error is a human-readable message written for your engineers. It names the offending
field and the constraint it broke. It is not localised and it is not meant for your end
users.
Status codes
Validation errors
Most400s come from the transaction configuration. The message tells you exactly which
constraint failed:
Every range and default is listed on Create transaction.
A
400 on Create transaction means nothing was created. There is no transaction to
clean up and no sdk_token was issued.What is safe to retry
1
4xx: never retry unchanged
The request itself is wrong. Retrying the same bytes returns the same error. The one
exception is
401, where requesting a new token and retrying once is correct.2
429 and 5xx: retry with backoff
Start around one second, double each time, add jitter, and give up after a handful of
attempts. A
5xx that persists for more than a minute is worth an alert on your side.3
Timeouts: be careful with Create transaction
Create transaction is not idempotent. If your request timed out you do not know
whether a transaction was created. Retrying blindly can leave an orphaned transaction
that expires on its own — harmless, but it will show up in reconciliation. Prefer a
generous client timeout over aggressive retries here.
A rejection is not an error
This trips up almost every first integration, so it is worth stating plainly:
A
REJECTED decision is a successful API call that returned a negative verdict. An
UNDETERMINED decision is a successful API call telling you the analysis did not
complete — a configuration problem or a provider failure, described in issues[].
Neither is an HTTP error, and your error handling should not treat them as one.
See Decisions and issues for how to act on each.
Getting help
When you contact support about a failed request, include thetransaction_id if you have
one, the exact error message, and the time of the request in UTC. That is enough for us
to find it.
