Sunshine's POST /api/pin returns HTTP 200 with {"status":false} when no pair session is pending. submitPIN (pkg/client/pairing.go:238-262) checks only the HTTP status code, so this failure is treated as success and the agent polls cert count for the full 30s timeout on a pairing that can no longer complete.
The agent reaches this state through a fixed 2s sleep between launching the pair subprocess and submitting the PIN (pairing.go:137-153). On a slow client start (cold Qt launch, slow disk, XWayland spin-up) the PIN arrives before the client's getservercert phase opens a session, and Sunshine discards it. Reproduced 2026-08-17 during the omarchy smoke test on cranky-toaster-86: a pair attempt where the client failed to launch returned {"status":false} and the flow had no way to see it.
Fix: parse the response body in submitPIN; on status:false retry the submit with ~1s backoff up to ~15s, while racing pairExitCh so early process death fails fast. Related hardening: treat cert-count increase (pairing.go:160-186) as a legacy fallback only, since any concurrent client pairing with the same body produces a false positive and triggers early termination of our own pair process; prefer headless exit 0, and verify with an authenticated probe before declaring the head paired. The structural fix on Linux is native pairing (gamestream_pair.go plus a moonlight_cert_linux.go QSettings writer, see #493 and #278), which removes the blind window entirely.
Affects the subprocess fallback on all platforms, primary path on Linux today.