APIAgent-ready
Every authentication failure now has the same machine-readable fields
Every 401 response now carries a code, message and retryable flag, so agents can handle auth failures the same way everywhere.
A 401 used to look different depending on which endpoint answered it: some sent a plain error string, others a nested error object. Every 401 now also carries three top-level fields, whatever the endpoint:
code:invalid_credentialswhen the credential you sent was rejected (an expired token, an unknown API key, a bad signature), orunauthorizedwhen none was sent or it is not the kind that endpoint accepts.message: the same text as before.retryable: alwaysfalse. Retrying without a different credential gets the same answer.
The existing error field is unchanged, so integrations that read it keep working. 401 responses also carry a WWW-Authenticate: Bearer realm="last-price" challenge. The discovery document and the API reference describe the shape.