Error responses
Registration and client-management endpoints return failures as a JSON object with a machine-readable code and a human-readable message:
{
"code": "ROLE_NOT_ALLOWED",
"message": "certificate does not contain role PSP_PI"
}Branch on code. The message explains the failure for logs and support conversations and can change without notice.
The Error schema is part of the registration API
specification.
Error codes
| Code | Meaning |
|---|---|
INVALID_REQUEST | The request body or a parameter is missing, malformed, or fails validation. |
INVALID_CERTIFICATE_CHAIN | The supplied certificate value could not be read as a PEM chain from leaf to root. |
CERTIFICATE_VALIDATION_FAILED | The certificate chain is not a valid, trusted eIDAS QWAC. See Security model. |
ROLE_NOT_ALLOWED | The certificate does not assert the PSD2 roles required for the operation. The message names the missing role. |
NAME_NOT_CERTIFICATE_BACKED | The requested consent display name does not match the Organization (O) attribute in the leaf QWAC of any of the client’s current certificate chains. |
CLIENT_NOT_FOUND | No client matches the {clientId} in the request path, or the path does not match the subject of the access token. Ownership is determined by the token subject. |
CLIENT_INACTIVE | The client has been deactivated and can no longer be used or changed. |
CERTIFICATE_NOT_ASSOCIATED | The eIDAS certificate presented over mTLS is not one of the chains associated with the client. DELETE /tpp/{clientId} authorizes on the presented certificate this way. |
INTERNAL_ERROR | Something went wrong on our end. Retry with the same X-Request-ID. |
The HTTP status that accompanies a code depends on the endpoint. Each guide lists the statuses its endpoint returns — see Add or rotate a certificate for an example.
Display-name errors
A rejected consent display name carries the names you can use instead in possibleDisplayNames:
{
"code": "NAME_NOT_CERTIFICATE_BACKED",
"message": "display name is not backed by an associated certificate",
"possibleDisplayNames": ["Example TPP A/S"]
}Each entry is the Organization attribute of the leaf QWAC in one of your current certificate chains. See Manage consent display name.
Related documentation
- Get a management access token — how management requests are authorized
- Register as a third party provider — registration errors
Last updated on