Published
Last reviewed: 2026-07-31
Scan failures
See why a scan failed or was blocked with normalized error codes — available to organization admins and owners.
Why a scan did not run
Organization admins and owners can review normalized reasons when a scan fails or is blocked before it starts (for example missing credits). This is separate from Team+ Audit logs, which record governance change history.
Where to look
- Settings → Scan Failures: organization-wide list of failed scan jobs and blocked scan attempts, with filters by error code and date.
- Project unit → Scan history: failed entries show a Failed badge; admins also see the reason when available.
Error codes
| Code | Meaning |
|---|---|
pat_required | A Personal Access Token is required for this repository |
repo_access | Repository could not be accessed (auth, permissions, or clone) |
rate_limit | Provider rate limit exceeded |
insufficient_credits | Not enough credits to run the scan |
payment_failed | Subscription payment failed |
sast_addon_required | SAST add-on not enabled (credits alone are not enough) |
entitlement_denied | Plan does not include the required feature |
lockfile_not_found | No lockfile for the project unit |
branch_or_commit_not_found | Branch or commit is not accessible |
workflow_timeout | Scan or workflow exceeded its time limit — if a credit was already consumed, it is restored automatically |
system_error | Unexpected platform failure — if a credit was already consumed, it is restored automatically; contact support if it persists |
Setup and access failures (pat_required, repo_access, lockfile_not_found, and similar) occur before debit and do not consume credits. See Credits.