API reference

Errors

The single error shape, every code the API returns, and which ones are worth retrying.

Every error has the same shape, whatever went wrong. Branch on code, which is stable; show or log message, which is written for a human and may be reworded.

Error response
{
  "error": {
    "code": "account_not_found",
    "message": "no such trading account"
  }
}

Codes

StatusCodeMeansRetry?
400invalid_bodyThe JSON did not parse, or a required field is missing.No — fix the request.
400invalid_account_numberThe path segment is not an 8-digit account number.No
400invalid_cursorThe cursor was not one we issued.No — restart paging.
400invalid_rangefrom is not before to.No
401invalid_api_keyUnknown or revoked key.No
402quota_exhaustedNot enough account credits to provision what you asked for.No — buy credits.
403missing_scopeThe key lacks the scope this endpoint needs.No
404account_not_foundNo such account in your organization.No
409idempotency_mismatchAn Idempotency-Key was reused with a different body.No
429rate_limitedOver the per-key budget.Yes — after Retry-After.
503busyThe database pool is saturated.Yes — shortly.
503curve_unavailableThe equity curve is not configured on this deployment.No

Retry only 429 and 503

Those two are the only ones where the same request can succeed later. Everything else means the request itself needs changing, and retrying it just burns your rate limit. Use exponential backoff with jitter, and honour Retry-After when it is present.

A 404 means “not yours” too

An account belonging to a different organization returns the same 404 as one that does not exist. Tenant isolation is enforced in the database, so there is no way to tell the two apart — and no way to probe for other firms’ accounts.