Errors
Every refusal past sign-in is a problem (RFC 9457) with a stable code. Its type links here.
The format
application/problem+json: the code, a title and a sentence that are always the same, the request’s id, and only the fields its code names. Never the words of a card or an answer.
| { |
| "type": "https://www.pendingyou.com/docs/api/errors#high_stakes", |
| "title": "This card is high stakes", |
| "status": 403, |
| "code": "high_stakes", |
| "detail": "Answer it in Pending You: it spends money, can’t be undone or goes public.", |
| "requestId": "rid_0b5e8c1d2a3f4e5d6c7b", |
| "url": "https://www.pendingyou.com/app/r/req_4f1c9a0e2b7d6c5a8e31" |
| } |
Every code
invalid400Not validPart of the request isn’t valid: fields names it, and reason says which rule.
Fix the request: fields names what was refused. Adds fields, reason.
app_not_available403This app isn’t availableThis app can’t be used with this Pending You account now: why says why.
Stop: the app is switched off, not verified for this person, or the API is off. Say so. Adds why.
high_stakes403This card is high stakesAnswer it in Pending You: it spends money, can’t be undone or goes public.
Show the card, and send the person to url to answer it in Pending You. Adds url.
area_change403This card changes an areaAnswer it in Pending You: its yes renames or restyles one of the person’s areas.
Send the person to url: its yes changes one of their areas. Adds url.
not_your_answer403Not this app’s answerOnly an answer given in this app can be taken back from it.
Only your own answer can be taken back.
forbidden403Not allowedThis app can’t do that: reason says which rule.
Don’t offer it for this card. Adds reason.
not_found404Not foundThere’s nothing here that this app can see.
Drop the card: it’s gone, or not in this sign-in’s reach.
method_not_allowed405Method not allowedThis address takes another method: Allow says which.
Use the method Allow names.
version_conflict409The card changedThe card changed since the version you showed: read it again (currentVersion), show it, and ask again.
Read the card again, show it, and ask the person again. Adds currentVersion.
not_waiting409Not waiting on the personThe card isn’t waiting on the person now: cardStatus says where it is, reason why.
Read the card again: it was answered, put in Later or closed meanwhile. Adds cardStatus, reason.
hold_over409Too late to take it backThe answer’s 5 seconds are over: its assistant can see it now.
Too late: the assistant has the answer. The person can reply on the card.
delegated409With a helperThe person handed this card to another of their assistants.
Take it back first, or leave it with its helper. Adds cardStatus.
conflict409Not nowThe card isn’t where this can happen: reason says which rule.
Read the card again. Adds reason.
idempotency_in_progress409Still runningA request with this Idempotency-Key is still running: wait a moment, then send it again.
Wait a moment, then send the same request again.
idempotency_mismatch422Idempotency-Key used for another requestThis Idempotency-Key went with another request: send each new one with a key of its own.
Use a new Idempotency-Key for a new request.
rate_limited429Too many requestsWait retryAfterSeconds, then try again.
Wait retryAfterSeconds (or retry-after), then try again. Adds retryAfterSeconds, scope.
server_error500Something went wrongSomething went wrong in Pending You. Try again; if it keeps happening, quote requestId.
Try again; if it keeps happening, quote requestId.
not_available501Not available yetThis part of Pending You’s API isn’t built yet.
Not built yet: don’t offer it.
Sign-in’s own
A token, its proof or its scope: OAuth’s refusals (RFC 6750, RFC 9449), with WWW-Authenticate and { error, error_description }.
| Status | Error | What to do |
|---|---|---|
401 | invalid_token | Refresh once; if it’s refused again, the sign-in ended: sign in again. |
401 | invalid_dpop_proof | Make the proof again: for this method, address and token, by your key. |
401 | use_dpop_nonce | Make the proof again with the DPoP-Nonce sent, and send the request once more. |
403 | insufficient_scope | The person didn’t allow it: the challenge names the scope it needs. |
400 | invalid_grant | At the token endpoint: the sign-in ended. Sign in again. |