Error codes

prohibited_field

Prohibited field

HTTP 400

The body names a field a referral must never carry: an SSN or tax id, a date of birth, an account, loan, member, card or routing number, a credit score or report, income or salary (matched on the field's name, at the top level and inside program and disclosure). field_errors names each one. Nothing else in the body is checked until they are gone, nothing is written, and the values are never stored, logged or sent back. Remove the fields and send the request again.

The problem body

Sent as application/problem+json, with the request id in request_id and the X-Request-Id header. Branch on code: the error and detail sentences can change, and some operations add members of their own.

Example problem
{
  "error": "Prohibited field",
  "code": "prohibited_field",
  "type": "https://secondappraisal.com/developers/errors/prohibited_field",
  "title": "Prohibited field",
  "status": 400,
  "detail": "Prohibited field",
  "instance": "/api/gap/v1/referrals",
  "request_id": "req_4f9a2c7e1b8d4a6f9c3e2b1a7d5f8e0c"
}

Operations that can send it