XKOVA Docs

Errors and Correlation IDs

XKOVA returns a single, stable error envelope on every customer API failure. This catalog lists the 110 reviewed customer error codes by HTTP status. It is generated from the explicit customer manifest and canonical error metadata.

Every error response carries the same envelope: a stable code, a human readable message, an optional details object, and a correlation_id to quote when contacting support. The retry column states whether retrying can change the outcome.

Retry semantics

ValueMeaning
noneNot retryable. Retrying will not change the outcome.
immediateRetry right away, for example after a transient network blip.
headerWait the seconds given in the Retry-After response header.
detailsWait the seconds given in details.retry_after_seconds.

400 3

CodeRetryWhen it occurs
ramp_profile_not_allowednoThe requested funding profile is not allowed for this tenant.
sandbox_ramp_chain_not_supportednoSandbox dUSDC funding is not available on the requested chain.
sandbox_ramp_token_not_supportednoThe sandbox conversion partner only funds XKOVA dUSDC and never substitutes issuer USDC.

401 12

CodeRetryWhen it occurs
member_auth_refresh_replay_detectednoAn already rotated refresh credential was replayed, so its complete session family was revoked.
member_auth_session_revokednoThe exact member session is revoked or its authoritative binding is no longer valid.
member_auth_token_invalidnoThe identity proof, exchange token, refresh credential, or ceremony token is invalid or mismatched.
request_content_digest_mismatchnoThe signed content digest does not match the exact request body bytes.
request_signature_coverage_invalidnoThe signature does not cover every required request component.
request_signature_expiredyes (immediate)The signature is expired, too far in the future, or requests an excessive validity window.
request_signature_invalidnoThe request signature is malformed, unsupported, or failed verification.
request_signature_replayednoThe request signature nonce has already been accepted for this signing credential.
request_signature_requirednoThis production mutation requires an HTTP Message Signature.
request_signing_credential_inactivenoThe signing credential is not active for the authenticated customer principal.
unauthorizedyes (immediate)The request does not contain a valid authentication credential.
unauthorized_account_holdernoThe authenticated member context does not resolve to an authorized account holder.

402 1

CodeRetryWhen it occurs
relayer_exposure_limit_reachednoThe tenant has reached the limit for XKOVA-sponsored production writes.

403 20

CodeRetryWhen it occurs
authorization_deniednoThe workspace authorization policy denied this value movement.
compliance_blockednoCompliance policy blocked the requested value movement.
contacts_disablednoThe tenant has disabled the contacts capability.
feature_not_enablednoThe tenant does not have the requested capability enabled.
first_use_requiredyes (immediate)The member must accept the current required policies before this operation can proceed.
human_authorization_invalidnoThe exact human action authorization is expired, consumed, or does not match the actor, session, scope, origin, or request.
human_authorization_requirednoA fresh exact human authorization is required before this request can be retried.
member_auth_account_holder_inactivenoThe verified identity resolves to a member account that is not active.
member_auth_origin_not_allowlistednoThe request origin is not registered for this member-auth application.
member_security_setup_requirednoComplete initial passkey and saved recovery-code setup in Account Center before starting this Hosted member action. Login MFA alone does not complete setup.
not_a_treasury_signernoThe acting institution user is not an active signer for the selected treasury wallet.
production_access_deniednoThe tenant or workspace is not approved and ready for this production operation.
role_deniednoThe authenticated principal does not have the role required for this operation.
rwa_document_not_entitlednoThe requested grantee is not entitled to access this gated document.
step_up_requiredyes (immediate)This operation requires a customer credential created with the required higher assurance.
tenant_account_disablednoCustomer authentication is disabled for this tenant.
tenant_read_onlynoThe tenant is currently read-only and cannot accept this mutation.
tokenization_not_authorizednoThe customer credential is not authorized for this tokenization mutation.
treasury_role_deniednoThe acting institution user lacks the required treasury role.
verification_requirednoThe member must complete the required identity verification before this operation can proceed.

404 5

CodeRetryWhen it occurs
email_domain_not_foundnoThe requested sending domain does not exist or is not visible to this tenant.
not_foundnoThe requested resource does not exist or is not visible to this caller.
tokenization_access_registry_not_setnoThe token does not have an access registry.
tokenization_authority_not_foundnoThe requested token authority does not exist in this workspace.
treasury_wallet_not_foundnoThe requested treasury wallet does not exist or is not visible to this tenant.

409 23

CodeRetryWhen it occurs
asset_schema_fork_conflictnoThe requested asset schema key is already in use in this workspace.
attester_already_registerednoAn active attester is already registered for the same scope and address.
attester_revokednoThe requested attester registration has been revoked.
authorization_requires_approvalnoThe workspace policy requires an approval before this value movement can proceed.
compliance_case_openyes (immediate)An active compliance review currently prevents this transaction from proceeding.
conflict_statenoThe requested transition is not valid from the resource's current state.
earned_beneficiary_unsetnoThe workspace fee beneficiary is not ready for this value movement.
email_domain_conflictnoThe sending domain is already registered for this tenant.
idempotency_conflictnoThe idempotency key was already used with a different request body.
insufficient_fundsnoThe source account does not have enough funds for the requested debit.
invalid_statenoThe resource exists but is not in a state that permits this action.
permit_nonce_in_flightyes (header)Another payment from this wallet is still using the same token approval sequence.
rebind_invalid_statenoThe schema-rebind ceremony is not in the state required for this step.
signer_mpc_not_provisionedyes (details)One or more selected signers have not completed secure wallet provisioning.
token_already_boundnoThe token is already bound to a different published asset schema.
token_transfer_frozennoThe token is under an active transfer freeze.
tokenization_access_registry_existsnoThe token already has an access registry.
tokenization_authority_already_verifiednoThis token authority has already completed proof of control.
tokenization_invalid_state_transitionnoThe requested token lifecycle transition is not valid from its current state.
tokenization_operation_already_relayednoThe tokenization operation has already been submitted for execution.
tokenization_operation_pendingnoA conflicting tokenization operation is already pending.
treasury_safe_nonce_exhaustednoXKOVA could not safely reserve the next control-wallet transaction sequence.
workspace_setup_incompletenoComplete workspace setup before calling this chain-bound operation.

413 1

CodeRetryWhen it occurs
payload_too_largenoThe request body exceeds the supported size limit.

422 35

CodeRetryWhen it occurs
account_frozennoThe linked account cannot currently accept this operation because it is frozen, locked, or closed.
attester_scope_mismatchnoThe attester is not registered for the requested token scope.
attester_signature_mismatchnoThe submitted attestation signature does not match the registered attester.
chain_not_allowednoThe requested chain is not available for this workspace or conflicts with a referenced resource.
email_domain_invalidnoThe submitted sending domain is not valid.
flow_not_certifiednoThe exact asset and rail flow is not certified for this installation.
member_auth_redirect_url_not_allowlistednoThe callback or redirect URL is not registered for this member-auth application.
off_ramp_burn_unverifiednoThe supplied burn transaction could not be verified for the withdrawal.
rebind_attestation_invalidnoThe stored schema-rebind attestation no longer verifies against the proposal.
rebind_not_forward_onlynoA schema rebind must move to a later published version of the same asset schema.
role_not_allowed_for_service_accountnoThe requested token role cannot be assigned to a service-account authority.
rwa_document_hash_mismatchnoThe uploaded document does not match the declared content hash.
rwa_relationship_cyclenoThe requested asset relationship would create a cycle.
rwa_relationship_external_ref_invalidnoThe external asset relationship reference does not satisfy the schema policy.
rwa_relationship_target_not_foundnoThe requested asset relationship target could not be resolved.
rwa_schema_unsafenoThe asset schema did not pass the publication safety checks.
tokenization_authority_kind_mismatchnoThis proof operation is not valid for the selected authority kind.
tokenization_authority_not_verifiednoThe selected token authority has not completed proof of control.
tokenization_operation_not_signablenoThe submitted signature is not valid for the current tokenization operation.
tokenization_policy_exceedednoThe requested token mint exceeds the configured policy limit.
tokenization_policy_not_setnoNo active mint policy exists for this token and authority pair.
tokenization_proof_invalidnoThe submitted token-authority proof of control is invalid or expired.
tokenization_raw_call_invalidnoThe requested advanced token-control call is outside the allowed contract and function boundary.
tokenization_recover_target_activenoToken recovery cannot target an account that still has active access.
tokenization_relay_expirednoThe gasless token transfer request has expired.
tokenization_relay_invalid_signaturenoThe gasless token transfer signature does not match the request sender.
tokenization_relay_wrong_targetnoThe gasless token transfer request targets a different token contract.
tokenization_unknown_rolenoThe requested token role is not supported.
tokenization_unsupported_decimalsnoThe requested token decimal configuration is not supported.
transfer_eligibility_deniednoThe token transfer did not pass the configured holder eligibility checks.
treasury_chain_unsupportednoSecure institution wallet control is not supported on the requested chain.
treasury_signer_count_below_minimumnoThe requested signer set is too small for the selected approval threshold.
treasury_threshold_invalidnoThe requested approval threshold is invalid for the signer set.
unknown_eventnoThe requested webhook event type is not supported.
validation_failednoThe request body, path, or query parameters failed validation.

429 2

CodeRetryWhen it occurs
rate_limitedyes (header)The customer request rate limit was exceeded.
sandbox_ramp_daily_cap_exceedednoThe destination wallet has reached its daily sandbox funding limit.

500 1

CodeRetryWhen it occurs
internal_errornoXKOVA encountered an unexpected failure. Use the correlation ID when contacting support.

502 1

CodeRetryWhen it occurs
integration_gateway_erroryes (immediate)The institution's Integration Gateway could not complete the requested operation.

503 5

CodeRetryWhen it occurs
core_banking_outageyes (header)The institution's authoritative account service is temporarily unavailable.
relayer_exposure_evidence_unavailableyes (immediate)XKOVA could not establish the current evidence needed to authorize a sponsored production write.
service_unavailableyes (header)XKOVA is temporarily unavailable. Retry according to the response metadata.
tenant_suspendednoThe tenant is currently suspended.
wallet_monitoring_not_readyyes (header)The member wallet exists, but its external transaction monitoring is still catching up. Retry after the response interval.

504 1

CodeRetryWhen it occurs
core_banking_timeoutyes (header)The institution's authoritative account service did not respond in time.