ReadonlyreasonAn optional machine-readable reason, rendered into the response body alongside the message. DECLARED HERE rather than sniffed structurally at the mapper so the channel is part of the contract a subclass opts into, and so the mapper needs no import of any subclass to render it (see the header for why that import must not exist).
ReadonlystatusThe response status. 4xx/5xx only — see doErrorResponse.
The key names a reservation owned by a different principal.
403 rather than 404: the caller sent a syntactically valid key it is simply not entitled to, and this is the one refusal whose body deliberately carries nothing else — not the owner, not the target, not the run. A key is guessable by construction (hosts derive them from order ids and request ids), so this response is reachable by probing, and everything it does not say is something a prober does not learn.