Skip to content

Refusal codes

The stable code a continuable refusal carries and the grant that lifts it: consumers match by identity, not message.

The package refuses before it acts when a request is well formed but not yet allowed; a continuable refusal carries a stable code so a consumer can offer the operator the grant that lifts it. After this page you match a refusal by identity, not by parsing its message, and know which variable each grant sets.

from strands_robots.refusal_codes import REFUSAL_CODES, REFUSAL_GRANTS

for code in REFUSAL_CODES:
    print(f"{code:28} lifted by {REFUSAL_GRANTS[code]}")

Only continuable refusals get a code; one nothing can lift (an instruction over the length limit, an unknown joint name) stays a plain error naming the valid set. A coded refusal's message may change between releases; its code and subject attribute do not.

Three grants are allowlists the refusal's subject is appended to (HF_REPO_NOT_ALLOWED, POLICY_TYPE_NOT_ALLOWED, POLICY_HOST_NOT_ALLOWED). The other two are not: STRANDS_TRUST_REMOTE_CODE takes 1, STRANDS_MESH_INPUT_VALUE_ABS a bound above the refused magnitude; a subject applied to those is a silent no-op, so read the meaning column before wiring a consent flow.

5 codes in REFUSAL_CODES. A refusal carries exc.code and exc.subject; the grant column is the environment variable in REFUSAL_GRANTS that lifts it.

code meaning grant raised in
TRUST_REMOTE_CODE_REQUIRED A HuggingFace-backed policy provider would execute code from a model repository. Subject: the provider name. Grant: set the variable to 1; the subject is not the value. STRANDS_TRUST_REMOTE_CODE policies.factory:270
HF_REPO_NOT_ALLOWED A model repo is outside the mesh allowlist. Subject: the repo id. Grant: add the subject to the allowlist. STRANDS_MESH_HF_REPO_ALLOW mesh.security:1591
POLICY_TYPE_NOT_ALLOWED A policy type or provider is outside the mesh allowlist. Subject: the type or provider name (both share one allowlist, so both carry this code). Grant: add the subject to the allowlist. STRANDS_MESH_POLICY_TYPE_ALLOW mesh.security:1608, mesh.security:1617
POLICY_HOST_NOT_ALLOWED A policy host is outside the mesh allowlist. Subject: the host, or the whole server_address the host was taken from. Grant: add the subject to the allowlist. STRANDS_MESH_POLICY_HOST_ALLOW mesh.security:1566, mesh.security:1634
TELEOP_VALUE_OUT_OF_RANGE A teleop input frame commands a joint past the value envelope. Subject: the joint key. Grant: raise the bound above the refused magnitude. The subject is not the value here, and the magnitude appears only in the message, so a consumer offering this grant still has to read it out of the prose. STRANDS_MESH_INPUT_VALUE_ABS mesh.security:1927

Recording errors

class base meaning
RecordingFrameError RuntimeError A frame the dataset recorder could not write, in fail-fast mode. Raised by add_frame when the underlying LeRobotDataset write fails and the recorder was constructed with strict=True (the default). The frame is already gone at that point, so the episode on disk is shorter than the rollout that produced it and every surviving frame is re-timestamped from the declared fps - the caller has to be told.

The dashboard's consent endpoint maps each code to a grant name (trust_remote_code, hf_repo_allow, policy_type_allow, policy_host_allow, teleop_degree_units) in strands_robots/dashboard/consent.py; see the dashboard page.

Edit page