message, and usually an error name and statusCode. Handle them by status, and read message for detail.
Status reference
Observed examples
401 — missing, wrong, or Bearer-prefixed key
404 — no verified asset at that address
400 — badge parameter outside its allowed values
404 — KYI token lookup, no match (normal body shape)
Handling guidance
- Retry
500and502with exponential backoff. Everything else is a caller bug or a real “not found” — don’t retry it. - Treat
404as data, not failure: a token that isn’t verified should come back 404. Show an “unverified” state, not an error state. - The KYI-tokens
404still returns a usable body (kyi_verified: false), so check the status code and the payload.
FAQ
Why 401 when my key is definitely correct?
Why 401 when my key is definitely correct?
Check for a
Bearer prefix — it’s the most common cause. The key must be the entire header value. Also check for stray whitespace or quotes around the key.Is there a rate-limit error?
Is there a rate-limit error?
No
429 or rate-limit headers were observed. See Limits, caching and versions.Related
- Authentication — the
Bearermistake that causes most 401s - Token KYI lookup — the query-form 400s