Errors
Registering a credential
| Code | Means |
|---|---|
API_CREDENTIAL_PUBLIC_KEY_INVALID | The key you sent is not EC P-256, is a certificate, or could not be read |
API_CREDENTIAL_ALLOWED_IPS_INVALID | Some entry in the IP list is neither valid IPv4 nor CIDR |
API_CREDENTIAL_ACCESS_PROFILE_UNKNOWN | Profile or version that does not exist |
Requesting a token
| Code | Means |
|---|---|
API_CREDENTIAL_INVALID_CLIENT | Wrong kid, aud, exp or signature in the token request |
API_CREDENTIAL_PROOF_REPLAY | The same jti was reused in a proof |
credential_revoked | The credential was revoked in the portal; create another one |
One code, many reasons
API_CREDENTIAL_INVALID_CLIENT is deliberately the same for every cause. Telling "bad signature"
apart from "unknown kid" would help someone trying to forge one. Sandbox returns the exact reason
in error_description; production returns only the code.
Calling the API
| Code | Means | Usually because |
|---|---|---|
DPOP_REQUIRED | You called /v2 with the bearer only | The proof header is missing |
DPOP_JKT_MISMATCH | The proof was signed by a key other than the token's | Two key pairs in the process, or the wrong one loaded |
DPOP_BODY_MISMATCH | The body sent is not the one hashed in bh | The object was serialized twice |
DPOP_QUERY_MISMATCH | The query sent is not the one hashed in qh | Canonicalization differs. Sort byte-wise, do not decode |
DPOP_HTU_MISMATCH | Method or URL differ from the proof | htu included the query, or a redirect changed the path |
DPOP_REPLAY | The same jti was reused in a request | A proof was cached and reused |
DPOP_STALE | iat outside the 60 second window | Clock drift. Use NTP |
IP_NOT_ALLOWED | Source outside the credential's IP list | Deploy from a new subnet, or a proxy exiting from another address |
403 on the route | The route is not allowed for the credential's profile | read_only credential on a write route |