Skip to Content
RegistrationError responses

Error responses

Registration and client-management endpoints return failures as a JSON object with a machine-readable code and a human-readable message:

{ "code": "ROLE_NOT_ALLOWED", "message": "certificate does not contain role PSP_PI" }

Branch on code. The message explains the failure for logs and support conversations and can change without notice.

The Error schema is part of the registration API specification.

Error codes

CodeMeaning
INVALID_REQUESTThe request body or a parameter is missing, malformed, or fails validation.
INVALID_CERTIFICATE_CHAINThe supplied certificate value could not be read as a PEM chain from leaf to root.
CERTIFICATE_VALIDATION_FAILEDThe certificate chain is not a valid, trusted eIDAS QWAC. See Security model.
ROLE_NOT_ALLOWEDThe certificate does not assert the PSD2 roles required for the operation. The message names the missing role.
NAME_NOT_CERTIFICATE_BACKEDThe requested consent display name does not match the Organization (O) attribute in the leaf QWAC of any of the client’s current certificate chains.
CLIENT_NOT_FOUNDNo client matches the {clientId} in the request path, or the path does not match the subject of the access token. Ownership is determined by the token subject.
CLIENT_INACTIVEThe client has been deactivated and can no longer be used or changed.
CERTIFICATE_NOT_ASSOCIATEDThe eIDAS certificate presented over mTLS is not one of the chains associated with the client. DELETE /tpp/{clientId} authorizes on the presented certificate this way.
INTERNAL_ERRORSomething went wrong on our end. Retry with the same X-Request-ID.

The HTTP status that accompanies a code depends on the endpoint. Each guide lists the statuses its endpoint returns — see Add or rotate a certificate for an example.

Display-name errors

A rejected consent display name carries the names you can use instead in possibleDisplayNames:

{ "code": "NAME_NOT_CERTIFICATE_BACKED", "message": "display name is not backed by an associated certificate", "possibleDisplayNames": ["Example TPP A/S"] }

Each entry is the Organization attribute of the leaf QWAC in one of your current certificate chains. See Manage consent display name.

Last updated on