Skip to main content

Errors

Responses use JSON with error / error_description or JSON:API-style errors arrays.

Status codes​

CodeMeaningTypical fix
401Missing/invalid/expired tokenRefresh via /oauth/token
403Valid token, forbiddenGrant scope/permission; use user token if required
400Bad request / validationFix body, filters, or required user
404Unknown route or recordCheck path, id, host/tenant
501Feature/module disabled for this orgEnable on System → organization → Restfull Toggle tab
422Semantic validationSee message (e.g. form errors)

Envelope​

{
"error": "400: Bad request",
"error_description": "Title is too short (under 15 characters). Body must start with a capital letter",
"error_details": [
{ "code": "too_short", "field": "title", "description": "Title is too short (under 15 characters)" },
{ "code": "must_start_with_caps", "field": "body", "description": "Body must start with a capital letter" }
]
}
  • error / error_description are always present (error_description may join several messages with ". ").
  • error_details is present for draft proposal update / publish validation failures: one entry per ActiveModel error (code, optional field, description).
  • Prefer branching on error_details[].code (and field) rather than parsing error_description text.

Draft proposal validation codes​

codeTypical meaning
blankTitle/body empty
too_shortUnder minimum length (title 15, body 15)
too_longOver maximum length
must_start_with_capsMust start with a capital letter
too_much_capsToo many capital letters
too_many_marksToo many consecutive punctuation marks
cant_be_equal_to_templateBody equals the component template

On update, only errors for fields present in the payload are returned.

Common messages​

Message / situationRemediation
Forbidden / CanCan deniedAdd permission in System admin (proposals.draft, …)
User requiredUse ROPC/impersonation token with resource_owner_id
User blocked / lockedPick another user
Already votedIdempotent vote handling on your side
Unknown order / filterMatch OpenAPI allowed values
Attachments API disabledRestfull Toggle attachments_enabled for the organization

Permissions debugging​

  1. Confirm scope on token includes the route family (proposals, …).
  2. Confirm permission on API client matches the action.
  3. Confirm Host matches the organization that owns the client.