Skip to main content
For 401, confirm the complete bearer token is active and sent in the header. For 403, compare the operation’s permission with API Access. For 404, verify the tenant is returned by /tenants and the resource belongs to it. For 422, inspect the field errors and supported include values. For 429, slow down and retry with backoff. When escalating, provide the operation, approximate time, tenant identifier, response status, and X-Request-Id. Never send a token, QR token, redemption token, or customer export.