Skip to main content

Error Codes

API errors use a standard response envelope:
Business and validation errors usually return HTTP 400. Unknown or rollout-disabled methods return HTTP 404 with code 1002. Credential-policy or scope denials return HTTP 403 with code 3008. Tenant-safe resource absence returns HTTP 404; it never reveals whether another merchant owns the identifier. State and idempotency conflicts return HTTP 409. Rate limits return HTTP 429 with the standard error envelope and retry headers. Internal processing failures (1000, 2001) return HTTP 500, provider interaction failures (7001) return HTTP 502, unavailable dependencies (2002) return HTTP 503, and provider timeouts (7002) return HTTP 504. Gateway readiness can return a non-envelope HTTP 503 while dependencies are not ready. Strict DTO validation, including invalid withdrawal data, can return code 9000 with HTTP 400.

Categories

Complete Reference

Common Fixes