Authorization required
An OAuth-backed connection that is not ready returns401:
@hookfish/sdk exposes these as HookfishError.authorizeUrl and
HookfishError.expiresAt. The SDK also preserves the HTTP status as status
and the parsed response as body. HookfishError.getResponse() reconstructs
the failed HTTP response, so Hono propagates an unhandled error without losing
its status or JSON body. Applications can still translate those fields in an
onError handler when they need a different public contract.
Provider scope not granted
If an authorization server grants fewer provider scopes than you requested, later access that requires a missing scope returns403 scope_not_granted:
connections.authorize(). Hookfish does not start another consent flow from
access() for scopes the provider already declined.
Common codes
Branch on
code, not message text. Do not forward provider diagnostics or
successful access payloads to browser code.