Skip to main content
Usage, Limits & Troubleshooting

Error & Support Code Reference

StackJack surfaces errors in three distinct places, each with its own format. This page maps all three and provides the full reference for the portal's SJ- support codes — the codes you'll see on…

Written By Christopher Scaminaci

Last updated About 22 hours ago

StackJack surfaces errors in three distinct places, each with its own format. This page maps all three and provides the full reference for the portal's SJ- support codes — the codes you'll see on portal error screens and are asked to quote to support.

The three error surfaces

Where you areWhat an error looks likeReference
Signing in / using the portalA titled message card with a support code like SJ-ACCESS-REVOKED and a Contact Support buttonThis page
Your AI tool connecting to StackJackAn HTTP 401/403 with a short JSON body, before any tool worksTool Errors and Troubleshooting
A tool call made by your AIA structured JSON envelope with an errorType (like rate_limited or monthly_limit_exceeded) and a correlationIdTool Errors and Troubleshooting

Two identifiers matter when contacting support:

  • Support codes (SJ-…) appear on portal error screens. The Contact Support button on those screens prefills an email to support@stackjack.io with the code, your workspace, your user, and the page — use it, and everything support needs is already included.
  • correlationId appears in tool-call error envelopes inside your AI conversation. It pinpoints the exact request in StackJack's telemetry; quote it verbatim.

Portal access states

Shown when you can sign in but can't (fully) use the portal. These are states, not faults — each has a specific resolver, usually your workspace administrator.

CodeWhat it meansWhat to do
SJ-ACCESS-AWAITING-APPROVALYour identity is recognized, but an administrator hasn't approved your portal access yet.Ask your administrator to approve you on the Team page.
SJ-ACCESS-NO-TOOLSYou're approved, but no tools have been assigned to you yet.Ask your administrator to assign your tools.
SJ-ACCESS-REVOKEDYour access to this workspace is no longer active.Ask your administrator to re-enable or re-invite you.
SJ-ACCESS-INVITE-ENDEDYour invitation to the organization named on the screen expired before you first signed in, or was withdrawn.Ask an owner or administrator of that organization to invite you again.
SJ-ACCESS-NO-TENANTYour identity couldn't be matched to any StackJack workspace.Try signing in again; contact support with the code if it persists.

See Approving New Members for the admin side of these states.

Sign-in errors

Shown on the dedicated sign-in error page when authentication itself fails.

CodeWhat it meansWhat to do
SJ-AUTH-LOGIN-EXPIREDThe sign-in attempt was left unfinished beyond its allowed lifetime.Start a fresh sign-in. This is usually an expired login tab, not an account problem.
SJ-AUTH-LOGIN-STATE-LOSTThe callback did not contain the browser data needed to match it to the sign-in attempt.Start fresh instead of reusing an old link or bookmark. If it repeats, allow cookies for the site (including in private-browsing mode) or try another browser.
SJ-AUTH-OIDC-REMOTE-FAILUREThe identity provider couldn't complete your sign-in.Try again; contact support with the code if it continues.
SJ-AUTH-GENERICSign-in failed for an unclassified reason.Try again; contact support with the code if it continues.

Connector authorization errors

Shown when a connector's browser-based authorization flow (for example, signing in to HaloPSA or NinjaOne to connect it) doesn't complete.

Access and eligibility:

CodeWhat it meansWhat to do
SJ-MEMBER-NOT-AUTHENTICATEDYou weren't signed in to StackJack when starting the flow.Sign in, then retry.
SJ-MEMBER-NOT-A-MEMBERYour identity isn't approved for this workspace's member connector flow.Ask your administrator to invite or approve you.
SJ-MEMBER-ACCESS-REVOKEDYour workspace access was revoked.Ask your administrator to restore it.
SJ-MEMBER-CONNECTOR-NOT-ASSIGNEDYou have no tools assigned for this connector.Ask your administrator to assign the connector's tools to you.
SJ-MEMBER-TENANT-NOT-FOUNDYour workspace couldn't be resolved for this flow.Sign in again; contact support with the code if it persists.
SJ-OWNER-IDENTITY-CHANGEDYour sign-in identity doesn't match the identity on record for this account — usually because the identity provider re-created your login (a new underlying user id for the same email).Do not create a new account, and don't just sign in again (that won't fix it). Contact support with the code below so an operator can relink your identity to this workspace (identity repair).
SJ-OWNER-ACCESS-REQUIREDThis particular setup flow is owner-only.Use the member connector flow, or ask the workspace owner to configure it.
SJ-OAUTH-NOSUBThe connector needs an active subscription before it can be authorized.Activate the connector subscription first.
SJ-OAUTH-INACTIVEThe connector subscription isn't currently active.Reactivate it or contact your administrator.

About SJ-MEMBER-TENANT-NOT-FOUND. This usually clears on a fresh sign-in — a recent role or ownership change (for example, being made a co-owner) now resolves automatically. If it keeps appearing after you sign in again, your identity may need a one-time link repair: contact support with the code (or ask your workspace administrator), and it can be fixed.

Flow and session problems (usually fixed by simply restarting the authorization):

CodeWhat it means
SJ-OAUTH-EXPIRED-STATEThe authorization session expired before completing.
SJ-OAUTH-INVALID-STATEThe session state couldn't be verified — often a stale link or interrupted session.
SJ-OAUTH-MISSING-PARAMSThe provider's response was incomplete.

Provider-side problems:

CodeWhat it meansWhat to do
SJ-OAUTH-TOKEN-EXCHANGE-FAILEDThe provider errored while exchanging the authorization code.Retry; contact support with the code if it repeats.
SJ-OAUTH-MISSING-REFRESH-TOKENThe provider accepted the sign-in but returned no refresh token, so the session couldn't be made durable.Enable offline_access (or the provider's equivalent persistent-token scope) on the API application, then retry. The error screen gives provider-specific steps for HaloPSA and NinjaOne.
SJ-OAUTH-CONNECTOR-DENIEDThe authorization was denied before completing.Retry and approve the requested access.
SJ-OAUTH-UNAUTHORIZEDThe provider rejected the request — credentials revoked or the API application is misconfigured.Verify the provider-side API application settings and retry.
SJ-OAUTH-UNSUPPORTED-CONNECTORThis connector doesn't support the requested flow.Use the connector's supported setup method.
SJ-OAUTH-INVALID-CONNECTORThe flow referenced an invalid connector type.Restart from the portal; contact support if it repeats.
SJ-OAUTH-UPSTREAMThe provider returned its own error, shown on screen.Retry; contact support with the code if it keeps failing.
SJ-OAUTH-GENERICThe flow failed for an unclassified reason.Retry; contact support with the code if it keeps failing.

Feature-gate errors in your AI tool

feature_disabled means a feature is switched off for your workspace. Two different features produce it, and the fix is different for each — read which tool the error names.

From an automation tool (stackjack_run_agent, stackjack_list_agents, stackjack_get_agent_run, stackjack_get_run_transcript), the message says Agentic Orchestration is not enabled for this tenant.

Automations are on by default for a workspace. Seeing this error means Automations were turned off for your workspace. It is not a feature you have to request before you can start. Contact support@stackjack.io to have them turned back on. See Enabling Automations.

From a catalog tool (the compact and minimal catalog tools), the message says catalog mode tools are not enabled. That one is self-serve: an admin enables catalog modes for the organization on the Settings page. See Catalog modes.

Automation runs and credits

Two credit behaviors are worth knowing before you read a run failure:

  • A positive balance is not enough on its own. Before a run starts, StackJack reserves the credits that run could need. If the balance does not cover the whole reservation, the run is refused with a message naming the amount needed and the balance available. A balance above zero but below the reservation still refuses.
  • A run refused for credits does not resume when you top up. It is finished, in the CreditExhausted state, and adding credits does not restart it. Add the credits, then start the run again.

Both are specific to credit-funded runs. A workspace running on its own Anthropic key behaves differently — see Agent Runner plans.

Other code families you may encounter

Automation-related surfaces use additional SJ- prefixed codes (for example SJ-WIZ-… from the automation wizard and SJ-AGENT-… on automation pages, documented in the Automations section), and support-side processes have their own internal codes. The rule is universal: any code starting with SJ- is safe to share and exactly what support wants to see — it carries no secrets and identifies the precise failure path.