Error catalogue

Every problem type the API returns (RFC 9457 application/problem+json). Branch on code; type is https://api.banking.wirebloom.com/problems/{slug}. See Errors for handling and retries.

StatusCodeTitleRetryableWhat it means
400bad_requestBad requestNoThe request is malformed (syntax, unknown parameter or body that is not JSON).
400invalid_cursorInvalid cursorNoThe pagination cursor is invalid or belongs to another sort / filter.
400refresh_token_reusedRefresh token reusedNoToken endpoint: a rotated refresh token was presented again and its family was revoked (errors[0].code=invalid_grant).
400unknown_filterUnknown filterNoA filter[...] parameter names a field the operation does not filter on.
401invalid_api_keyInvalid API keyNoThe API key is unknown, revoked or past expiresAt.
401invalid_credentialsInvalid credentialsNoLogin failed (interactive sign-in only).
401invalid_signatureInvalid signatureNoAn inbound webhook signature did not verify.
401mfa_requiredMulti-factor authentication requiredNoMulti-factor verification is required to finish signing in (interactive only).
401session_expiredSession expiredNoThe interactive session expired; sign in again.
401unauthenticatedAuthentication requiredNoNo valid credentials: send Authorization: Bearer <key>.
403access_rejectedAccess rejectedNoThe customer's registration access was rejected by staff (customer registration, spec 2026-09-28); the account cannot sign in until it is reversed.
403dual_controlDual control requiredNoThe action needs a second person (four-eyes) to approve it.
403forbiddenForbiddenNoThe caller lacks the capability the operation requires.
403impersonation_restrictedNot allowed while impersonatingNoStaff impersonating a user may not perform this action.
403insufficient_scopeInsufficient scopeNoThe API key does not carry a scope listed in the operation's x-api-key-scopes.
403ip_not_allowedIP address not allowedNoThe request came from an address outside the key's ipAllowlist.
403reason_requiredAccess reason requiredNoPlatform staff must give an access reason for this tenant.
403step_up_requiredStep-up authentication requiredNoA fresh step-up verification is required for this action (sessions only; API keys skip step-up).
403tenant_forbiddenTenant not allowedNoX-Tenant-Id names a tenant the credentials are not bound to.
403terms_outdatedTerms acceptance requiredNoThe user must accept the current terms first.
404feature_disabledFeature disabledNoThe feature is not enabled for this operator or environment (for example sandbox simulations in production).
404not_foundNot foundNoThe resource does not exist or belongs to another tenant (existence is never revealed).
405method_not_allowedMethod not allowedNoThe path exists but not with this HTTP method.
409activation_blockedActivation checklist incompleteNoA banking connection cannot be activated while a blocking checklist step is open.
409conflictConflictNoGeneric conflict with the current state when no specific 409 type applies.
409connection_in_useConnection in useNoA banking connection still holds balances, settlement money, in-flight items or active mandates.
409domain_not_approvedEmail domain not approvedNoThe email domain is not on the customer's approved list.
409duplicate_recipientDuplicate recipientNoA recipient with the same bank details already exists.
409funds_requests_disabledFunds requests disabledNoFunds requests are disabled for this customer.
409idempotency_key_in_useIdempotency key in useYesA request with the same Idempotency-Key is still running; retry after Retry-After.
409insufficient_fundsInsufficient fundsNoThe balance cannot cover the amount plus fees.
409invalid_transitionInvalid state transitionNoThe resource is not in a state that allows this action.
409last_mfa_factorLast MFA factorNoThe last MFA factor of a user cannot be removed.
409not_cancellableNot cancellableNoThe resource can no longer be cancelled.
409onboarding_not_openOnboarding not openNoOnboarding is not open yet: the operator's onboarding mode is prepare (customer registration, spec 2026-09-28), so KYB submission and identity verification wait until launch.
409primary_owner_protectedPrimary owner protectedNoThe primary owner cannot be removed or demoted.
409provider_unsupportedNot available on this banking connectionNoThe operator's active banking connection does not offer this feature (for example open-banking consents or provider costs on a partner that lacks them); do not retry.
409quote_expiredQuote expiredNoThe FX quote expired; request a new quote and retry with it.
412precondition_failedPrecondition failedNoIf-Match does not match the current ETag: re-read the resource and apply your change again.
413payload_too_largePayload too largeNoThe request body exceeds the limit (1 MiB for JSON).
415unsupported_media_typeUnsupported media typeNoSend Content-Type: application/json (or the media type the operation documents).
422currency_not_enabledCurrency not enabledNoThe currency is not enabled for this customer or operator.
422document_not_cleanDocument not cleanNoThe document has not passed the malware scan (yet).
422idempotency_key_reusedIdempotency key reusedNoThe Idempotency-Key was used within 24 h with a different body.
422limit_exceededLimit exceededNoThe operation exceeds a payment or customer limit.
422recipient_not_approvedRecipient not approvedNoPayments need an approved recipient.
422validation_errorValidation failedNoOne or more fields are invalid; see errors[] (JSON Pointer field, code, message).
422verification_unavailableVerification unavailableNoAccount-holder verification is not available for this destination.
428precondition_requiredPrecondition requiredNoUpdates of versioned resources need If-Match with the ETag from your last read.
429rate_limitedToo many requestsYesToo many requests for the key's bucket; wait for Retry-After and back off with jitter.
500internal_errorInternal errorYesUnexpected server error; retry with the same Idempotency-Key and quote requestId if it persists.
501not_implementedNot implementedNoThe routed banking partner does not offer the operation (for example a recall on a rail without recalls).
502provider_errorProvider errorYesThe banking partner returned an error; retry with the same Idempotency-Key.
503service_unavailableService unavailableYesThe service is temporarily unavailable; retry with backoff.
504provider_timeoutProvider timeoutYesThe banking partner did not answer in time; retry with the same Idempotency-Key.