Error codes

edge_auth_required

Edge authentication required

HTTP 403

At launchSent from launch, once the origin lock enforces.

The request reached our platform directly instead of through SecondAppraisal's edge, so it was refused before anything was read or written. Send it to the public hostname (secondappraisal.com or gap.secondappraisal.com), never to a platform address.

The platform's answer: plain JSON

At launchOnce the origin lock enforces, the platform refuses a request that reached it without passing through SecondAppraisal's edge, before the API sees it, whatever its method. Send every request to the public hostname, never to a platform address.

This answer has no code, type or request_id, and no X-Request-Id header, so branch on error when there is no code.

The platform's answer: status and headers
HTTP 403
content-type: application/json
cache-control: no-store
The platform's answer: body
{
  "error": "edge_auth_required",
  "message": "This request reached the platform without passing through SecondAppraisal's edge. Send it to the public hostname, not to a platform address."
}

The API's answer: a problem

The API checks the edge again before it reads anything, and answers this problem to a request the platform let through unchecked.

Sent as application/problem+json, with the request id in request_id and the X-Request-Id header. Branch on code: the error and detail sentences can change, and some operations add members of their own.

Example problem
{
  "error": "Edge authentication required",
  "code": "edge_auth_required",
  "type": "https://secondappraisal.com/developers/errors/edge_auth_required",
  "title": "Edge authentication required",
  "status": 403,
  "detail": "Edge authentication required",
  "instance": "/api/gap/v1/referrals",
  "request_id": "req_4f9a2c7e1b8d4a6f9c3e2b1a7d5f8e0c"
}

Operations that can send it