レスポンスコードResponse codes
ブラウザから直接開いた場合はこのページ群を、/api/ と /a/ 配下では同じ内容を application/problem+json(RFC 9457)で返します。アプリケーション層のエラー(409 token-already-used、422 context-mismatch など)は API が直接返すため、ここには含めていません。
Browsers get these pages; under /api/ and /a/ the same content is returned as application/problem+json (RFC 9457). Application-level errors such as 409 token-already-used and 422 context-mismatch are returned by the API itself and are not listed here.
- 400不正なリクエストBad requestBad Request — リクエストの形式が仕様と一致しません。SDK を経由せずに API を呼び出した場合や、署名(integrity.payload_hmac)が一致しない場合に返されます。The request does not match the specification. This is returned when the API is called without the SDK, or when the signature (integrity.payload_hmac) does not match.json
- 403アクセスが拒否されましたAccess deniedForbidden — このアクセスは自動化された通信と判定されたか、既知の攻撃パターンに一致しました。判定の詳細は安全上の理由から開示していません。This access was judged to be automated or matched a known attack pattern. Details of the decision are not disclosed for security reasons.json
- 404ページが見つかりませんPage not foundNot Found — 指定された URL に対応するページや資産はありません。課題画像や音声の URL は一度しか取得できないため、再読み込みでもこの応答になります。There is no page or asset at this URL. Challenge image and audio URLs can only be fetched once, so reloading them also produces this response.json
- 405許可されていないメソッドMethod not allowedMethod Not Allowed — このエンドポイントは指定された HTTP メソッドを受け付けません。This endpoint does not accept the HTTP method you used.json
- 410有効期限が切れていますExpiredGone — 課題トークンまたは課題資産の有効期限(180 秒)が過ぎました。期限を短くしているのは、トークンの転売や中継を難しくするためです。The challenge token or asset has expired (180 seconds). Lifetimes are short to make reselling or relaying tokens harder.json
- 429リクエストが多すぎますToo many requestsToo Many Requests — 短時間に多数のリクエストが送られたため、一時的に制限しています。IP アドレスの範囲、サイトキー、端末指紋の三つの単位で制限しています。Too many requests were sent in a short time, so access is temporarily limited. Limits apply per IP range, per site key and per device fingerprint.json
- 500サーバー内部エラーInternal server errorInternal Server Error — 処理中に予期しないエラーが発生しました。記録を確認して対応します。An unexpected error occurred while processing the request. It has been logged.json
- 502上流サーバーに接続できませんUpstream unavailableBad Gateway — 検証サービスが応答を返せませんでした。デプロイ直後や再起動中に短時間表示されることがあります。The verification service did not respond. This can appear briefly right after a deploy or restart.json
- 503サービスを一時停止していますService temporarily unavailableService Unavailable — 検証サービスは現在利用できません。メンテナンス、または過負荷による保護が働いています。The verification service is currently unavailable, due to maintenance or overload protection.json
- 504上流サーバーが応答しませんUpstream timeoutGateway Timeout — 検証サービスからの応答が制限時間(5 秒)内に返りませんでした。1 秒以内の応答を目標としているため、待ち時間を長く取らない設計にしています。The verification service did not respond within the 5-second limit. Because the target is sub-second responses, the gateway deliberately does not wait longer.json