{success, data} envelope on success responses either, they return the resource directly:
@kerne/server throws a typed KerneError (or a subclass - AuthenticationError, AuthorizationError, NotFoundError, ValidationError, RateLimitError, EntitlementDeniedError) built from this shape, so you can instanceof it instead of parsing code yourself.
A few subclasses are raised client-side before a request goes out - EntitlementDeniedError from enforce(), NotFoundError from billing.cancel() / priceIdFor(), ValidationError from priceIdFor() on an ambiguous price, RateLimitError from auth.sendVerificationEmail()’s cooldown. They carry the same code/type/statusCode shape but no requestId, since no server request produced them.

