Errors
The API uses standard HTTP status codes. The body of a failed response carries a single
field, error, whose text describes the cause:
{ "error": "Invalid API key" }
That message is written for the developer, not for the end user: it may change, so it must never be used as a test value. Branch your logic on the status code.
Codes returned
| Status | Cause | What to do |
|---|---|---|
400 | Invalid body or parameter | Fix the request; retrying it unchanged will fail again |
401 | Key missing, unknown or revoked | Check the X-API-Key header |
403 | Valid key without the required right, or called from an unauthorised IP | Check the key's scope and IP restriction |
404 | Resource does not exist, or belongs to another account | Do not tell the two apart: the answer is identical on purpose |
429 | Request ceiling reached | Wait, then retry with a backoff |
500 | Incident on the Metaventus side | Retry after a few seconds; if it persists, contact us |
What the API does not do
A 404 on another account's resource is indistinguishable from a 404 on a resource that
does not exist. That is deliberate: confirming that an identifier you do not own exists
would leak information.
Any 2xx other than 200 is still a success. 201 signals a creation, 202 a request
accepted whose processing continues in the background, 204 an operation that succeeded
with no response body. Treating "not 200" as a failure is the most common integration
mistake.