API Documentation

Error Codes

What every error code and every result and status value means.

Documentation Pages

Auth API in Duo Format

Every failure answers {"stat": "FAIL", "code": …, "message": …} with the HTTP status equal to the first three digits of code. message_detail names the parameter at fault, when there is one.

CodeHTTPmessageMeaning
40001400Missing required request parametersA required parameter is missing. message_detail names it.
40002400Invalid request parametersA parameter value is invalid, the user is unknown, or factor is sms/phone. message_detail names the parameter.
40101401Missing request credentialsNo Authorization header, or it is not Basic ikey:signature.
40102401Invalid integration key in request credentialsUnknown integration key, or the integration was revoked.
40103401Invalid signature in request credentialsThe signature does not match. See Signing Requests.
40104401Missing request timestampNo Date header, or it is not an RFC 2822 date.
40105401Request timestamp is too far from the server timeThe Date header is more than 5 minutes off the server clock. Sync your clock (NTP).
40106401Invalid content type in requestPOST must be application/x-www-form-urlencoded (v2) or application/json (v5).
40401404Resource not foundUnknown path.
40501405Method not allowedWrong HTTP method for this path (the Allow header names the right one).
41301413Request entity too largeRequest body over 128 KiB.
42901429Too many requestsA rate limit was hit. Wait as long as the Retry-After header says.
50001500Internal server errorAn unexpected server error. Try again later.
50301503Service temporarily unavailableThe database or the server encryption key is unavailable.

Result and Status Values

Answers of auth without async, and of auth_status:

resultstatusMeaning
waitingpushedThe request was sent and not answered yet. Call auth_status again.
allowallowApproved on the phone, or the backup code was right. Let the user in.
denydenyDenied, cancelled, a wrong code, no phone signed in to WiraPass, or paused. status_msg explains.
denyfraudThe user pressed "Not me". Deny access and alert your administrators.
denytimeoutNot answered within 60 seconds.
denylocked_outThe backup code is locked after too many wrong tries.

Only allow means yes. Treat unknown values as deny.

Simple JSON API

Failures answer {"error": "<CODE>", "message": "…"}.

CodeHTTPMeaning
UNAUTHORIZED401The API key is unknown, malformed or revoked.
INVALID_EMAIL400The email is not valid.
NOT_FOUND404Unknown request, or another integration's.
NOT_ENROLLED404The user has no active approval phone.
NO_SIGNED_IN_DEVICE409No approval phone is signed in to WiraPass. Use a backup code.
FROZEN429The user pressed "Not me"; requests are paused until until.
TOO_MANY_PENDING4293 requests are already waiting for an answer.
RATE_LIMITED429A rate limit was hit; see retryAfterSec and Retry-After.
WRONG_CODE401The backup code is wrong or was already used.
CODE_LOCKED423The backup code is locked after 10 wrong tries; the user creates a new one on an active phone.

Request statuses: pending, approved, denied, reported, expired, cancelled. Only approved means yes; reported means Not me.

Duo is a trademark of Cisco. WiraPass is not affiliated with Duo or Cisco and only offers API compatibility.