signature_replay
Signature replayed
HTTP 409
At launchOnly a request signed by a signed credential is answered this way, and signed credentials can be registered from launch.
A request with this signature's nonce was already received for this credential with a signature that verified, so this one was refused before it was read further. A nonce is spent when its signature has verified, its body has matched Content-Digest, it came from an address the credential's IP allowlist holds (when it holds one) and the credential was within its rate limit, whatever that request is then answered; a request refused 403 ip_not_allowed, 503 credentials_unavailable because the allowlist couldn't be decided, 429 rate_limited, or 503 platform_standby because the nonce itself couldn't be written, hasn't spent it. Sign every request, a retry too, with a new nonce, and keep the same Idempotency-Key for a retry.
The problem body
Sent as application/problem+json, with the request id in request_id and the X-Request-Id header. Branch on code: the error and detail sentences can change, and some operations add members of their own.
{
"error": "Signature replayed",
"code": "signature_replay",
"type": "https://secondappraisal.com/developers/errors/signature_replay",
"title": "Signature replayed",
"status": 409,
"detail": "Signature replayed",
"instance": "/api/gap/v1/referrals",
"request_id": "req_4f9a2c7e1b8d4a6f9c3e2b1a7d5f8e0c"
}Operations that can send it
- POST /api/gap/v1/referrals · HTTP 409 · Create a referral
- GET /api/gap/v1/referrals · HTTP 409 · List referrals
- GET /api/gap/v1/referrals/{id} · HTTP 409 · Retrieve a referral
- PATCH /api/gap/v1/referrals/{id} · HTTP 409 · Update or cancel a referral
- POST /api/gap/v1/referrals/bulk · HTTP 409 · Create referrals in bulk
- POST /api/gap/v1/referrals/{id}/simulate · HTTP 409 · Simulate a sandbox referral's next stepAt launchIt opens with the referral sandbox.
- POST /api/gap/v1/referrals/{id}/attest · HTTP 409 · Attest a warm handoffAt launchIt opens with the referral sandbox.
- GET /api/gap/v1/analytics · HTTP 409 · Savings and spend analytics
- POST /api/gap/v1/plans/enrollments · HTTP 409 · Enroll one vehicle
- GET /api/gap/v1/plans/enrollments · HTTP 409 · List your roster
- GET /api/gap/v1/plans/enrollments/{id} · HTTP 409 · Retrieve one enrollment
- PATCH /api/gap/v1/plans/enrollments/{id} · HTTP 409 · Cancel, swap the VIN, or edit contact details
- POST /api/gap/v1/plans/enrollments/bulk · HTTP 409 · Enroll up to 500 vehicles
- POST /api/gap/v1/plans/roster-sync · HTTP 409 · Reconcile your full roster
- POST /api/gap/v1/plans/loss-notices · HTTP 409 · Tell us a member vehicle was declared a total loss
- GET /api/gap/v1/plans/redemptions · HTTP 409 · Member consultations drawn against your roster
- GET /api/gap/v1/plans/statements · HTTP 409 · Your monthly membership statements
- GET /api/gap/v1/events · HTTP 409 · List your eventsAt launchIt opens with the partner security platform.
- GET /api/gap/v1/me · HTTP 409 · The key making this call
- POST /api/gap/v1/credentials/{id}/verify · HTTP 409 · Activate a signed credentialAt launchIt opens when signed credentials open.
- POST /api/gap/v1/signature-check · HTTP 409 · Check a signature (test credentials)Planned: not served yet.
- POST /api/gap/v1/review-status/lookup · HTTP 409 · Look up review status by VIN, claim number or referenceAt launchIt opens with review records.
- GET /api/gap/v1/referrals/{id}/review-record · HTTP 409 · Retrieve a referral's review recordAt launchIt opens with review records.