Error codes

signature_profile_invalid

Signature doesn't follow the profile

HTTP 401

The signature headers don't follow the gap-v2 profile: one signature labelled sa in Signature-Input and Signature; covering @method and @target-uri, then content-digest and idempotency-key on POST and PATCH (on GET and HEAD, idempotency-key exactly when it is sent), then x-sa-environment; with the parameters created, nonce, keyid, alg (ed25519 or ecdsa-p256-sha256) and tag="gap-v2", in that order; a 64-byte signature; an Idempotency-Key of 1 to 255 visible ASCII characters (! to ~, no spaces); X-SA-Environment of TEST or PRODUCTION; and no Authorization header beside them. Nothing about the credential was checked.

The problem body

Sent as application/problem+json, with the request id in request_id and the X-Request-Id header. Branch on code: the error and detail sentences can change, and some operations add members of their own.

Example problem
{
  "error": "Signature doesn't follow the profile",
  "code": "signature_profile_invalid",
  "type": "https://secondappraisal.com/developers/errors/signature_profile_invalid",
  "title": "Signature doesn't follow the profile",
  "status": 401,
  "detail": "Signature doesn't follow the profile",
  "instance": "/api/gap/v1/referrals",
  "request_id": "req_4f9a2c7e1b8d4a6f9c3e2b1a7d5f8e0c"
}

Operations that can send it