The person API

Errors

Every refusal past sign-in is a problem (RFC 9457) with a stable code. Its type links here.

The format

application/problem+json: the code, a title and a sentence that are always the same, the request’s id, and only the fields its code names. Never the words of a card or an answer.

403 · application/problem+jsonJSON
{
"type": "https://www.pendingyou.com/docs/api/errors#high_stakes",
"title": "This card is high stakes",
"status": 403,
"code": "high_stakes",
"detail": "Answer it in Pending You: it spends money, can’t be undone or goes public.",
"requestId": "rid_0b5e8c1d2a3f4e5d6c7b",
"url": "https://www.pendingyou.com/app/r/req_4f1c9a0e2b7d6c5a8e31"
}

Every code

invalid400Not valid

Part of the request isn’t valid: fields names it, and reason says which rule.

Fix the request: fields names what was refused. Adds fields, reason.

app_not_available403This app isn’t available

This app can’t be used with this Pending You account now: why says why.

Stop: the app is switched off, not verified for this person, or the API is off. Say so. Adds why.

high_stakes403This card is high stakes

Answer it in Pending You: it spends money, can’t be undone or goes public.

Show the card, and send the person to url to answer it in Pending You. Adds url.

area_change403This card changes an area

Answer it in Pending You: its yes renames or restyles one of the person’s areas.

Send the person to url: its yes changes one of their areas. Adds url.

not_your_answer403Not this app’s answer

Only an answer given in this app can be taken back from it.

Only your own answer can be taken back.

forbidden403Not allowed

This app can’t do that: reason says which rule.

Don’t offer it for this card. Adds reason.

not_found404Not found

There’s nothing here that this app can see.

Drop the card: it’s gone, or not in this sign-in’s reach.

method_not_allowed405Method not allowed

This address takes another method: Allow says which.

Use the method Allow names.

version_conflict409The card changed

The card changed since the version you showed: read it again (currentVersion), show it, and ask again.

Read the card again, show it, and ask the person again. Adds currentVersion.

not_waiting409Not waiting on the person

The card isn’t waiting on the person now: cardStatus says where it is, reason why.

Read the card again: it was answered, put in Later or closed meanwhile. Adds cardStatus, reason.

hold_over409Too late to take it back

The answer’s 5 seconds are over: its assistant can see it now.

Too late: the assistant has the answer. The person can reply on the card.

delegated409With a helper

The person handed this card to another of their assistants.

Take it back first, or leave it with its helper. Adds cardStatus.

conflict409Not now

The card isn’t where this can happen: reason says which rule.

Read the card again. Adds reason.

idempotency_in_progress409Still running

A request with this Idempotency-Key is still running: wait a moment, then send it again.

Wait a moment, then send the same request again.

idempotency_mismatch422Idempotency-Key used for another request

This Idempotency-Key went with another request: send each new one with a key of its own.

Use a new Idempotency-Key for a new request.

rate_limited429Too many requests

Wait retryAfterSeconds, then try again.

Wait retryAfterSeconds (or retry-after), then try again. Adds retryAfterSeconds, scope.

server_error500Something went wrong

Something went wrong in Pending You. Try again; if it keeps happening, quote requestId.

Try again; if it keeps happening, quote requestId.

not_available501Not available yet

This part of Pending You’s API isn’t built yet.

Not built yet: don’t offer it.

unavailable503Unavailable

Pending You can’t answer right now: try again in a minute.

Try again in a minute.

Sign-in’s own

A token, its proof or its scope: OAuth’s refusals (RFC 6750, RFC 9449), with WWW-Authenticate and { error, error_description }.

StatusErrorWhat to do
401invalid_tokenRefresh once; if it’s refused again, the sign-in ended: sign in again.
401invalid_dpop_proofMake the proof again: for this method, address and token, by your key.
401use_dpop_nonceMake the proof again with the DPoP-Nonce sent, and send the request once more.
403insufficient_scopeThe person didn’t allow it: the challenge names the scope it needs.
400invalid_grantAt the token endpoint: the sign-in ended. Sign in again.