The SDK stops with a message that names the problem. Messages about a source system start with Credentials:, and messages from the Datayield API start with API:.
Setup
No datayield.config.json at <path>. Run "datayield init" first.
Run datayield init in the folder you want to use, or pass --config with the path to your config.
No API key. Run "datayield init" or set DATAYIELD_API_KEY.
The SDK found no key in ~/.datayield/credentials or the environment. On CI, check that the DATAYIELD_API_KEY secret is set and passed to the step.
API keys start with dy_test_ or dy_live_.
The value is not a Datayield key. Copy one from the portal under Settings → API keys.
No pseudonym salt. Run "datayield init" (or set DATAYIELD_SALT)...
Uploads need a salt so tokens stay the same across batches. Run datayield init on this machine, or on CI set DATAYIELD_SALT to the salt from the machine that sent earlier batches. Do not create a new salt for a source that already has batches.
<path> is readable by other users
The credentials file has loose permissions. Run chmod 600 ~/.datayield/credentials.
Refusing to send an API key over http://...
The API URL must use HTTPS. Only localhost is allowed over plain HTTP.
Source credentials
Credentials: <System> rejected the credentials (HTTP 401).
The token is wrong, expired or revoked. The rest of the message says where to get a new one. For Xero, QuickBooks and Salesforce, scheduled runs need a refresh token, because their access tokens expire within an hour.
Credentials: <System> refused access (HTTP 403).
The token works but lacks a scope or permission. The message names what is missing. Each connector page lists the scopes to grant.
... would not issue an access token
The OAuth refresh failed. Check the client ID, client secret and refresh token. If the refresh token no longer works, authorize the app again and run datayield connect with the new token.
<key> was rotated by the provider but comes from the environment
The system issued a new refresh token, but yours comes from an env: variable the SDK cannot update. Put the new token in that variable, such as the repository secret, before the next run.
Option "<key>" refers to <NAME>, which is not set.
An env:NAME option points at a variable that is missing in this environment.
<source>: invalid <connector> options
An option is missing or malformed. The message lists each problem. Fix it with datayield connect <connector> --name <source> -o key=value.
Runs
Exit code 2: Leak check failed: <n> output cells still contain a known identifier. Nothing was uploaded.
A value from an identifier column survived scrubbing somewhere else in the output. Run datayield preview --out review and read review/report.md to find the column, then set its role in scrub.columns in the config. The SDK will not upload until the leak check passes.
nothing new since the last run
No records changed in the window. The state moves forward and no batch is created. For the CSV connector without timestampColumn, it means no file was modified since the last run.
the window start ... is not before ...
--since is in the future, or the state file holds a time ahead of the machine's clock. Check the clock, or pass an earlier --since.
<secrets> secrets were removed. Removing them here does not revoke them; rotate them.
Credentials turned up in the source data. They are blanked in the output and listed in the report by row and column, never by value. Rotate them in the systems they belong to.
Many records below the k threshold
The summary shows min k and how many rows are below the threshold. See Re-identification testing for how to coarsen dates or amounts, or set suppressBelow in the scrub settings.
Rate limits and outages
The SDK retries rate-limited (429) and failed (5xx) requests with backoff, up to four times, and honors Retry-After when the system sends it. The Linear connector retries rate limits up to three times. If a system is still unavailable, the run fails without moving the state forward, and the next run pulls the same window again.
Uploads
API: ... (401)
The key was revoked or is wrong. Create a new key in the portal and run datayield init --api-key <new key>.
Upload failed with HTTP <status>.
The batch was created but the file did not arrive. The state did not move, so run again.
The API says this is a test key, but it looks like a live key (or the reverse)
The key does not match what the API has on record. Copy the key again from the portal.
Still stuck
Run datayield preview --out review and send review/report.md with the error when you contact us. The report holds no raw values. Do not send the scrubbed records or your credentials file.