Skip to content
AutoCore1.0.0-rc.1 · Release Candidate
1.0.0-rc.1 · Release Candidate2 min read

API Error Envelope

The stable error response shape and machine-readable error codes.

Parse error.code first, then present the safe message and retain the request ID.

Source boundary

Source boundary: AutoCore current main 7a504f6e430c16d4fcb03ebdea3cc3fb7816df60, checked against immutable v1.0.0-rc.1 at 9edfb109f44cc80385784c694b96392cfc04e70f.

Errors use { error: { code, message, details, requestId } }. The exception filter maps validation to 422, throttling to 429, not-found to 404, conflict to 409, and unexpected failures to a generic 500 response.

CheckSource-backed expectation
ScopeError details are diagnostic input, not a license to expose stack traces, secrets, SQL, or provider payloads.
EvidenceUse placeholders, timestamps, release identity, route, status, and request ID where relevant.
Safe actioncurl -i https://api.example.invalid/api/v1/does-not-exist
Stop conditionUnknown authorization, destructive impact, secret exposure, or conflicting evidence.

Verification

Run the safe check, record its result, and compare the outcome with the documented contract. If the result depends on external configuration or provider availability, mark it as configuration-dependent rather than claiming a product guarantee.

Code
curl -i https://api.example.invalid/api/v1/does-not-exist

Safety boundary

Examples are non-production and use placeholders. Do not deploy, reset, force a migration, create secrets, activate providers, replay sensitive work, or expose private data from this page.

Related articles