacking still did not match. Everything written was removed.download_scheme_refused— the update address is not HTTPS, so nothing was requested.download_redirect_refused— the download redirected somewhere this module will not follow.download_size_exceeded— the download passed its declared maximum size and was abandoned.download_sha_mismatch— the downloaded file does not match the manifest's published checksum.download_http_status— the download answered with a status that carries no file.download_write_failed— the download arrived fine but could not be written to this server's disk.download_transport_failed— no usable answer arrived at all — a network path problem.probe_token_invalid— the decode probe's token was rejected. Nothing was swapped.probe_token_expired— the decode probe's token expired before the check completed. Nothing was swapped.probe_token_reused— a probe token was presented twice. Nothing was swapped.probe_path_outside_staging— the probe was asked about a path outside the staging directory and refused.probe_unreachable— the staged build could not be proven loadable because the probe could not be reached.probe_http_status— the probe answered with a status that is not a probe result.probe_sentinel_mismatch— the new build would not load on this PHP version. Nothing was swapped.swap_cross_device— staging and the live module directory are on different filesystems, so the swap cannot be atomic.swap_staging_incomplete— the staged update is missing files. Nothing was moved.swap_ownership_wrong— the staged files are owned by the wrong user. Nothing was moved.swap_rollback_failed— the update failed AND the rollback failed. Act now — see the family article.swap_live_foreign— something this module did not put there already occupies its own directory. Nothing moved or deleted.swap_rename_failed— a step of the install did not take; everything already moved was moved back.swap_aside_unavailable— there is nowhere outside the web root to keep the previous version.swap_aside_inside_docroot— the previous-version directory is inside the web root and unguarded.update_already_running— another administrator is updating this module right now.update_lock_stale— a lock file older than an update takes is sitting on this install.update_requires_admin— updates can only be started by a signed-in administrator.probe_unavailable— this build has no decode probe at all, so it refuses to install anything.update_not_needed— this installation already runs the published version.update_post_swap_check_failed— the new release installed, did not prove loadable, and was put straight back.update_stage_fault— a step of the update raised a fault this module has no name for.update_lock_unwritable— the update lock file could not be created.storage_path_relative— the configured update storage path is relative; it must be absolute.storage_inside_docroot_unguarded— the update storage directory is inside the web root with nothing preventing it being served.storage_reachable_over_http— proven, not guessed: the update storage directory was just fetched over HTTP.
Licensing and activation — Licence\LicenceError (13 codes) — see "Licensing and activation faults"
licence_unreachable— nothing wrong with the licence; it was never assessed (network path problem).licence_invalid— the licence server does not recognise this key.licence_expired— the licence term has ended.licence_suspended— the vendor has suspended this licence.licence_domain_mismatch— the licence is registered to a different domain than this install resolved.licence_response_unrecognised— something other than the licence server answered.licence_integrity_failed— the answer's integrity check failed — treat as a security event.licence_integrity_unverifiable— no shared secret is configured, so the answer's integrity could not be checked.licence_check_deferred— not a failure: the re-check floor has not elapsed, so the last verdict is shown.licence_key_missing— no licence key is stored for this module.identity_domain_unresolved— this install could not work out its own domain, so no check was attempted.identity_dir_unresolved— this install could not work out its own directory.identity_ip_unresolved— this install could not work out its own network address (not fatal).
Provisioning and lifecycle — Lifecycle\LifecycleError (22 codes) — see "Provisioning and lifecycle faults"
claim_in_flight— another provisioning pass for this service is already open.orphan_key_unrecognisable— a stray management key at the vendor does not match this module's stored one.convergence_read_failed— could not read what already exists at the vendor, so nothing was changed.probe_indeterminate_create— could not confirm the storage account was created; the service was NOT marked Active.probe_indeterminate_suspend— could not confirm the suspend took effect; the customer may still have access.probe_indeterminate_unsuspend— could not confirm access was restored; the customer may still be locked out.probe_indeterminate_terminate— could not confirm the account was shut off; nothing was destroyed.probe_still_reachable— the gateway answered during a suspend — the opposite of what was needed.probe_not_reachable— the gateway refused during an unsuspend — the opposite of what was needed.probe_gateway_error— the gateway reported its own fault, with a request id. Not a suspension.server_entry_not_found— this service points at a server entry that no longer exists.server_entry_wrong_type— the server entry belongs to a different provisioning module.service_not_found— no storage account record exists for this service.owner_unresolvable— could not tell which service or addon a call is about.retention_unset— no purge retention is configured; an unset retention means never purge.purge_not_due— the retention period on this terminated account has not elapsed yet.purge_owner_changed— the billing record's owner changed between termination and clean-up.purge_state_not_scheduled— this account is not marked as scheduled for clean-up.purge_server_unresolved— the clean-up could not resolve the server entry (no credential).remove_reported_success_but_user_present— the vendor said "removed" and a re-read still shows the account.remove_unconfirmed_within_window— a removal was sent and never confirmed gone across the entire confirmation window.new_provisioning_refused— new provisioning is refused because the cached licence verdict is Invalid; existing customers are unaffected.
Storage account state — State\StateError (19 codes) — see "Storage account state faults"
seal_empty_secret— internal guard, not actionable: refused to seal an empty secret.seal_failed— the billing system could not encrypt the storage secret.no_sealed_secret— no sealed management secret is stored for this region.decrypt_empty_on_nonempty_ciphertext— this billing system's encryption key was likely rotated or restored.decrypt_fingerprint_mismatch— the stored secret decrypted to something other than what was sealed.owner_model_missing— WHMCS did not say which service or addon a call is about.owner_model_unknown— internal fault, not actionable: WHMCS described the owner in a shape this module does not recognise.owner_addon_id_missing— internal fault, not actionable: an addon call arrived with no addon id.owner_shape_contradiction— internal fault, not actionable (cannot fire today by design): a call was described as both a standalone service and an addon.addon_server_context_missing— this storage addon has no server entry attached, so no credential reaches it — not a bad token.addon_quantity_unsupported— this addon was ordered with quantity above one; one addon row can only ever be one storage account.schema_missing— this module's own database tables do not exist.schema_create_failed— this module's database tables could not be created.migration_not_callable— one of this module's database update files is malformed.binding_not_found— no storage account is recorded for this service.region_row_not_found— this storage account holds nothing for that region.duplicate_binding— internal fault, not actionable: more than one storage account row claims this service.mirror_field_not_admin_only— the custom field this module writes to is customer-visible.mirror_write_failed— informational, no fix needed: the admin view's custom fields are stale; the storage account itself is unaffected.
S3 gateway, bucket and object faults — S3\S3Fault, S3\ObjectKeyError, S3\ObjectLockError (31 codes) — see "S3 gateway, bucket and object faults"
The eighteen gateway faults and three non-fault outcomes (S3\S3Fault):
gateway_not_reached— something other than the object gateway answered (edge, console or a followed redirect).sdk_absent— the bundled AWS SDK was not found on this server.unreachable— (storage gateway) no HTTP response arrived at all.gateway_error— the gateway reported its own fault, with a request id. Also this class's explicit catch-all.account_suspended— the customer's storage account is suspended (answers as a maintenance page).not_offered— this operation is permanently unavailable on this platform.wrong_region_for_key— the key does not exist at this gateway at all — almost always the wrong region.access_denied— the key is known here and the operation was refused.no_such_bucket— no bucket by that name exists.bucket_not_empty— a bucket delete was refused; the measured cause is an active Object Lock retention, not emptiness.lock_not_available_after_create— Object Lock cannot be added to an existing bucket; the bucket is not missing.retained_until— a version is held by a live Object Lock retention until a date. No override exists.bypass_refused— a retention bypass was refused. No override exists on this platform.delete_not_effective— a delete reported success but a re-listing still shows the content.bucket_name_refused— this module refused the bucket name before sending anything, stricter than the gateway.budget_exhausted— a bounded operation hit its limit and stopped — incomplete, not broken.credential_missing— no access key is held for the region this operation needs.upload_corrupted— the gateway's checksum did not match; the object was not stored. Not a platform fault.partial_delete— not a fault: a batch delete succeeded overall and refused some keys individually.cors_not_configured— not a fault: the normal state of a fresh bucket with no CORS rules.versioning_not_configured— not a fault: the normal read-back of a bucket created without versioning.
Object key and folder-path refusals, made before any request is sent (S3\ObjectKeyError):
prefix_absolute— a folder path began with a separator; it must be relative.prefix_traversal— a folder path contained a ".." segment.prefix_control_character— a folder path contained a control character.prefix_too_long— the folder path is longer than object storage allows for a key.prefix_empty— the folder name was empty.key_empty— no object name was given.
Object Lock acknowledgement guards, internal and not actionable (S3\ObjectLockError):
acknowledgement_unattributed— the acknowledging WHMCS client id was absent or not positive. No bucket was created.acknowledgement_no_fingerprint— the disclosure-wording fingerprint was empty. No bucket was created.acknowledgement_no_bucket— the acknowledgement named no bucket. No bucket was created.acknowledgement_bad_time— the acknowledgement time was not a valid UTC ISO-8601 instant. No bucket was created.
Reseller vendor API — Api\ResellerFault (10 codes) — see "Reseller vendor API faults"
auth— the reseller API refused the credential.rate_limited— the credential is fine; the 40-per-60-second request budget is spent.not_found— the reseller account does not hold that user. Expected for a convergence read.precondition— the vendor refused because the account is already in some state.invalid_params— this module sent a parameter the vendor rejected — a bug here, not an operator mistake.vendor_error— the reseller API reported its own fault, in its own words.bad_response— something that is not the reseller API answered, or the body is not what was asked for.unreachable— (reseller API) no connection was established at all; the request never left.timeout— a connection was made and no answer arrived in time; the request may have been acted on.stats_not_cached— the vendor has not computed statistics for that bucket yet. The bucket is not missing.
Configuration — Config\ConfigurationError (15 codes) — see "Configuration faults"
token_missing— the reseller API token (Password field) is empty.padded_token— the token has leading or trailing whitespace.token_malformed— the token is present but is not shaped like a token at all.credential_is_a_mask— the Password field holds WHMCS's own password mask, not a credential; the real value is gone.access_hash_is_a_mask— the Access Hash field holds WHMCS's own mask, not an override.whitelabel_domain_missing— the Username field (the brand's white-label domain) is empty.whitelabel_domain_invalid— the white-label domain is not a valid hostname.secret_in_plaintext_field— a credential-shaped value sits in the plaintext Access Hash field.api_base_invalid— the Hostname field does not yield a usable reseller API base.region_code_invalid— a region code is not a usable DNS label.credential_missing_for_region— no access key exists for that region.region_option_missing— this product declares no storage region for the customer to choose.tier_option_missing— this product declares no storage tier for the customer to choose.region_source_unresolved— the region for this order could not be resolved from this owner's one source.addon_path_not_offered— storage is sold as a standalone product in this version; a product addon is refused by design.
Operator alerts — Log\OperatorAlertError (8 codes) — see "Operator alert faults"
All eight are internal consistency guards, not actionable by an operator. See the family article.
alert_owner_unidentified— an alert was about to be written naming no identifiable service.alert_server_unidentified— an alert about a server entry named no entry.alert_name_empty— an alert carried no name for the thing that happened.alert_detail_empty— a divergence alert carried no detail sentence.alert_count_negative— an alert was given a negative count.alert_time_empty— an alert carried no timestamp.alert_limits_empty— a reconciler report stated no checks it could not make.alert_limit_name_invalid— a reconciler report's stated-limit list held something that is not a name.