Error Codes
Semua error response mengikuti format RFC 7807 (Problem Details) dengan field error, message, dan errors (opsional).
Error Response Format
HTTP/1.1 401 Unauthorized
Content-Type: application/json
{
"error": "invalid_token",
"message": "The access token is invalid or expired."
}
HTTP Status Codes
| Status | Meaning | Used when... |
|---|---|---|
| 200 | OK | Request berhasil |
| 201 | Created | Resource berhasil dibuat |
| 400 | Bad Request | Request malformed atau missing required field |
| 401 | Unauthorized | Token tidak ada, invalid, atau expired |
| 403 | Forbidden | Token tidak punya scope yang diperlukan |
| 404 | Not Found | Resource tidak ditemukan |
| 422 | Unprocessable Entity | Validasi gagal (dengan detail field) |
| 429 | Too Many Requests | Rate limit exceeded |
| 500 | Server Error | Kesalahan server internal |
OAuth2 Error Codes
| error | Status | Description |
|---|---|---|
| invalid_client | 401 | Client ID atau secret salah, atau client inactive |
| invalid_grant | 400 | Authorization code atau refresh token invalid/expired, atau username/password salah |
| unauthorized_client | 403 | Client tidak punya izin untuk grant type tertentu |
| unsupported_grant_type | 400 | Grant type yang dipakai tidak didukung server |
| invalid_scope | 400 | Scope yang diminta tidak diizinkan untuk client ini |
| invalid_token | 401 | Access token invalid, expired, atau sudah di-revoke |
| insufficient_scope | 403 | Token tidak punya scope yang diperlukan endpoint |
| unauthorized | 401 | Header Authorization tidak ada atau format salah |
Validation Errors (422)
Ketika validasi gagal, response akan menyertakan detail field yang error:
422 Unprocessable Entity
{
"message": "The given data was invalid.",
"errors": {
"nama": ["The nama field is required."],
"jenis_kelamin": ["The selected jenis kelamin is invalid."],
"nisn": ["The nisn must be 10 characters."]
}
}
Rate Limiting
API ini dilindungi rate limiting. Limit default:
| Tier | Limit | Scope |
|---|---|---|
| Default | 60 requests / menit | Per IP |
| Authenticated | 300 requests / menit | Per token |
| Enterprise | 1000 requests / menit | Per token |
Ketika rate limit exceeded, response header akan menyertakan:
Response Headers
X-RateLimit-Limit: 300
X-RateLimit-Remaining: 247
X-RateLimit-Reset: 1728398400