edge_auth_required
Edge authentication required
HTTP 403
At launchSent from launch, once the origin lock enforces.
The request reached our platform directly instead of through SecondAppraisal's edge, so it was refused before anything was read or written. Send it to the public hostname (secondappraisal.com or gap.secondappraisal.com), never to a platform address.
The platform's answer: plain JSON
At launchOnce the origin lock enforces, the platform refuses a request that reached it without passing through SecondAppraisal's edge, before the API sees it, whatever its method. Send every request to the public hostname, never to a platform address.
This answer has no code, type or request_id, and no X-Request-Id header, so branch on error when there is no code.
HTTP 403
content-type: application/json
cache-control: no-store{
"error": "edge_auth_required",
"message": "This request reached the platform without passing through SecondAppraisal's edge. Send it to the public hostname, not to a platform address."
}The API's answer: a problem
The API checks the edge again before it reads anything, and answers this problem to a request the platform let through unchecked.
Sent as application/problem+json, with the request id in request_id and the X-Request-Id header. Branch on code: the error and detail sentences can change, and some operations add members of their own.
{
"error": "Edge authentication required",
"code": "edge_auth_required",
"type": "https://secondappraisal.com/developers/errors/edge_auth_required",
"title": "Edge authentication required",
"status": 403,
"detail": "Edge authentication required",
"instance": "/api/gap/v1/referrals",
"request_id": "req_4f9a2c7e1b8d4a6f9c3e2b1a7d5f8e0c"
}Operations that can send it
- POST /api/gap/v1/referrals · HTTP 403 · Create a referral
- GET /api/gap/v1/referrals · HTTP 403 · List referrals
- GET /api/gap/v1/referrals/{id} · HTTP 403 · Retrieve a referral
- PATCH /api/gap/v1/referrals/{id} · HTTP 403 · Update or cancel a referral
- POST /api/gap/v1/referrals/bulk · HTTP 403 · Create referrals in bulk
- POST /api/gap/v1/referrals/{id}/simulate · HTTP 403 · Simulate a sandbox referral's next stepAt launchIt opens with the referral sandbox.
- POST /api/gap/v1/referrals/{id}/attest · HTTP 403 · Attest a warm handoffAt launchIt opens with the referral sandbox.
- GET /api/gap/v1/analytics · HTTP 403 · Savings and spend analytics
- POST /api/gap/v1/plans/enrollments · HTTP 403 · Enroll one vehicle
- GET /api/gap/v1/plans/enrollments · HTTP 403 · List your roster
- GET /api/gap/v1/plans/enrollments/{id} · HTTP 403 · Retrieve one enrollment
- PATCH /api/gap/v1/plans/enrollments/{id} · HTTP 403 · Cancel, swap the VIN, or edit contact details
- POST /api/gap/v1/plans/enrollments/bulk · HTTP 403 · Enroll up to 500 vehicles
- POST /api/gap/v1/plans/roster-sync · HTTP 403 · Reconcile your full roster
- POST /api/gap/v1/plans/loss-notices · HTTP 403 · Tell us a member vehicle was declared a total loss
- GET /api/gap/v1/plans/redemptions · HTTP 403 · Member consultations drawn against your roster
- GET /api/gap/v1/plans/statements · HTTP 403 · Your monthly membership statements
- GET /api/gap/v1/events · HTTP 403 · List your eventsAt launchIt opens with the partner security platform.
- GET /api/gap/v1/openapi · HTTP 403 · This OpenAPI document
- GET /api/gap/v1/openapi.json · HTTP 403 · This OpenAPI document (
.jsonalias) - GET /api/gap/v1/me · HTTP 403 · The key making this call
- POST /api/gap/v1/credentials/{id}/verify · HTTP 403 · Activate a signed credentialAt launchIt opens when signed credentials open.
- POST /api/gap/v1/signature-check · HTTP 403 · Check a signature (test credentials)Planned: not served yet.
- POST /api/gap/v1/review-status/lookup · HTTP 403 · Look up review status by VIN, claim number or referenceAt launchIt opens with review records.
- GET /api/gap/v1/referrals/{id}/review-record · HTTP 403 · Retrieve a referral's review recordAt launchIt opens with review records.