Error responses
Every error carries an HTTP status code and a structured JSON body with a stable, machine-
readable code and a human-readable message.
{
"success": false,
"code": "invalid_client_credentials",
"message": "The provided clientId or clientSecret is invalid"
}Branch on the code, not the message — messages may be reworded, codes are stable.
Common codes
| Status | code | Meaning |
|---|---|---|
400 | validation_error | The request body or query failed validation |
401 | invalid_client_credentials | Missing or wrong client id / secret |
403 | insufficient_scope | The credential lacks the required scope |
403 | credential_inactive | The credential has been revoked |
403 | client_inactive | The project/account is not active |
403 | customer_not_accessible | The customer isn’t mapped to this project |
404 | not_found | The resource doesn’t exist |
See Authentication for the auth-specific cases.