Error codes

ip_not_allowed

Address not allowed

HTTP 403

At launchSent from launch, once the origin lock and the partner security platform enforce.

The key holds an IP allowlist, and this request came from an address outside it: the address our edge saw, never one a header names. Send the request from an address the allowlist holds, or change the key's allowlist in the portal. A request refused this way isn't counted against the key's rate limit, and a signed request's nonce isn't spent.

The problem body

Sent as application/problem+json, with the request id in request_id and the X-Request-Id header. Branch on code: the error and detail sentences can change, and some operations add members of their own.

Example problem
{
  "error": "Address not allowed",
  "code": "ip_not_allowed",
  "type": "https://secondappraisal.com/developers/errors/ip_not_allowed",
  "title": "Address not allowed",
  "status": 403,
  "detail": "Address not allowed",
  "instance": "/api/gap/v1/referrals",
  "request_id": "req_4f9a2c7e1b8d4a6f9c3e2b1a7d5f8e0c"
}

Operations that can send it