The serving URL returns 404
The Theme has never been published
The Theme has never been published
404.Fix: publish the Theme. See Versioning.The Theme does not serve that file
The Theme does not serve that file
Build-time tokens does not serve tokens.css at all.Fix: check the Theme’s Integration tab, which lists the URLs that actually exist. Add the pair you need and republish. See What gets served.The Theme has no integrations at all
The Theme has no integrations at all
You asked for a version that was never published
You asked for a version that was never published
/7/ only exists if version 7 exists. Versions start at 1 and never skip, but a Theme with 3 versions has no /7/.Fix: read servingUrls.version from the API, or use latest.Wrong Environment
Wrong Environment
{environmentID} segment.You are using a slug rather than an id
You are using a slug rather than an id
/acme/sandbox/… is a portal URL, not a serving URL.Fix: copy the URL from the Theme’s Integration tab.The serving URL returns 403
A403 never tells you which check refused — deliberately, because naming the failing check tells an attacker which header to forge. So work through all three:
The Theme is signed and your signature is wrong
The Theme is signed and your signature is wrong
403 for a missing signature, a malformed one, an unknown kid, and a wrong MAC — one answer for all four.Check, in order:- Is the canonical string exactly
path + "?kid=" + kid, with the path from the leading slash and no host? - Is the digest base64url with padding stripped, not standard base64?
- Is the
kidin the URL the same one you signed with? - Was the key deleted?
An origin allowlist is refusing you
An origin allowlist is refusing you
- A
<link rel=\"stylesheet\">sends noOriginheader unless you addcrossorigin. The only signal isReferer, and a page withReferrer-Policy: no-referrerwithholds that too — so a browser request with an allowlist set can be refused even from a listed origin. - A sandboxed iframe sends
Origin: null, which is refused rather than treated as missing.
crossorigin to the link. See Access control.An IP allowlist is refusing you
An IP allowlist is refusing you
A publish is not showing up
Give it a few seconds
Give it a few seconds
latest moves when materialisation finishes, not when the button goes green.Your cache is still holding the old answer
Your cache is still holding the old answer
latest is cached for your Environment’s lifetime — 60 seconds by default — and served stale-while-revalidate for up to 5 minutes past that.To confirm a publish landed, poll the pinned URL for the new version number. It appears as soon as materialisation finishes and is never served stale. See Caching.You are pinned to an old version
You are pinned to an old version
/7/ in it, publishing version 8 changes nothing for that app — which is exactly why you pinned it.Fix: bump the number, or move to latest.A token is missing from the output
The Variant overrides a path the Theme does not have
The Variant overrides a path the Theme does not have
The token has no CSS spelling
The token has no CSS spelling
tokens.css is a lossy projection. A token CSS cannot express becomes a comment naming its path rather than being dropped silently.Fix: search the stylesheet for the path. If it is commented, read tokens.json instead.The document relies on $extends or $ref
The document relies on $extends or $ref
{color.brand} — which are fully supported.A Theme publish dropped the override
A Theme publish dropped the override
move has to be inferred, and the inference can lose an override when the rename also changed the value.Fix: re-set the override on the Variant, and use move for renames in future.Publishing a Variant returns 409
A Variant can be published only once per Theme version. Its version number is the Theme version its overrides answer, so the second publish finds that file already written. Re-reading and retrying will not clear it. Publish the Theme first, then the Variant.A Variant has unpublished changes nobody made
Expected after a Theme publish. The automatic migration writes each Variant’s draft and does not publish it. Review the draft and publish.The API returns 403 and the person is a Team Admin
Correct behaviour. A Team role grants nothing inside an Environment. A Team Admin with no grant on that Environment is refused, by design. Fix: grant them the Environment. See Roles.The API returns 401
The token is missing, expired, or minted for the wrong audience. The Public API accepts onlyhttps://api.livry.dev/public/v1, and a developer-portal token is refused.
Note also that machine credentials are not issuable yet — the API is reachable today only with a user-backed token. See Authentication.
The API returns 402
A plan ceiling, not a rate limit. Creating a Variant past your Theme’s allowance. Retrying will not help. See Plans and limits.Colours look wrong after switching brand
Your app is holding values rather thanvar() references. Swapping the stylesheet only rebrands what references custom properties.
Check your theme configuration for literal hex values, and see Choosing an approach.
var(), which is why those read tokens.values.json and must re-fetch on a brand change.