Skip to main content

Errors

Registering a credential​

CodeMeans
API_CREDENTIAL_PUBLIC_KEY_INVALIDThe key you sent is not EC P-256, is a certificate, or could not be read
API_CREDENTIAL_ALLOWED_IPS_INVALIDSome entry in the IP list is neither valid IPv4 nor CIDR
API_CREDENTIAL_ACCESS_PROFILE_UNKNOWNProfile or version that does not exist

Requesting a token​

CodeMeans
API_CREDENTIAL_INVALID_CLIENTWrong kid, aud, exp or signature in the token request
API_CREDENTIAL_PROOF_REPLAYThe same jti was reused in a proof
credential_revokedThe credential was revoked in the portal; create another one
One code, many reasons

API_CREDENTIAL_INVALID_CLIENT is deliberately the same for every cause. Telling "bad signature" apart from "unknown kid" would help someone trying to forge one. Sandbox returns the exact reason in error_description; production returns only the code.

Calling the API​

CodeMeansUsually because
DPOP_REQUIREDYou called /v2 with the bearer onlyThe proof header is missing
DPOP_JKT_MISMATCHThe proof was signed by a key other than the token'sTwo key pairs in the process, or the wrong one loaded
DPOP_BODY_MISMATCHThe body sent is not the one hashed in bhThe object was serialized twice
DPOP_QUERY_MISMATCHThe query sent is not the one hashed in qhCanonicalization differs. Sort byte-wise, do not decode
DPOP_HTU_MISMATCHMethod or URL differ from the proofhtu included the query, or a redirect changed the path
DPOP_REPLAYThe same jti was reused in a requestA proof was cached and reused
DPOP_STALEiat outside the 60 second windowClock drift. Use NTP
IP_NOT_ALLOWEDSource outside the credential's IP listDeploy from a new subnet, or a proxy exiting from another address
403 on the routeThe route is not allowed for the credential's profileread_only credential on a write route

A quick decision tree​