Skip to content
APIAgent-ready

Every authentication failure now has the same machine-readable fields

Every 401 response now carries a code, message and retryable flag, so agents can handle auth failures the same way everywhere.

A 401 used to look different depending on which endpoint answered it: some sent a plain error string, others a nested error object. Every 401 now also carries three top-level fields, whatever the endpoint:

  • code: invalid_credentials when the credential you sent was rejected (an expired token, an unknown API key, a bad signature), or unauthorized when none was sent or it is not the kind that endpoint accepts.
  • message: the same text as before.
  • retryable: always false. Retrying without a different credential gets the same answer.

The existing error field is unchanged, so integrations that read it keep working. 401 responses also carry a WWW-Authenticate: Bearer realm="last-price" challenge. The discovery document and the API reference describe the shape.