Error codes
Every refusal the API makes is an RFC 9457 problem, sent as application/problem+json. Branch on its code, which never changes; the error sentence is for people and can. Its type is the URL of the code's page below, and its request_id is the one to quote when you contact us.
Some answers come from the platform or our edge itself, before the API sees the request, as plain JSON with an error member and no code, type or X-Request-Id: 503 platform_standby to a write during a failover; at launch, once the origin lock enforces, 403 edge_auth_required to a request that didn't pass through our edge; and 503 service_unavailable, below, to any request during an outage. When there is no code, branch on error.
Our edge's outage answer
During an outage, our edge answers every request itself, whatever its method, before the API sees it. Nothing was processed: send the same request again after the seconds in Retry-After, with the same Idempotency-Key where the operation takes one.
HTTP 503
content-type: application/json
retry-after: 60
cache-control: public, max-age=10
x-robots-tag: noindex, nofollow, noarchive{
"error": "service_unavailable",
"retryAfter": 60,
"message": "Our upstream provider is experiencing an outage. The site will be back online as soon as service is restored. If urgent, please visit https://secondappraisal.com/ to reveal contact details."
}If our edge can't reach the API, it answers 502, or 504 when the API hasn't answered in five minutes, with a plain-text body. Retry those with the same Idempotency-Key too.
| Code | HTTP status | Meaning |
|---|---|---|
| invalid_json | 400 | Invalid JSON |
| unsupported_media_type | 415 | Unsupported media type |
| payload_too_large | 413 | Payload too large |
| too_many_rows | 413 | Too many rows |
| prohibited_field | 400 | Prohibited field |
| validation_failed | 400 | Validation failed |
| operation_not_open | 404 | Operation not open yet |
| idempotency_key_too_long | 400 | Idempotency-Key too long |
| internal_error | 500 | Internal error |
| missing_api_key | 401 | Missing API key |
| invalid_api_key | 401 | Invalid API key |
| api_key_expired | 401 | API key expired |
| key_not_scoped | 403 | Key not scoped for this surface |
| test_key_referrals_unavailable | 403 | Test keys can't reach referrals yet |
| provider_terminated | 403 | Account terminated |
| provider_suspended | 403 | Account suspended |
| provider_not_active | 403 | Account not active |
| rate_limited | 429 | Rate limit exceeded |
| auth_unavailable | 500 | Key check unavailable |
| permission_denied | 403 | Permission denied |
| credentials_unavailable | 503 | Credentials unavailable |
| signed_requests_required | 401 | Signed requests required |
| ip_not_allowed | 403 | Address not allowed |
| auth_failures_throttled | 429 | Too many failed authentications |
| signature_profile_invalid | 401 | Signature doesn't follow the profile |
| signature_expired | 401 | Signature outside its window |
| target_uri_not_allowed | 401 | Host not accepted for signed requests |
| signature_invalid | 401 | Signature invalid |
| environment_mismatch | 401 | Wrong environment |
| credential_not_activated | 401 | Credential not activated |
| signature_replay | 409 | Signature replayed |
| public_key_in_use | 409 | Public key in use |
| edge_auth_required | 403 | Edge authentication required |
| platform_standby | 503 | Platform on standby |
| membership_program_closed | 404 | Membership closed to institutions |
| membership_not_enabled | 403 | Membership not enabled |
| membership_rider_unsigned | 403 | Membership rider unsigned |
| membership_billing_mode_required | 403 | Membership billing mode required |
| membership_billing_method_required | 403 | Billing method required |
| msa_required | 403 | Agreement not executed |
| billing_required | 403 | Billing method required |
| email_required_sms_disabled | 422 | Borrower email required |
| script_version_stale | 409 | Disclosure script out of date |
| duplicate_reference | 409 | Duplicate referral |
| invalid_cursor | 400 | Invalid cursor |
| not_found | 404 | Not found |
| referral_locked | 409 | Referral locked |
| cancel_not_allowed | 409 | Cancel not allowed |
| economics_locked | 409 | Program terms locked |
| nothing_to_update | 400 | Nothing to update |
| idempotency_key_mode_conflict | 409 | Idempotency-Key used in the other mode |
| state_not_served | 422 | State not served |
| duplicate_referral | 409 | Loss already referred |
| simulate_requires_test_key | 403 | Test key required |
| invalid_transition | 409 | Invalid transition |
| reporting_withdrawn | 409 | Reporting withdrawn |
| vin_already_live | 409 | VIN already enrolled |
| vin_already_consulted | 422 | VIN already consulted |
| state_required | 422 | Garaged state required |
| state_blocked | 422 | State not served |
| vin_invalid | 422 | Invalid VIN |
| invalid_customer_price | 422 | Invalid member price |
| idempotency_key_reused | 422 | Idempotency-Key reused |
| plan_not_enabled | 403 | Membership not enabled |
| not_live | 409 | Enrollment not live |
| not_a_member_vehicle | 404 | Not a member vehicle |
| request_refused | 400 | Request refused |