Skip to main content

Error reference

Standard OAuth 2.0 errors​

These errors are returned via the query parameters of the redirect URL or in token endpoint responses.

Error codeHTTP statusDescriptionCommon cause
invalid_request400The request is missing a required parameterMissing client_id, redirect_uri, etc.
invalid_client401Client authentication failedWrong client_id or client_secret
invalid_grant400The grant is invalidCode expired, already used, or wrong redirect_uri
invalid_scope400The requested scope is not allowedScope not registered for the client
unauthorized_client401The client is not authorized for the grant typeFlow not enabled for the client
unsupported_grant_type400The grant type is not supportedUsing an unsupported flow
access_denied403The user denied authorizationThe user clicked "Deny"
consent_required400Consent is required but prompt=noneUse an interactive flow
login_required400The user is not signed in but prompt=noneUse an interactive flow
server_error500The server encountered an errorContact support
temporarily_unavailable503The server is temporarily unavailableTry again later

Token validation errors​

ErrorHTTP statusDescriptionResolution
invalid_token401The token is invalid or expiredRefresh or re-authenticate
insufficient_scope403The token lacks the required scopeRequest additional scopes

The GET /api/magiclink/validate endpoint returns a numeric error code in the errorCode field of the response, along with an accompanying text explanation in the errorMessage field. The errorCode field is a number (not a string).

errorCodeMeaningUser action
1Token not found (TokenNotFound)Request a new magic link
2Token expired (TokenExpired)Request a new magic link
3Token already used (TokenAlreadyUsed)Request a new magic link
4User account not found (UserNotFound)Contact support
5User account deactivated (UserNotActive)Contact support
6Account locked (UserLocked)Wait or contact support
7Invalid token format (InvalidTokenFormat)Request a new magic link
8Invalid ticket (InvalidTicket)Request a new magic link

Example error response:

{
"valid": false,
"userGuid": null,
"email": null,
"errorMessage": "The magic link has expired.",
"errorCode": 2
}

HTTP status code overview​

Status codeMeaningCommon scenarios
200SuccessA successful request
302RedirectAn OAuth redirect
400Bad RequestInvalid parameters
401UnauthorizedInvalid credentials or token
403ForbiddenAccess denied, insufficient scope
404Not FoundThe resource does not exist
429Too Many RequestsRate limit exceeded
500Server ErrorInternal error
503Service UnavailableTemporary unavailability

Error response formats​

Authorization endpoint (via redirect)​

https://myapp.com/callback?error=access_denied&error_description=User%20denied%20access&state=xyz

Token endpoint (JSON)​

{
"error": "invalid_grant",
"error_description": "The authorization code has expired."
}

Error handling​

// Example error handling
async function handleTokenResponse(response) {
if (!response.ok) {
const error = await response.json();

switch (error.error) {
case 'invalid_grant':
// Code expired or invalid - restart the flow
redirectToLogin();
break;
case 'invalid_client':
// Configuration error - check the credentials
console.error('Invalid client credentials');
break;
default:
console.error('OAuth error:', error.error_description);
}
}
}