Decide by status first, then by code where it matters:
Status
Meaning
What your code should do
Status400
MeaningThe request was invalid
What your code should doFix the request. Retrying it unchanged fails the same way
Status401
MeaningThe key or agent access token is missing, malformed, expired or revoked
What your code should doFor a secret key, check the key and its mode, and don't retry. An agent gets a new access token on invalid_token, and asks its person to connect it again on agent_disconnected
Status403
MeaningNot allowed for this account, key or agent
What your code should doDon't retry. On insufficient_scope, use a key or agent with Full access
Status404
MeaningNot found in this account and mode
What your code should doCheck the id and whether the key's mode matches the object's
Status409
MeaningThe object's state doesn't allow this
What your code should doRead the object and act on its current status
Status410
MeaningThe session can't be paid any more
What your code should doCreate a new session
Status413, 415
MeaningThe body is too large or isn't JSON
What your code should doFix the request
Status429
MeaningRate limited
What your code should doWait for Retry-After seconds, then retry
Status500, 502, 503
MeaningSomething failed on our side or upstream
What your code should doRetry with backoff. Creates are safe to retry with the same Idempotency-Key
Causeamount isn't a string, or isn't from "1.00" to "100000.00" with at most two decimal places
Codeinvalid_currency
EndpointCreate
Causecurrency isn't USD, EUR, GBP, CAD or AUD
Codemissing_description
EndpointCreate
Causedescription is missing, blank or not a string
Codetoo_long
EndpointCreate
Causedescription or reference is over 120 characters. See field
Codeinvalid_reference
EndpointCreate
Causereference isn't a string
Codeinvalid_email
EndpointCreate, Start
Causecustomer_email or customer.email isn't a valid address, or Start needs one and none is on the session
Codeinvalid_url
EndpointCreate
Causesuccess_url or cancel_url isn't a full http(s):// address, has a username or password, is over 1,000 characters, or isn't https:// in Live mode
Codeinvalid_metadata
EndpointCreate
CauseOver 20 keys, a blank key, a key over 40 characters or starting with __, or a value that isn't a string of at most 500 characters
Codeinvalid_idempotency_key
EndpointCreate
CauseThe Idempotency-Key header is blank, over 120 characters or has characters other than printable ASCII
Codeinvalid_customer
EndpointCreate
Causecustomer isn't an object, or customer.email and customer_email are different addresses
Codeinvalid_order
EndpointCreate
CauseA field in order has the wrong type, is too long or is out of range, such as a quantity that isn't a whole number from 1 to 100,000 or an item without name or amount. See field
Codeinvalid_order_totals
EndpointCreate
CauseThe items less discount plus shipping and tax don't equal amount to the cent, or without items, shipping and tax less discount come to more than amount
Codeinvalid_country
EndpointStart
Causecountry isn't a two-letter code such as US
Codeinvalid_limit
EndpointAny list
Causelimit isn't a whole number from 1 to 100
Codeinvalid_cursor
EndpointAny list
Causestarting_after isn't one of your payments, orders or customers (whichever you're listing) in this mode
Codeinvalid_outcome
EndpointSimulate
Causeoutcome isn't paid, underpaid, declined or failed
Codeinvalid_fulfillment
EndpointUpdate an order
Causefulfillment is missing or isn't none, unfulfilled or fulfilled
Every 401 carries a WWW-Authenticate header that points to the API's protected resource metadata, where an agent can find out how to get access.
Code
Cause
Codeinvalid_api_key
CauseNo Authorization: Bearer header, a malformed key, or a revoked one. Create a key in Developers
Codeinvalid_token
CauseAn agent's access token expired, is malformed, or wasn't issued for Railbed. Get a new one from the token endpoint described in auth.md
Codeagent_disconnected
CauseThe agent was disconnected in the dashboard, or the person who connected it no longer manages keys for the business. Ask an owner or developer to connect it again
CauseThe account is suspended. Email support@railbed.com
Codeinsufficient_scope
CauseThe key's or agent's access level doesn't include the scope this endpoint needs, such as a Read only key creating a checkout session. The message and the WWW-Authenticate header (error="insufficient_scope", scope="…") name the scope. Use a key or agent with Full access
Codelive_payment
CauseSimulate was called on a Live payment. Only Test payments can be simulated
CauseNo such session, payment, order or customer in your account in this key's mode, or no such endpoint. A Test key can't see Live objects and the other way round
CauseThe key was used with a different body. Rarely, the first request with the key hadn't finished saving: retry in a moment
Codeno_payout_wallet
EndpointCreate
CauseLive mode needs a payout wallet. Add one in Settings
Codeorder_paid
EndpointCreate
CauseThe store order in order.id is already paid, or held with money you could accept as paid or that part-paid it. Nothing was created. Check the order before asking the buyer to pay again. See Store orders and retries
Codeunavailable
EndpointStart
CauseThe account can't take payments now
Codeno_providers
EndpointStart
CauseNo card provider can take this amount and currency right now. Nothing was started; try later or a different amount
Codealready_paid
EndpointStart
CauseThe payment is complete
Codeheld
EndpointStart
CauseThe money arrived and the payment is held for review
Codefailed
EndpointStart
CauseThe payment was declined. Create a new session
CauseThe body isn't sent as Content-Type: application/json
Status429
Coderate_limited
CauseOver about 120 requests a minute (each connected agent has its own 120, and a business's agents share 600), 12 starts a minute, or about 60 requests a minute from one address with a missing or invalid key. Wait for Retry-After