Skip to content

fix: quota denial message no longer tells the agent to retry - #144

Merged
vvillait88 merged 1 commit into
mainfrom
fix-quota-denial-message
Oct 3, 2026
Merged

vvillait88 merged 1 commit into
mainfrom
fix-quota-denial-message

Conversation

@vvillait88

Copy link
Copy Markdown
Contributor

Summary

When /v1/assess returns 429 quota_exceeded and failOpen / fail_open is off, the gate denies with api_error and the quota-specific contact_merchant instructions ("Do not retry: the same 503 will be returned until the merchant resolves the issue"). The reason carried no message, so the body fell back to the api_error default, "AgentScore is unreachable. This is transient: retry in a few seconds." An agent reading both got two opposite instructions in one response.

The quota denial now carries its own message, QUOTA_EXCEEDED_MESSAGE: "AgentScore identity verification is unavailable for this merchant. Retrying will not help." Every place that builds the quota denial sets it (the typed and the untyped 429 paths). Found in a docs audit while checking the errors reference against the SDK's emitted bodies.

Type of change

  • Bug fix (no breaking change)
  • New feature (no breaking change)
  • Breaking change (existing callers must update)
  • Docs, tests, or internal maintenance only

Public API

Adds the exported constant QUOTA_EXCEEDED_MESSAGE beside QUOTA_EXCEEDED_INSTRUCTIONS. The 503 body's error.message on the quota path changes text; its shape and status do not. No release is cut for this alone; the next release carries it.

Test plan

The quota tests now assert the message. Positive control: with the message removed from the deny sites, those tests fail; restored, they pass. Full lint, type check and test suite pass locally.

Checklist

  • Tests cover the new behavior, and the suite passes locally
  • Lint, format, and type checks pass
  • Docs and README examples updated if the public surface changed (no README text covers this message)
  • No secrets, credentials, or personal data in the diff or the tests

@vvillait88
vvillait88 merged commit dbf8713 into main Oct 3, 2026
6 checks passed
@vvillait88
vvillait88 deleted the fix-quota-denial-message branch October 3, 2026 22:55
@vvillait88 vvillait88 mentioned this pull request Oct 4, 2026
5 of 8 tasks
vvillait88 added a commit that referenced this pull request Oct 4, 2026
## Summary

Releases 3.0.1, carrying everything merged since 3.0.0:

- the quota denial message no longer tells an agent to retry; both quota
deny sites in `core.ts` now say verification is unavailable for this
merchant and that retrying will not help (#144)
- A2A signing and transport docs and supported versions corrected (#143)
- README: the UCP example imports the payment-handler builders it uses
(#145), and UCP profile `keys[]` is informational (#142)

Also in this PR: `@agent-score/sdk` floor raised to 2.8.1, released
today.

Worked with: Varun.

Out of scope: nothing else is pending on main.

## Type of change

- [x] Bug fix (no breaking change)
- [ ] New feature (no breaking change)
- [ ] Breaking change (existing callers must update)
- [ ] Docs, tests, or internal maintenance only

## Public API

none. The denial reason code and response shape are unchanged; only the
message text differs.

## Test plan

`bun run lint`, `typecheck`, `test` (1849 passed, 4 skipped) and `build`
pass locally on this branch.

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
- [x] No secrets, credentials, or personal data in the diff or the tests
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant