Error codes

signature_invalid

Signature invalid

HTTP 401

The signature didn't verify. The answer is the same whatever failed: keyid names no signed credential of ours, or a revoked one; alg isn't the algorithm its key was registered with; the body doesn't match Content-Digest; or the signature isn't the credential's over the signature base built from the request as received. Rebuild the base from the exact request you sent, with @target-uri as a WHATWG URL parser serializes it (a ' in a query is %27, an empty ? is dropped), and check your signature with your public key.

The problem body

Sent as application/problem+json, with the request id in request_id and the X-Request-Id header. Branch on code: the error and detail sentences can change, and some operations add members of their own.

Example problem
{
  "error": "Signature invalid",
  "code": "signature_invalid",
  "type": "https://secondappraisal.com/developers/errors/signature_invalid",
  "title": "Signature invalid",
  "status": 401,
  "detail": "Signature invalid",
  "instance": "/api/gap/v1/referrals",
  "request_id": "req_4f9a2c7e1b8d4a6f9c3e2b1a7d5f8e0c"
}

Operations that can send it