ErtisAuth

Error Codes

Every error code the API returns.

Every error response carries an errorCode (see API Conventions for the shape). This page lists the codes by area, with their HTTP status.

General#

CodeStatusMeaning
ModelValidationError400The request failed validation; data lists the problems
ValidationException400One or more user fields are invalid or not unique; errors lists them
FieldValidationException400A user field is invalid (fieldName, fieldPath)
SchemaValidationException400A user type schema is invalid
ParameterFormatError400An id is not a valid ObjectId
InvalidQuery400A _query body is not valid, or uses a forbidden operator
UnsupportedAggregationStage400An aggregation stage is not allowed
SearchKeywordRequired400keyword is missing
IdenticalDocumentError409An update without any change
BulkDeleteFailed404None of the resources could be deleted
BulkDeletePartial200Only some of the resources were deleted
UnhandledExceptionError500An unexpected error; see the server log

Authentication and tokens#

CodeStatusMeaning
AuthorizationHeaderMissing401No Authorization header
TokenTypeNotSupported400The scheme is not Bearer or Basic, or the wrong one for the endpoint
BearerTokenRequired400The endpoint needs a Bearer token
InvalidToken401The token is malformed, has a wrong signature, belongs to an unknown membership or application, or is not usable here
TokenWasExpired401The access token has expired
TokenWasRevoked401The access token was revoked
RefreshTokenRequired400No refresh token was given
TokenIsNotRefreshable401The token is not a refresh token
RefreshTokenWasExpired401The refresh token has expired
RefreshTokenWasRevoked401The refresh token was already used or revoked
InvalidCredentials401Unknown user or wrong password (or wrong one-time password)
InvalidCredentialsOrMissingToken400Neither credentials nor a token were given to /generate-token
UserInactive401The account is not active
ScopeRequired400A scoped token was requested without scopes
InvalidScope400A scope is not a valid permission expression
UserHasNoPermissionForThisScope400The user doesn't have a requested scope
MembershipIdsDoNotMatch400The token and X-Ertis-Alias belong to different memberships
MembershipIdRequired400X-Ertis-Alias is missing
Unauthorized401Generic authentication failure, e.g. a provider rejected the login

Authorization#

CodeStatusMeaning
AccessDenied403The caller may not perform the request, or the token belongs to another membership
InvalidRbac400A permission expression is invalid
InvalidUbac400A user or application permission expression is invalid
UbacsConflicted409The same expression is in a user's permissions and forbidden
PermissionParameterRequired400permission is missing in a check-permission request
AuthenticationServiceUnavailable503(SDK) ErtisAuth could not be reached

Setup#

CodeStatusMeaning
SetupRejected401The setup token is missing, too short or wrong
AlreadySetUp409The installation is already set up
SetupInProgress409Another setup request is running

Memberships#

CodeStatusMeaning
MembershipNotFound404
MembershipAlreadyExists409The slug is taken
MembershipCouldNotDeleted409The membership still has resources
HashAlgorithmRequired400
UnsupportedHashAlgorithm400
MembershipHashAlgorithmInvalid500A stored membership has no valid hash algorithm
UnsupportedEncoding400
UnsupportedLanguage400Unknown default_language

Users#

CodeStatusMeaning
UserNotFound404
PasswordRequired400
PasswordMinLengthRuleError400The password is shorter than 6 characters
EmailAddressRequired400
UsernameOrEmailAddressRequired400
RoleRequired400
UserAlreadyActive400
UserAlreadyInactive400
UserTypeRequired400
UserTypeImmutable400A user's type can't be changed
HostRequired400X-Host is missing
ResetTokenRequired400
InvalidUtilizer501A mail hook should be sent to a utilizer without an email address

User types#

CodeStatusMeaning
UserTypeNotFound404
UserTypeAlreadyExists409The slug is taken
UserTypeNameRequired400
UserTypeCannotBeBothAbstractAndSealed400
InheritedTypeNotFound400The base type does not exist
InheritedTypeIsSealed400The base type can't be inherited from
InheritedTypeIsAbstract400A user can't have an abstract type
UserTypeInheritanceCycle400The inheritance chain loops
ReservedUserTypeName409Base User is reserved
ReservedUserTypeSlug409base-user is reserved
UniqueFieldHasDuplicates409Existing users share a value of a field being made unique
UserTypeCanNotBeDelete400The type still has users or derived types

Roles and applications#

CodeStatusMeaning
RoleNotFound404
RoleAlreadyExists409The slug is taken
ReservedRole409admin is reserved
SystemRolesCannotBeDeleted409The admin role can't be deleted
ApplicationNotFound404
ApplicationAlreadyExists409The slug is taken

Providers#

CodeStatusMeaning
ProviderNotFound404
ProviderAlreadyExists409The slug is taken
ProviderTypeRequired400
UnknownProvider400Unknown type
UnsupportedProvider400The provider type is not supported here
ProviderSlugCannotBeChanged400
InvalidProviderLoginRequest400The login body doesn't match the provider type
ProviderNotConfigured403No provider with this slug
ProviderIsDisable403The provider is not active
UntrustedProvider403The client id doesn't match the provider
ProviderEmailNotTrusted409A user with the same unverified email exists
ProviderProfileIncomplete401The provider profile lacks the email or the name
ProviderNotConfiguredCorrectly501The provider configuration is incomplete or wrong
ProviderUnavailable503The provider could not be reached

Account recovery#

CodeStatusMeaning
OtpNotConfiguredYet400The membership has no OTP policy
OtpHostNotConfiguredYet400The membership has no OTP host
OtpHostRequired400X-Host is missing, or otp_settings.host is empty
OtpHostMismatch401X-Host is not the membership's OTP host
OtpExpired401The one-time password has expired
OneTimePasswordNotFound404
OneTimePasswordAlreadyExists409

Device code flow#

CodeStatusMeaning
TokenCodePolicyNotFound404The membership has no code policy, or it doesn't exist
TokenCodePolicyAlreadyExists409The slug is taken
TokenCodePolicyInUse409The membership uses the policy
TokenCodeNotFound404Unknown or expired user code
TokenCodeExpired401The code has expired
UnauthorizedTokenCode401The code is not approved yet
TokenCodeDenied401The user denied the code
TokenCodeSlowDown400The device polls more often than interval
TokenCodeAlreadyAuthorized409The code was already approved or denied
TokenCodeCouldNotBeGenerated503No unused user code could be generated; try again

Hooks, events and sessions#

CodeStatusMeaning
WebhookNotFound404
WebhookAlreadyExists409The slug is taken
MailHookNotFound404
MailHookAlreadyExists409The slug is taken
NotDefinedAnyMailProvider501The membership has no mail provider
ActivationMailHookWasNotDefined501No active User Activation mail hook
ResetPasswordMailHookWasNotDefined501No active Reset Password mail hook
EventNotFound404
ActiveTokenNotFound404

Found a mistake in the docs? Open an issue