Every error response carries an errorCode (see API Conventions for the shape). This page lists the codes by area, with their HTTP status.
General#
| Code | Status | Meaning |
|---|
ModelValidationError | 400 | The request failed validation; data lists the problems |
ValidationException | 400 | One or more user fields are invalid or not unique; errors lists them |
FieldValidationException | 400 | A user field is invalid (fieldName, fieldPath) |
SchemaValidationException | 400 | A user type schema is invalid |
ParameterFormatError | 400 | An id is not a valid ObjectId |
InvalidQuery | 400 | A _query body is not valid, or uses a forbidden operator |
UnsupportedAggregationStage | 400 | An aggregation stage is not allowed |
SearchKeywordRequired | 400 | keyword is missing |
IdenticalDocumentError | 409 | An update without any change |
BulkDeleteFailed | 404 | None of the resources could be deleted |
BulkDeletePartial | 200 | Only some of the resources were deleted |
UnhandledExceptionError | 500 | An unexpected error; see the server log |
Authentication and tokens#
| Code | Status | Meaning |
|---|
AuthorizationHeaderMissing | 401 | No Authorization header |
TokenTypeNotSupported | 400 | The scheme is not Bearer or Basic, or the wrong one for the endpoint |
BearerTokenRequired | 400 | The endpoint needs a Bearer token |
InvalidToken | 401 | The token is malformed, has a wrong signature, belongs to an unknown membership or application, or is not usable here |
TokenWasExpired | 401 | The access token has expired |
TokenWasRevoked | 401 | The access token was revoked |
RefreshTokenRequired | 400 | No refresh token was given |
TokenIsNotRefreshable | 401 | The token is not a refresh token |
RefreshTokenWasExpired | 401 | The refresh token has expired |
RefreshTokenWasRevoked | 401 | The refresh token was already used or revoked |
InvalidCredentials | 401 | Unknown user or wrong password (or wrong one-time password) |
InvalidCredentialsOrMissingToken | 400 | Neither credentials nor a token were given to /generate-token |
UserInactive | 401 | The account is not active |
ScopeRequired | 400 | A scoped token was requested without scopes |
InvalidScope | 400 | A scope is not a valid permission expression |
UserHasNoPermissionForThisScope | 400 | The user doesn't have a requested scope |
MembershipIdsDoNotMatch | 400 | The token and X-Ertis-Alias belong to different memberships |
MembershipIdRequired | 400 | X-Ertis-Alias is missing |
Unauthorized | 401 | Generic authentication failure, e.g. a provider rejected the login |
Authorization#
| Code | Status | Meaning |
|---|
AccessDenied | 403 | The caller may not perform the request, or the token belongs to another membership |
InvalidRbac | 400 | A permission expression is invalid |
InvalidUbac | 400 | A user or application permission expression is invalid |
UbacsConflicted | 409 | The same expression is in a user's permissions and forbidden |
PermissionParameterRequired | 400 | permission is missing in a check-permission request |
AuthenticationServiceUnavailable | 503 | (SDK) ErtisAuth could not be reached |
Setup#
| Code | Status | Meaning |
|---|
SetupRejected | 401 | The setup token is missing, too short or wrong |
AlreadySetUp | 409 | The installation is already set up |
SetupInProgress | 409 | Another setup request is running |
Memberships#
| Code | Status | Meaning |
|---|
MembershipNotFound | 404 | |
MembershipAlreadyExists | 409 | The slug is taken |
MembershipCouldNotDeleted | 409 | The membership still has resources |
HashAlgorithmRequired | 400 | |
UnsupportedHashAlgorithm | 400 | |
MembershipHashAlgorithmInvalid | 500 | A stored membership has no valid hash algorithm |
UnsupportedEncoding | 400 | |
UnsupportedLanguage | 400 | Unknown default_language |
Users#
| Code | Status | Meaning |
|---|
UserNotFound | 404 | |
PasswordRequired | 400 | |
PasswordMinLengthRuleError | 400 | The password is shorter than 6 characters |
EmailAddressRequired | 400 | |
UsernameOrEmailAddressRequired | 400 | |
RoleRequired | 400 | |
UserAlreadyActive | 400 | |
UserAlreadyInactive | 400 | |
UserTypeRequired | 400 | |
UserTypeImmutable | 400 | A user's type can't be changed |
HostRequired | 400 | X-Host is missing |
ResetTokenRequired | 400 | |
InvalidUtilizer | 501 | A mail hook should be sent to a utilizer without an email address |
User types#
| Code | Status | Meaning |
|---|
UserTypeNotFound | 404 | |
UserTypeAlreadyExists | 409 | The slug is taken |
UserTypeNameRequired | 400 | |
UserTypeCannotBeBothAbstractAndSealed | 400 | |
InheritedTypeNotFound | 400 | The base type does not exist |
InheritedTypeIsSealed | 400 | The base type can't be inherited from |
InheritedTypeIsAbstract | 400 | A user can't have an abstract type |
UserTypeInheritanceCycle | 400 | The inheritance chain loops |
ReservedUserTypeName | 409 | Base User is reserved |
ReservedUserTypeSlug | 409 | base-user is reserved |
UniqueFieldHasDuplicates | 409 | Existing users share a value of a field being made unique |
UserTypeCanNotBeDelete | 400 | The type still has users or derived types |
Roles and applications#
| Code | Status | Meaning |
|---|
RoleNotFound | 404 | |
RoleAlreadyExists | 409 | The slug is taken |
ReservedRole | 409 | admin is reserved |
SystemRolesCannotBeDeleted | 409 | The admin role can't be deleted |
ApplicationNotFound | 404 | |
ApplicationAlreadyExists | 409 | The slug is taken |
Providers#
| Code | Status | Meaning |
|---|
ProviderNotFound | 404 | |
ProviderAlreadyExists | 409 | The slug is taken |
ProviderTypeRequired | 400 | |
UnknownProvider | 400 | Unknown type |
UnsupportedProvider | 400 | The provider type is not supported here |
ProviderSlugCannotBeChanged | 400 | |
InvalidProviderLoginRequest | 400 | The login body doesn't match the provider type |
ProviderNotConfigured | 403 | No provider with this slug |
ProviderIsDisable | 403 | The provider is not active |
UntrustedProvider | 403 | The client id doesn't match the provider |
ProviderEmailNotTrusted | 409 | A user with the same unverified email exists |
ProviderProfileIncomplete | 401 | The provider profile lacks the email or the name |
ProviderNotConfiguredCorrectly | 501 | The provider configuration is incomplete or wrong |
ProviderUnavailable | 503 | The provider could not be reached |
Account recovery#
| Code | Status | Meaning |
|---|
OtpNotConfiguredYet | 400 | The membership has no OTP policy |
OtpHostNotConfiguredYet | 400 | The membership has no OTP host |
OtpHostRequired | 400 | X-Host is missing, or otp_settings.host is empty |
OtpHostMismatch | 401 | X-Host is not the membership's OTP host |
OtpExpired | 401 | The one-time password has expired |
OneTimePasswordNotFound | 404 | |
OneTimePasswordAlreadyExists | 409 | |
Device code flow#
| Code | Status | Meaning |
|---|
TokenCodePolicyNotFound | 404 | The membership has no code policy, or it doesn't exist |
TokenCodePolicyAlreadyExists | 409 | The slug is taken |
TokenCodePolicyInUse | 409 | The membership uses the policy |
TokenCodeNotFound | 404 | Unknown or expired user code |
TokenCodeExpired | 401 | The code has expired |
UnauthorizedTokenCode | 401 | The code is not approved yet |
TokenCodeDenied | 401 | The user denied the code |
TokenCodeSlowDown | 400 | The device polls more often than interval |
TokenCodeAlreadyAuthorized | 409 | The code was already approved or denied |
TokenCodeCouldNotBeGenerated | 503 | No unused user code could be generated; try again |
Hooks, events and sessions#
| Code | Status | Meaning |
|---|
WebhookNotFound | 404 | |
WebhookAlreadyExists | 409 | The slug is taken |
MailHookNotFound | 404 | |
MailHookAlreadyExists | 409 | The slug is taken |
NotDefinedAnyMailProvider | 501 | The membership has no mail provider |
ActivationMailHookWasNotDefined | 501 | No active User Activation mail hook |
ResetPasswordMailHookWasNotDefined | 501 | No active Reset Password mail hook |
EventNotFound | 404 | |
ActiveTokenNotFound | 404 | |