Auth API in Duo Format
Every failure answers {"stat": "FAIL", "code": …, "message": …} with the HTTP status equal to the first three digits of code. message_detail names the parameter at fault, when there is one.
| Code | HTTP | message | Meaning |
|---|---|---|---|
40001 | 400 | Missing required request parameters | A required parameter is missing. message_detail names it. |
40002 | 400 | Invalid request parameters | A parameter value is invalid, the user is unknown, or factor is sms/phone. message_detail names the parameter. |
40101 | 401 | Missing request credentials | No Authorization header, or it is not Basic ikey:signature. |
40102 | 401 | Invalid integration key in request credentials | Unknown integration key, or the integration was revoked. |
40103 | 401 | Invalid signature in request credentials | The signature does not match. See Signing Requests. |
40104 | 401 | Missing request timestamp | No Date header, or it is not an RFC 2822 date. |
40105 | 401 | Request timestamp is too far from the server time | The Date header is more than 5 minutes off the server clock. Sync your clock (NTP). |
40106 | 401 | Invalid content type in request | POST must be application/x-www-form-urlencoded (v2) or application/json (v5). |
40401 | 404 | Resource not found | Unknown path. |
40501 | 405 | Method not allowed | Wrong HTTP method for this path (the Allow header names the right one). |
41301 | 413 | Request entity too large | Request body over 128 KiB. |
42901 | 429 | Too many requests | A rate limit was hit. Wait as long as the Retry-After header says. |
50001 | 500 | Internal server error | An unexpected server error. Try again later. |
50301 | 503 | Service temporarily unavailable | The database or the server encryption key is unavailable. |
Result and Status Values
Answers of auth without async, and of auth_status:
| result | status | Meaning |
|---|---|---|
waiting | pushed | The request was sent and not answered yet. Call auth_status again. |
allow | allow | Approved on the phone, or the backup code was right. Let the user in. |
deny | deny | Denied, cancelled, a wrong code, no phone signed in to WiraPass, or paused. status_msg explains. |
deny | fraud | The user pressed "Not me". Deny access and alert your administrators. |
deny | timeout | Not answered within 60 seconds. |
deny | locked_out | The backup code is locked after too many wrong tries. |
Only allow means yes. Treat unknown values as deny.
Simple JSON API
Failures answer {"error": "<CODE>", "message": "…"}.
| Code | HTTP | Meaning |
|---|---|---|
UNAUTHORIZED | 401 | The API key is unknown, malformed or revoked. |
INVALID_EMAIL | 400 | The email is not valid. |
NOT_FOUND | 404 | Unknown request, or another integration's. |
NOT_ENROLLED | 404 | The user has no active approval phone. |
NO_SIGNED_IN_DEVICE | 409 | No approval phone is signed in to WiraPass. Use a backup code. |
FROZEN | 429 | The user pressed "Not me"; requests are paused until until. |
TOO_MANY_PENDING | 429 | 3 requests are already waiting for an answer. |
RATE_LIMITED | 429 | A rate limit was hit; see retryAfterSec and Retry-After. |
WRONG_CODE | 401 | The backup code is wrong or was already used. |
CODE_LOCKED | 423 | The backup code is locked after 10 wrong tries; the user creates a new one on an active phone. |
Request statuses: pending, approved, denied, reported, expired, cancelled. Only approved means yes; reported means Not me.