Troubleshoot API responses
Start with the HTTP status, then inspect the body and relevant headers. A JSON:API error document contains an errors array. Not every infrastructure or rate-limit response is guaranteed to have a JSON:API body.
| Status | What to check |
|---|---|
400 Bad Request | JSON shape, field validation, filter syntax, IDs and supported relationships |
401 Unauthorized | Missing, expired or invalid bearer token; authentication environment |
403 Forbidden | Requested scopes, permitted adviser context and record access |
404 Not Found | Route, identifier and visibility; do not assume it proves deletion |
409 Conflict | A conflict reported by the operation, including identity or relationship constraints where applicable |
415 Unsupported Media Type | The request's content type and JSON:API body format |
423 Locked on a Beta endpoint | Temporary beta availability restriction; see below |
429 Too Many Requests | Request cost, available tokens and retry guidance |
5xx | A server or upstream failure; use a bounded retry policy for safe requests |
This table is a troubleshooting guide. The endpoint reference remains the source for documented responses for a particular operation.
Read an error document
An illustrative JSON:API validation error looks like:
{
"errors": [
{
"status": "400",
"title": "Invalid request",
"detail": "Check the supplied email address.",
"source": { "pointer": "/data/attributes/email" }
}
]
}
status is a string inside an error object. detail explains the specific problem, and source.pointer or source.parameter can identify the input. Fields and wording vary; handle the status and documented codes rather than matching human-readable messages.
Temporary beta lock: 423
For an endpoint marked Beta, 423 Locked with feature_not_enabled means the beta feature is not enabled for the resolved user, or a valid user could not be resolved. This restriction is temporary during beta, not a permanent requirement for the endpoint's general availability.
Normal authentication and authorisation checks run first. Confirm the adviser context, then arrange beta enablement with LMG. Repeated retries or broader scopes will not unlock a disabled beta. Read the beta guide.
Ask for help with useful context
Provide the environment, HTTP method, path, time, response status and any returned correlation identifier. Include a minimal sanitised request or error example. Keep bearer tokens, client secrets and personal client information out of support examples.