Error codes

signature_replay

Signature replayed

HTTP 409

At launchOnly a request signed by a signed credential is answered this way, and signed credentials can be registered from launch.

A request with this signature's nonce was already received for this credential with a signature that verified, so this one was refused before it was read further. A nonce is spent when its signature has verified, its body has matched Content-Digest, it came from an address the credential's IP allowlist holds (when it holds one) and the credential was within its rate limit, whatever that request is then answered; a request refused 403 ip_not_allowed, 503 credentials_unavailable because the allowlist couldn't be decided, 429 rate_limited, or 503 platform_standby because the nonce itself couldn't be written, hasn't spent it. Sign every request, a retry too, with a new nonce, and keep the same Idempotency-Key for a retry.

The problem body

Sent as application/problem+json, with the request id in request_id and the X-Request-Id header. Branch on code: the error and detail sentences can change, and some operations add members of their own.

Example problem
{
  "error": "Signature replayed",
  "code": "signature_replay",
  "type": "https://secondappraisal.com/developers/errors/signature_replay",
  "title": "Signature replayed",
  "status": 409,
  "detail": "Signature replayed",
  "instance": "/api/gap/v1/referrals",
  "request_id": "req_4f9a2c7e1b8d4a6f9c3e2b1a7d5f8e0c"
}

Operations that can send it