Error Codes

Every standardized error code the Checkpoint platform returns, grouped by category, with HTTP status and message

This page is generated from the shared error registry in packages/checkpoint-shared/src/constants/errors.ts. Do not edit it by hand: run pnpm --filter @kya-os/checkpoint-shared run errors:docs to regenerate it, and CI fails any change that leaves this page out of date with the registry.

Error responses carry these codes in the error.code field of the standard error envelope, alongside a human-readable message. The HTTP status column shows the status returned for that code. A status marked "(default)" means the code has no explicitly assigned status in the registry and falls back to 500. A few endpoints also emit route-local codes that are not part of this registry, for example PROVISIONING_INVALID_REQUEST from the provisioning API.

Authentication

CodeHTTP statusMessage
AUTH_INVALID_API_KEY401The provided API key is invalid
AUTH_EXPIRED_API_KEY401The API key has expired
AUTH_INVALID_TOKEN401The provided token is invalid
AUTH_EXPIRED_TOKEN401The token has expired
AUTH_MISSING_CREDENTIALS401Authentication credentials are required
AUTH_UNAUTHORIZED401You are not authorized to perform this action
AUTH_MANAGEMENT_TOKEN_NOT_ACCEPTED401Management session tokens are accepted only by /api/cli/management routes
AUTH_INVALID_PIXEL_ID500 (default)The provided pixel ID is invalid
AUTH_INVALID_SECRET_KEY500 (default)The provided secret key is invalid

Validation

CodeHTTP statusMessage
VALIDATION_INVALID_REQUEST400The request is invalid
VALIDATION_MISSING_REQUIRED_FIELD400A required field is missing
VALIDATION_INVALID_FIELD_TYPE400Field type is invalid
VALIDATION_INVALID_FIELD_VALUE400Field value is invalid
VALIDATION_FIELD_TOO_LONG500 (default)Field value exceeds maximum length
VALIDATION_FIELD_TOO_SHORT500 (default)Field value is below minimum length
VALIDATION_INVALID_EMAIL500 (default)Invalid email address format
VALIDATION_INVALID_URL500 (default)Invalid URL format
VALIDATION_INVALID_UUID500 (default)Invalid UUID format
VALIDATION_INVALID_IP_ADDRESS500 (default)Invalid IP address format
VALIDATION_INVALID_USER_AGENT500 (default)Invalid or missing user agent
VALIDATION_BAD_REQUEST400Bad request
VALIDATION_INVALID_START_DATE400Invalid request data
VALIDATION_INVALID_END_DATE400Invalid request data
VALIDATION_INVALID_DATE_RANGE400Invalid request data

Detection

CodeHTTP statusMessage
DETECTION_FAILED500 (default)Agent detection failed
DETECTION_INSUFFICIENT_DATA500 (default)Insufficient data for detection
DETECTION_PATTERN_MATCH_FAILED500 (default)Pattern matching failed
DETECTION_WASM_NOT_LOADED500 (default)WASM module is not loaded
DETECTION_WASM_EXECUTION_FAILED500 (default)WASM execution failed
DETECTION_CONFIDENCE_BELOW_THRESHOLD500 (default)Detection confidence below threshold
DETECTION_SIGNATURE_VERIFICATION_FAILED500 (default)Signature verification failed

Rate limiting

CodeHTTP statusMessage
RATE_LIMIT_EXCEEDED429Rate limit exceeded
RATE_LIMIT_BURST_EXCEEDED429Burst limit exceeded
RATE_LIMIT_DAILY_EXCEEDED429Daily request limit exceeded
RATE_LIMIT_MONTHLY_EXCEEDED500 (default)Monthly request limit exceeded
RATE_LIMIT_CONCURRENT_EXCEEDED500 (default)Concurrent request limit exceeded
RATE_LIMIT_QUOTA_EXCEEDED500 (default)Account quota exceeded
RATE_LIMITED429Too many requests

Permissions

CodeHTTP statusMessage
PERMISSION_INSUFFICIENT403Insufficient permissions
PERMISSION_RESOURCE_NOT_FOUND404Resource not found
PERMISSION_ACCESS_DENIED403Access to resource denied
PERMISSION_OPERATION_NOT_ALLOWED403Operation not allowed
PERMISSION_PROJECT_ACCESS_DENIED500 (default)Project access denied
PERMISSION_PIXEL_ACCESS_DENIED500 (default)Pixel access denied
PERMISSION_FORBIDDEN403Access denied
PERMISSION_DENIED403Permission denied

Network

CodeHTTP statusMessage
NETWORK_CONNECTION_FAILED500 (default)Connection failed
NETWORK_TIMEOUT504Request timeout
NETWORK_DNS_FAILED500 (default)DNS resolution failed
NETWORK_SSL_ERROR500 (default)SSL/TLS error
NETWORK_PROXY_ERROR500 (default)Proxy error
NETWORK_UPSTREAM_ERROR502Upstream service error

Internal

CodeHTTP statusMessage
INTERNAL_SERVER_ERROR500Internal server error
INTERNAL_DATABASE_ERROR500Database error
INTERNAL_CACHE_ERROR500 (default)Cache error
INTERNAL_CONFIGURATION_ERROR500 (default)Configuration error
INTERNAL_INITIALIZATION_ERROR503Initialization error
INTERNAL_PROCESSING_ERROR500Processing error
INTERNAL_UNKNOWN_ERROR500 (default)An unknown error occurred
SERVICE_UNAVAILABLE_TRANSIENT503A dependency is temporarily unavailable. Retry shortly.
TRANSACTION_FAILED500The deletion failed because of a database error. Nothing was deleted.
DELETE_FAILED500Failed to delete project
PARTITION_RETIREMENT_IN_PROGRESS503The project data is being archived. Retry shortly.

Session

CodeHTTP statusMessage
SESSION_NOT_FOUND404Session not found
SESSION_EXPIRED500 (default)Session has expired
SESSION_INVALID500 (default)Session is invalid
SESSION_CREATION_FAILED500 (default)Failed to create session
SESSION_UPDATE_FAILED500 (default)Failed to update session
SESSION_STORAGE_ERROR500 (default)Session storage error
SESSION_MAX_EXCEEDED500 (default)Maximum sessions exceeded

Pixel

CodeHTTP statusMessage
PIXEL_NOT_FOUND404Pixel not found
PIXEL_DISABLED500 (default)Pixel is disabled
PIXEL_CONFIGURATION_ERROR500 (default)Pixel configuration error
PIXEL_DOMAIN_NOT_ALLOWED500 (default)Domain not allowed for this pixel
PIXEL_PATH_SKIPPED500 (default)Path is configured to be skipped
PIXEL_EVENT_INVALID500 (default)Invalid pixel event
PIXEL_BATCH_TOO_LARGE413Event batch exceeds maximum size
MISSING_PIXEL_ID400Project ID is required
DETECTION_STORAGE_FAILED500Failed to store detection data
PIXEL_CREATION_FAILED500Failed to create pixel for project

API

CodeHTTP statusMessage
API_ENDPOINT_NOT_FOUND404API endpoint not found
API_METHOD_NOT_ALLOWED405HTTP method not allowed
API_VERSION_NOT_SUPPORTED500 (default)API version not supported
API_CONTENT_TYPE_NOT_SUPPORTED415Content type not supported
API_RESPONSE_TOO_LARGE500 (default)Response exceeds maximum size
API_REQUEST_TOO_LARGE413Request exceeds maximum size

Billing

CodeHTTP statusMessage
LIMIT_EXCEEDED402Billing limit exceeded
BILLING_SUSPENDED402Account billing suspended
BILLING_GRACE_PERIOD200Account in billing grace period

Resources

CodeHTTP statusMessage
CONFLICT409Resource conflict
PROJECT_NOT_FOUND500 (default)Project not found
REVIEW_REQUIRED422Deploy requires explicit confirmation of the consequential writes it will perform.

Policy

CodeHTTP statusMessage
POLICY_FETCH_FAILED500Failed to fetch policy

Analytics

CodeHTTP statusMessage
INVALID_PERIOD400Period must be one of: hour, day, week, month
ANALYTICS_FETCH_ERROR500Failed to retrieve analytics data
STATS_FETCH_ERROR500Failed to retrieve stats

Deploy

CodeHTTP statusMessage
MISSING_USER_IDENTIFIER400Either userEmail or userGithubId is required to identify the user
USER_NOT_FOUND404User not found in Checkpoint. The user must have an existing Checkpoint account to deploy.
NO_ORGANIZATION400User has no organization in Checkpoint. Please complete onboarding first at https://kya.vouched.id
DEPLOY_FAILED500 (default)Deployment failed
WFP_NOT_CONFIGURED500 (default)Managed hosting is not configured
NATIVE_ISSUER_PROVISIONING_BUSY500 (default)Native issuer provisioning is busy or temporarily unavailable; retry deployment
NATIVE_ISSUER_PROVISIONING_FAILED500 (default)Native issuer provisioning failed; deployment retained for retry

Un-prefixed

CodeHTTP statusMessage
VALIDATION_ERROR400Invalid request data
INTERNAL_ERROR500Internal server error
INVALID_REQUEST400Invalid JSON body
INVALID_JSON400Request body must be valid JSON
INVALID_START_DATE400Invalid startDate format. Use ISO 8601 format (YYYY-MM-DD or YYYY-MM-DDTHH:mm:ss.sssZ)
INVALID_END_DATE400Invalid endDate format. Use ISO 8601 format (YYYY-MM-DD or YYYY-MM-DDTHH:mm:ss.sssZ)
INVALID_DATE_RANGE400startDate must be before endDate
INVALID_DATE400Invalid date format. Use ISO 8601 format (YYYY-MM-DD or YYYY-MM-DDTHH:mm:ss.sssZ)
UNKNOWN_ERROR500Failed to delete project

Lowercase (kya-os events wire format)

CodeHTTP statusMessage
invalid_json400Request body must be valid JSON
validation_error400Invalid request body

Bouncer (lower-case wire format)

CodeHTTP statusMessage
no_project400API key is not associated with a project
missing_agent_did400agent_did query parameter is required
not_configured400Bouncer is not configured for this project
invalid_credential_config400Credential provider missing required fields: authEndpoint and responseFields
project_not_found404Project not found
project_mismatch403API key does not have access to this project
missing_delegation_id400Delegation ID is required
invalid_token401Invalid or expired delegation token
delegation_mismatch403Delegation ID does not match token
tokens_not_found404OAuth tokens not available for this delegation
decryption_error500Failed to decrypt OAuth tokens
no_proofs400At least one proof is required
batch_too_large400Maximum batch size is 100 proofs
no_proofs_processed400No proofs were processed. This indicates a server error.
all_proofs_rejected400All proofs were rejected due to validation failures
unauthorized401API key is not associated with a project
forbidden403API key does not have access to this project
not_found404Session not found
config_not_found404Bouncer config not found for project
agent_denied403Agent is on the deny list
delegation_not_found404Delegation not found
session_not_found404Session not found
proof_validation_error400Proof validation failed
insufficient_scopes403Missing required scopes
delegation_validation_error400Delegation validation failed
invalid_http_registration400Invalid or unsupported native HTTP registration
authorization_host_unavailable503Authorization host is a project deployment that cannot currently serve consent

Delegation OAuth (lower-case wire format)

CodeHTTP statusMessage
invalid_request400Invalid request body
unsupported_grant_type400Only authorization_code grant type is supported
invalid_grant500 (default)Invalid or expired authorization code
invalid_delegation404Delegation not found or inactive
internal_error500An internal error occurred during token exchange
invalid_state400Restart authorization from the requesting agent.
invalid_transaction400Restart authorization from the requesting agent.
oauth_unavailable503OAuth is temporarily unavailable. Please request a new authorization link.
oauth_not_configured400OAuth provider is not configured. Please configure OAuth in the dashboard.
oauth_configuration_unsupported400The selected provider is not configured for the platform delegation callback.
invalid_provider_config400OAuth provider is missing authorization endpoint
rate_limit_exceeded429Too many requests. Please try again later.

Bouncer (upper-case wire format)

CodeHTTP statusMessage
INVALID_REQUEST_BODY400Invalid JSON in request body
MCPI_CONFIG_NOT_FOUND404KYA-OS configuration not found
CONSENT_CONFIG_NOT_FOUND404Consent configuration not found for this project
PROJECT_LOOKUP_FAILED500Failed to lookup project
CONFIG_VALIDATION_ERROR400Configuration validation failed
CONFIG_FETCH_FAILED500Failed to fetch configuration
CONFIG_UPDATE_FAILED500Failed to update configuration
DEPLOYMENT_NOT_FOUND404No active deployment for this project
INVALID_REQUEST_ID400Invalid delegation request ID format
DELEGATION_REQUEST_NOT_FOUND404No delegation request exists for this ID. It may have expired, or it was never issued.

Audit ingest

CodeHTTP statusMessage
AUDIT_CREDENTIAL_REQUIRED401A source-bound audit ingest credential is required
AUDIT_REQUEST_TOO_LARGE413Audit submission exceeds 6291456 bytes
AUDIT_INVALID_JSON400Request body must be valid JSON
AUDIT_INVALID_CREDENTIAL401Invalid audit ingest credential
AUDIT_RATE_LIMITED429Audit ingest rate limit exceeded
AUDIT_INVALID_SUBMISSION400Invalid audit recorder submission envelope
AUDIT_INTERNAL_ERROR500Audit recorder is temporarily unavailable

Audit protocol (relayed from @kya-os/mcp)

CodeHTTP statusMessage
AUDIT_UNAUTHORIZED_SUBMISSION403Audit producer is not authorized for this ledger
AUDIT_LEDGER_MISMATCH409Submission belongs to a different audit ledger than the credential binding
AUDIT_EPOCH_MISMATCH409Submission belongs to a different ledger epoch
AUDIT_EVENT_ID_CONFLICT409Producer event identity was reused with different content
AUDIT_INVALID_EVENT422Audit event failed protocol validation
AUDIT_EVIDENCE_FAILURE422Submitted evidence could not be matched or persisted
AUDIT_EVIDENCE_INTEGRITY422Evidence ciphertext or metadata digest does not verify
AUDIT_INVALID_CONFIGURATION503Audit recorder is temporarily unavailable
AUDIT_JOURNAL_FAILURE503Audit recorder is temporarily unavailable
AUDIT_APPEND_CONFLICT_EXHAUSTED503Audit recorder is temporarily unavailable
AUDIT_EVIDENCE_LEGAL_HOLD500Audit recorder is temporarily unavailable
AUDIT_EVIDENCE_ACCESS_DENIED500Audit recorder is temporarily unavailable
AUDIT_CHECKPOINT_INVALID500Audit recorder is temporarily unavailable
AUDIT_CHECKPOINT_ROLLBACK500Audit recorder is temporarily unavailable
AUDIT_CHECKPOINT_CONFLICT500Audit recorder is temporarily unavailable
AUDIT_CHECKPOINT_PUBLICATION_FAILED500Audit recorder is temporarily unavailable
AUDIT_PROJECTION_CONFLICT500Audit recorder is temporarily unavailable
AUDIT_MIRROR_VERIFICATION_FAILED500Audit recorder is temporarily unavailable
AUDIT_MIRROR_CONTINUITY_FAILED500Audit recorder is temporarily unavailable
AUDIT_MIRROR_OUT_OF_ORDER500Audit recorder is temporarily unavailable

KYA-OS native HTTP protocol (kyaos/*)

CodeHTTP statusMessage
kyaos/issuer-forbidden403The caller is not an authorized native issuer for this project
kyaos/profile-violation500 (default)The request does not conform to the KYA-OS native HTTP profile
kyaos/invalid-session404The session is unknown, expired, or not owned by this project
kyaos/session-conflict409The session is already bound to a different registration or grant
kyaos/pickup-expired410The pickup anchor has expired
kyaos/scope-insufficient403The requested scopes exceed what the session allows
kyaos/consent-required403Consent terms must be accepted before a delegation can be issued
kyaos/pickup-pinned403The pickup anchor is pinned to a different holder key
kyaos/authorization-host-unavailable503The authorization host cannot currently serve this request
kyaos/chain-broken403The propagation chain could not be verified
kyaos/delegation-revoked403The delegation has been revoked
kyaos/expired410The credential or proof has expired
kyaos/holder-mismatch403The holder does not match the delegation or grant
kyaos/invalid-signature403The signature could not be verified
kyaos/session-mismatch409The session does not match the delegation or proof
kyaos/policy-unavailable503The policy revision is currently unavailable