Skip to content
You are reading the unreleased documentation. No version is released yet, and these pages describe code that is not in a release.

Error codes

Every error answers { "error": { "code", "message", "details"? } } with the HTTP status of the exception. The codes below are read from the exception sites in the code. A validation failure carries VALIDATION_ERROR with one entry per field in details.

Thrown by the framework or by an exception raised without an explicit code; the code follows the HTTP status.

  • BAD_REQUEST: 400
  • UNAUTHORIZED: 401
  • FORBIDDEN: 403
  • NOT_FOUND: 404
  • CONFLICT: 409
  • UNPROCESSABLE_ENTITY: 422
  • RATE_LIMITED: 429
  • INTERNAL_SERVER_ERROR: 500

A Prisma error the filter maps before it reaches the client.

  • Prisma P2002: CONFLICT, 409. A record with this value already exists.
  • Prisma P2003: CONFLICT, 409. Cannot delete, record is still referenced by another entity.
  • Prisma P2025: NOT_FOUND, 404. The requested record was not found.

HTTP 403.

  • Access denied
  • Thrown in apps/api/src/modules/users/users.service.ts.

HTTP 400.

  • At least one of isDefaultShipping or isDefaultBilling must be true
  • Thrown in apps/api/src/modules/users/address-default-flag-required.exception.ts.

HTTP 404.

  • Address not found
  • Thrown in apps/api/src/modules/users/users.service.ts.

HTTP 400.

  • One or more asset IDs are invalid
  • Thrown in apps/api/src/modules/reviews/asset-invalid.exception.ts.

HTTP 403.

  • Insufficient permissions
  • Thrown in apps/api/src/modules/auth/auth-permission-insufficient.exception.ts.

HTTP 401.

  • Authentication required
  • Thrown in apps/api/src/common/session-auth.guard.ts.

HTTP 401.

  • Account is deactivated
  • Thrown in apps/api/src/common/session-auth.guard.ts.

HTTP 400.

  • Request could not be completed.
  • Thrown in apps/api/src/common/bot-protection/bot-protection.guard.ts.

HTTP 400.

  • Coupon ”${couponCode}” is not an active promotion.
  • Thrown in apps/api/src/modules/campaigns/campaign.service.ts.

HTTP 409.

  • A ${campaign.status} campaign cannot be edited.
  • Thrown in apps/api/src/modules/campaigns/campaign.service.ts.

HTTP 409.

  • A ${campaign.status} campaign cannot be sent.
  • This campaign is already sending or sent.
  • Thrown in apps/api/src/modules/campaigns/campaign.service.ts.

HTTP 400.

  • Captcha verification failed.
  • Thrown in apps/api/src/common/bot-protection/bot-protection.guard.ts.

HTTP 400.

  • Captcha verification is required.
  • Thrown in apps/api/src/common/bot-protection/bot-protection.guard.ts.

HTTP 400.

  • Cart is empty
  • Thrown in apps/api/src/modules/cart/cart.service.ts.

HTTP 400.

  • Cart identity required (userId or sessionId)
  • Thrown in apps/api/src/modules/cart/cart.service.ts.

HTTP 400.

  • Insufficient stock for the requested quantity
  • Thrown in apps/api/src/modules/cart/cart-insufficient-stock.exception.ts.

HTTP 404.

  • Cart item ”${itemId}” not found
  • Thrown in apps/api/src/modules/cart/cart.service.ts.

HTTP 404.

  • Cart not found
  • Thrown in apps/api/src/modules/cart/cart.service.ts.

HTTP 404.

  • Product variant not found or unavailable
  • Thrown in apps/api/src/modules/cart/cart-variant-not-found.exception.ts.

HTTP 409.

  • Cannot set a descendant as parent
  • Thrown in apps/api/src/modules/categories/categories.service.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/categories/category-not-found.exception.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/categories/category-parent-not-found.exception.ts.

HTTP 400.

  • Invalid coupon
  • Thrown in apps/api/src/modules/promotions/coupon-invalid.exception.ts.

HTTP 409.

  • Email already in use
  • Thrown in apps/api/src/modules/users/users.service.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/users/customer-not-found.exception.ts.

HTTP 400.

  • Thrown in apps/api/src/modules/gift-cards/gift-card-amount-invalid.exception.ts.

HTTP 400.

  • Gift card code ”${code}” is already in use
  • Thrown in apps/api/src/modules/gift-cards/gift-cards.service.ts.

HTTP 400.

  • Currency ”${currency}” is not enabled for this store
  • Thrown in apps/api/src/modules/gift-cards/gift-card-currency-not-enabled.exception.ts.

HTTP 400.

  • Thrown in apps/api/src/modules/gift-cards/gift-card-deactivated.exception.ts.

HTTP 400.

  • Thrown in apps/api/src/modules/gift-cards/gift-card-insufficient-balance.exception.ts.

HTTP 400.

  • Invalid or expired gift card
  • Thrown in apps/api/src/modules/gift-cards/gift-card-invalid.exception.ts.

HTTP 400.

  • Gift card has no recipient email on file
  • Thrown in apps/api/src/modules/gift-cards/gift-cards.service.ts.

HTTP 404.

  • Gift card ”${id}” not found
  • Thrown in apps/api/src/modules/gift-cards/gift-card-not-found.exception.ts.

HTTP 409.

  • X-Idempotency-Key was previously used with a different request body.
  • Thrown in apps/api/src/common/exceptions/idempotency.exception.ts.

HTTP 403.

  • X-Idempotency-Key was previously used by another caller.
  • Thrown in apps/api/src/common/exceptions/idempotency.exception.ts.

HTTP 400.

  • X-Idempotency-Key must be a UUID v4 string.
  • Thrown in apps/api/src/common/exceptions/idempotency.exception.ts.

HTTP 400.

  • X-Idempotency-Key header is required for this endpoint.
  • Thrown in apps/api/src/common/exceptions/idempotency.exception.ts.

HTTP 400.

  • The unsubscribe link is invalid or has expired.
  • Thrown in apps/api/src/modules/mail/unsubscribe.controller.ts.

HTTP 400.

  • Webhook URL is not a valid URL
  • Thrown in apps/api/src/modules/webhooks/webhooks.utils.ts.

HTTP 400.

  • Thrown in apps/api/src/modules/inventory/inventory-adjust-mode.exception.ts.

HTTP 400.

  • Cannot set stock to ${setTo}: ${reserved} unit(s) are already reserved
  • Thrown in apps/api/src/modules/inventory/inventory-set-below-reserved.exception.ts.

HTTP 409.

  • Stock changed since this screen was opened
  • Thrown in apps/api/src/modules/inventory/inventory-stock-conflict.exception.ts.

HTTP 400.

  • attach the license file as file
  • Thrown in apps/api/src/modules/license/license.controller.ts.

HTTP 400.

  • this engine has no ${LICENSE_FILE_ENV} path configured, so there is nowhere to install a license
  • Thrown in apps/api/src/modules/license/license.service.ts.

HTTP 400.

  • Thrown in apps/api/src/modules/license/license.service.ts.

HTTP 400.

  • the license verified but could not be written (${code})
  • Thrown in apps/api/src/modules/license/license.service.ts.

HTTP 404.

  • Address ”${addressId}” not found
  • Thrown in apps/api/src/modules/orders/orders.service.ts.

HTTP 409.

  • Thrown in apps/api/src/modules/orders/order-cancel-ineligible.exception.ts.

HTTP 409.

  • This order has a shipment in transit and cannot be cancelled. Use the return flow instead.
  • Thrown in apps/api/src/modules/orders/order-cancel-shipment-in-transit.exception.ts.

HTTP 400.

  • Cart is empty
  • Thrown in apps/api/src/modules/orders/order-cart-empty.exception.ts.

HTTP 400.

  • Customer not found
  • Thrown in apps/api/src/modules/orders/orders.service.ts.

HTTP 409.

  • Thrown in apps/api/src/modules/orders/order-edit-insufficient-stock.exception.ts.

HTTP 404.

  • Order item ”${removal.orderItemId}” not found
  • Thrown in apps/api/src/modules/orders/orders.service.ts.

HTTP 404.

  • Variant ”${addItem.variantId}” not found
  • Thrown in apps/api/src/modules/orders/orders.service.ts.

HTTP 400.

  • A shipping address is required to check out as a guest
  • Thrown in apps/api/src/modules/orders/order-guest-address-required.exception.ts.

HTTP 403.

  • Guest checkout is not available
  • Thrown in apps/api/src/modules/orders/order-guest-checkout-disabled.exception.ts.

HTTP 400.

  • A contact email is required to check out as a guest
  • Thrown in apps/api/src/modules/orders/order-guest-email-required.exception.ts.

HTTP 400.

  • A cart session is required to check out as a guest
  • Thrown in apps/api/src/modules/orders/order-guest-session-required.exception.ts.

HTTP 409.

  • Order creation already in progress for this idempotency key
  • Thrown in apps/api/src/modules/orders/order-idempotency-in-flight.exception.ts.

HTTP 409.

  • Thrown in apps/api/src/modules/orders/order-insufficient-stock.exception.ts.

HTTP 404.

  • Invoice not yet generated
  • Thrown in apps/api/src/modules/orders/order-invoice-not-ready.exception.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/orders/order-not-found.exception.ts.

HTTP 403.

  • Not your order
  • Thrown in apps/api/src/modules/orders/order-not-yours.exception.ts.

HTTP 400.

  • Thrown in apps/api/src/modules/orders/order-payment-method-invalid.exception.ts.

HTTP 400.

  • No payment method is available
  • Thrown in apps/api/src/modules/orders/order-payment-method-unavailable.exception.ts.

HTTP 400.

  • Item ”${si.orderItemId}” does not belong to this order
  • Thrown in apps/api/src/modules/orders/orders.service.ts.

HTTP 404.

  • Shipment ”${shipmentId}” not found for order ”${orderId}”
  • Thrown in apps/api/src/modules/orders/orders.service.ts.

HTTP 409.

  • Thrown in apps/api/src/modules/orders/order-shipment-order-closed.exception.ts.

HTTP 400.

  • Shipping address is required
  • Thrown in apps/api/src/modules/orders/orders.service.ts.

HTTP 400.

  • Cannot transition from ${order.status} to ${newStatus}
  • Thrown in apps/api/src/modules/orders/orders.service.ts.

HTTP 400.

  • Order in ${order.status} status cannot be edited
  • Thrown in apps/api/src/modules/orders/orders.service.ts.

HTTP 400.

  • Variant ”${item.variantId}” not found or unavailable
  • Thrown in apps/api/src/modules/orders/orders.service.ts.

HTTP 403.

  • @OwnerGuard route cannot also be @Public()
  • Thrown in libs/shared/common/src/guards/owner-guard.exceptions.ts.

HTTP 401.

  • Authenticated user required
  • Thrown in libs/shared/common/src/guards/owner-guard.exceptions.ts.

HTTP 409.

  • Product is already archived
  • Thrown in apps/api/src/modules/products/products.service.ts.

HTTP 404.

  • Archived product not found
  • Thrown in apps/api/src/modules/products/products.service.ts.

HTTP 400.

  • Only one asset can be marked as primary
  • Thrown in apps/api/src/modules/products/products.service.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/products/product-attribute-not-found.exception.ts.

HTTP 409.

  • Value code ”${code}” already exists in this attribute
  • Thrown in apps/api/src/modules/products/product-attribute-value-code-taken.exception.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/products/product-attribute-value-not-found.exception.ts.

HTTP 400.

  • Thrown in apps/api/src/modules/products/product-category-not-found.exception.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/products/product-faq-not-found.exception.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/products/product-not-found.exception.ts.

HTTP 409.

  • SKU ”${sku}” is already in use
  • Thrown in apps/api/src/modules/products/product-sku-taken.exception.ts.

HTTP 409.

  • Slug ”${slug}” is already taken
  • Thrown in apps/api/src/modules/products/product-slug-taken.exception.ts.

HTTP 400.

  • Specifications ${labels.map((l) => "${l}").join(’ and ’)} are the same specification
  • Thrown in apps/api/src/modules/products/product-spec-duplicate-key.exception.ts.

HTTP 400.

  • Thrown in apps/api/src/modules/products/product-spec-empty-key.exception.ts.

HTTP 409.

  • Product type code ”${code}” already exists
  • Thrown in apps/api/src/modules/products/product-type-code-taken.exception.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/products/product-type-not-found.exception.ts.

HTTP 409.

  • Cannot delete the last active variant
  • Thrown in apps/api/src/modules/products/products.service.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/products/product-variant-not-found.exception.ts.

HTTP 401.

  • Current password is incorrect
  • Thrown in apps/api/src/modules/users/profile-current-password-incorrect.exception.ts.

HTTP 400.

  • Current password is required to change email, phone, or password
  • Thrown in apps/api/src/modules/users/profile-current-password-required.exception.ts.

HTTP 409.

  • Email already in use
  • Thrown in apps/api/src/modules/users/profile-email-in-use.exception.ts.

HTTP 409.

  • This question has already been answered
  • Thrown in apps/api/src/modules/reviews/question-already-answered.exception.ts.

HTTP 400.

  • This question is not available for answers
  • Thrown in apps/api/src/modules/reviews/question-not-available.exception.ts.

HTTP 409.

  • You have already submitted a review for this product
  • Thrown in apps/api/src/modules/reviews/review-duplicate.exception.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/reviews/review-not-found.exception.ts.

HTTP 403.

  • Not your review
  • Thrown in apps/api/src/modules/reviews/review-not-owned.exception.ts.

HTTP 404.

  • Product ”${slug}” not found
  • Thrown in apps/api/src/modules/reviews/review-product-not-found.exception.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/reviews/review-question-not-found.exception.ts.

HTTP 400.

  • A verified purchase is required to leave a review
  • Thrown in apps/api/src/modules/reviews/review-eligibility.exception.ts.

HTTP 409.

  • Role name already exists
  • Thrown in apps/api/src/modules/users/users.service.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/users/role-not-found.exception.ts.

HTTP 400.

  • url must be on the public storefront origin.
  • Thrown in apps/api/src/modules/seo/seo-submit.exceptions.ts.

HTTP 400.

  • Provide exactly one inspection target: url or productId — not both.
  • Thrown in apps/api/src/modules/seo/seo-inspect.exceptions.ts.

HTTP 400.

  • Provide exactly one submit target: url, productIds, or sitemap — not several.
  • Thrown in apps/api/src/modules/seo/seo-submit.exceptions.ts.

HTTP 400.

  • None of the requested engines can be submitted to for this target type.
  • Thrown in apps/api/src/modules/seo/seo-submit.exceptions.ts.

HTTP 400.

  • An inspection target is required: one of url or productId.
  • Thrown in apps/api/src/modules/seo/seo-inspect.exceptions.ts.

HTTP 400.

  • A submit target is required: one of url, productIds, or sitemap.
  • Thrown in apps/api/src/modules/seo/seo-submit.exceptions.ts.

HTTP 400.

  • currencyConfig must be an object with a code
  • Thrown in apps/api/src/modules/settings/settings.service.ts.

HTTP 400.

  • defaultLocale must be one of the supportedLocales
  • Thrown in apps/api/src/modules/settings/settings.service.ts.

HTTP 400.

  • ${key} is written by the license verification, not through settings
  • Thrown in apps/api/src/modules/settings/settings.service.ts.

HTTP 400.

  • the engine ships no strings for ${foreign.join(’, ’)} (catalogue: ${LOCALE_CATALOGUE.join(’, ’)})
  • Thrown in apps/api/src/modules/settings/settings.service.ts.

HTTP 400.

  • decimalSeparator and thousandsSeparator must differ
  • Thrown in apps/api/src/modules/settings/settings.service.ts.

HTTP 400.

  • rtlLocales must be a subset of supportedLocales (${outside.join(’, ’)})
  • Thrown in apps/api/src/modules/settings/settings.service.ts.

HTTP 400.

  • Selected shipping method is not valid for this destination
  • Thrown in apps/api/src/modules/shipping/shipping-method-invalid.exception.ts.

HTTP 400.

  • Shipping is not available for this destination
  • Thrown in apps/api/src/modules/shipping/shipping-unavailable.exception.ts.

HTTP 409.

  • Email already registered
  • Thrown in apps/api/src/modules/users/users.service.ts.

HTTP 404.

  • Thrown in apps/api/src/modules/users/staff-not-found.exception.ts.

HTTP 403.

  • Cannot deactivate your own account
  • Thrown in apps/api/src/modules/users/users.service.ts.

HTTP 403.

  • Cannot modify your own staff record
  • Thrown in apps/api/src/modules/users/users.service.ts.

HTTP 400.

  • Only email templates can be test-sent (this one is ”${template.channel}”)
  • Thrown in apps/api/src/modules/notifications/notification-templates.service.ts.

HTTP 400.

  • Your account has no email on file.
  • Your account has no email address to send a test to
  • Thrown in apps/api/src/modules/campaigns/campaign.service.ts, apps/api/src/modules/notifications/notification-templates.service.ts.

HTTP 400.

  • Template references undeclared variable(s): ${unknown.join(’, ’)}. Add them to the flow’s variables list or remove the token.
  • Thrown in apps/api/src/modules/notifications/notification-templates.service.ts.

HTTP 400.

  • Cannot change credentials for this account type
  • Thrown in apps/api/src/modules/users/users.service.ts.

HTTP 404.

  • User not found
  • Thrown in apps/api/src/modules/users/users.service.ts.

HTTP 400.

  • Validation failed
  • Thrown in apps/api/src/main.ts.

HTTP 404.

  • Webhook subscription not found
  • Thrown in apps/api/src/modules/webhooks/webhooks.service.ts.

HTTP 400.

  • Webhook URL must not target internal or loopback addresses
  • Thrown in apps/api/src/modules/webhooks/webhooks.utils.ts.

HTTP 400.

  • Webhook URL must use the HTTPS scheme
  • Thrown in apps/api/src/modules/webhooks/webhooks.utils.ts.

HTTP 404.

  • Product ”${productId}” not found
  • Thrown in apps/api/src/modules/wishlist/wishlist-product-not-found.exception.ts.