Success. A transfer create whose Idempotency-Key was already used also answers 200, with the transfer it created.
201
Created: a customer, a wallet, a case, a note, a webhook subscription, a rule or a threshold; a provider or integration saved for the first time; a transfer completed at once below the Travel Rule threshold.
202
Accepted, with work still to do: a queued transfer, or an action on a transfer's information requests.
204
An OPTIONS request.
400
The request cannot be used as it is: an unreadable query, body or cursor, a missing or invalid field, an unknown action, or a transfer state the action does not apply to.
401
The API key is missing, malformed, unknown or revoked.
403
The key lacks the scope, or its owner's role the permission; the change needs a live key; the company is suspended or its plan lacks the feature; or the request carried the dashboard's session cookie.
404
The path does not exist, the host names no company, or the record is not in the key's environment.
405
The path does not take the method. Allow lists the methods it takes.
409
The request conflicts with the record's current state: a duplicate, a concurrent change, a closed case, a blocked erasure, a connection with no saved credentials.
413
The body is over 64 KiB.
422
A well-formed body that a case, rule, threshold, webhook, provider or integration does not accept, or a link to a record that does not exist.
429
A rate limit or the company's usage limit. Retry-After says when to try again.
500
An unexpected error. The answer says nothing more.
503
Temporarily unavailable: a lookup timed out, encrypted data cannot be read just now, the company is not ready, or a provider failed. Retry-After is sent when a retry may succeed.
VALIDATION_ERROR is 400 on customers, wallets and transfers, and 422 on cases, rules, thresholds, webhooks, providers and integrations.
The key is not in the issued format: covalence_pk_ and 64 hexadecimal characters.
401
KEY_NOT_FOUND
No key of this company matches. A key of another company is not found either.
401
KEY_REVOKED
The key was revoked, or its owner lost access: their membership ended, their account was disabled, their role no longer allows the key's environment, or the company's access to API keys is unavailable.
403
INSUFFICIENT_SCOPE
The key lacks the endpoint's scope. The message names it.
403
INSUFFICIENT_PERMISSION
The key's owner's role lacks the permission the action needs, or the action needs a second scope (a suspicion report needs strs:read, a report download transfers:read).
403
CSRF_VALIDATION_FAILED
A POST, PUT, PATCH or DELETE carried the dashboard's session cookie.
403
TENANT_SUSPENDED
The company is suspended.
403
TENANT_FEATURE_DISABLED
The company's plan does not include the feature or the provider.
404
NOT_FOUND
The path does not exist, or the host names no company.
405
METHOD_NOT_ALLOWED
The path does not take the method.
400
INVALID_JSON
The body is not JSON.
413
BODY_TOO_LARGE
The body is over 65,536 bytes.
400
VALIDATION_ERROR
Text with a NUL character (U+0000) in the path, the query or the body.
400
INVALID_QUERY
A query the list or search cannot read, or a parameter it does not take. details.issues names each problem.
400
INVALID_CURSOR
A cursor that the list did not hand out, such as an item's ID.
409
CONFLICT
Another request changed the same record at the same time. Retry.
A create body that fails validation (details.validationErrors, details.schemaName: "create-transfer"), an asset disabled in the environment, an originator customer or address that does not match, an originator without a country, or no provider able to route the transfer. An accept with a txHash that is not a transaction hash. A reject body that fails validation (details.validationErrors).
400
MISSING_REQUIRED_FIELD
A reject or retry without a reason. details.field is reason.
400
INVALID_REQUEST
No action, or one the endpoint does not take: details.allowedActions lists accept, reject and retry. Also an action the transfer's workflow refuses; the message says why.
400
INVALID_TRANSFER_STATE
A retry of a transfer that is not failed or held. details has currentState, action and allowedStates.
404
TRANSFER_NOT_FOUND
No such transfer in the key's environment, whatever the action. details has resource and id.
409
CONFLICT
Two creates collided, and the transfer could not be matched to an Idempotency-Key.
503
TIMEOUT
The create's price or threshold lookup timed out. Retry-After: 5.
400
INVALID_INFORMATION_REQUEST
An information request action that is not valid. details.issues names each problem.
Provider's
Provider's code
An information request the provider refused. Its 400, 404 and 409 keep their status; any other refusal is 503. The code is the provider's (HTTP_502, for one).
Wait for Retry-After before retrying a 429 or 503.
Retry a 409 CONFLICT as it is: another change won the race.
Send POST /api/v2/transfers with an Idempotency-Key: a retry with the same key answers 200 with the transfer the first request created, and never creates a second one.
Do not retry other 4xx answers unchanged: fix the request first.