# auth: broaden discovery-unavailable wording to missing-or-unreachable

`64ae399`→[main](/content/gh/entireio/cli/commits/main/index.html)·

toothbrush·1mo ago·1 file·+1 added/-1 removed

The sentinel covers 404/503/malformed too, so calling a reachable
host's missing well-known "unreachable" misled; the wrapped error
still carries the precise cause.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

## Sessions

1edf76e5cd82View transcript

[?\
Auth Refactor: Eliminate Static FallbacksClaude Code·Fable 5.\[1m\]·2 steps](/content/gh/entireio/cli/session/e6146684-ebfa-4f57-beff-34194cac8c2a#timeline-1edf76e5cd82/index.html)

## Changes

1

- cmd/entire/cli/auth

- Mdata_api.go+1/-1

```
73 unmodified lines

74
75
76
77
77
78
79
80

73 unmodified lines

selected, err := resolveContextForAPI(dctx, userdirs.Config(), userdirs.Cache(), host, httpClient, nil)
	if errors.Is(err, clusterdiscovery.ErrDiscoveryUnavailable) {
		return "", fmt.Errorf("%s does not advertise its trusted login servers (/.well-known/entire-api.json unreachable); cannot authenticate: %w", host, err)
		return "", fmt.Errorf("%s does not advertise its trusted login servers (/.well-known/entire-api.json missing or unreachable); cannot authenticate: %w", host, err)
	}
	if err != nil {
		return "", err
```
