internal_error
An internal operation failed. Retry reads with backoff. Before retrying a write, check whether it already took effect. Contact support with the request details if the failure persists.not_found
The requested resource could not be found. Check the resource ID and the project selected by your credentials.method_not_allowed
The endpoint does not support the HTTP method you used. Check the method in the endpoint reference.validation_error
One or more request fields failed validation. Use the field details in the response to correct the request before retrying. A request from an origin that is not authorized for the project also returnsvalidation_error, with a message naming the origin. Check the origin configured for your web integration and the project’s authorized origins.
login_error
Authentication or authorization failed. Check the credential format, the key’s permissions, expiry and IP restrictions. Use the HTTP status to distinguish missing or invalid authentication from denied access. A project ID in the query, header or path that does not match the project of your credentials also returnslogin_error.
invalid_json
The request body could not be parsed as JSON. Check JSON syntax and send a valid JSON body.rate_limited
The request exceeded a rate limit. Reduce request frequency and retry with backoff, honoringRetry-After when provided. Limits depend on the service and deployment configuration; do not assume one fixed limit applies to every endpoint.
already_exists
The resource already exists or a uniqueness constraint would be violated. Look up the existing resource before attempting another create request.wrong_content_type
The request uses an unsupported content type. Use the content type declared by the endpoint, typicallyapplication/json for JSON request bodies.
client_error
The service classified the failure as a client-side request error. Inspect the response details and the endpoint’s requirements before retrying.source
TheX-Corbado-Source header contains an unsupported value. Corbado SDKs set this header themselves; when you call the API directly, omit it.
For signed-passkey verification, create an application session only when the HTTP request succeeds and verificationResult is success. A successful HTTP status alone does not establish a successful login.