HTTP 401, authentication and identity
AUTH-003
Second factor required.
What it means
The password was accepted but the session has not completed its second factor. Every ShiftGraph account carries one; there is no account type that skips it.
What to do
Complete the factor prompt. If the device is unavailable, a recovery code signs you in and burns itself.
The response
Every failure arrives in this shape. The trace_id is worth keeping: it identifies the request in our logs and carries nothing about your data.
{
"type": "https://shiftgraph.dev/errors/AUTH-003",
"title": "Second factor required.",
"status": 401,
"code": "AUTH-003",
"trace_id": "01J8Z…"
}Related codes
Sessions, second factors, sign-in methods, and the credentials that reach the API. A second factor is required of every account, so several of these have no bypass by design.
- AUTH-001Invalid email or password.HTTP 401
- AUTH-002Your session has expired. Sign in again.HTTP 401
- AUTH-004That code didn't match. Try again.HTTP 401
- AUTH-005This action needs a fresh verification.HTTP 403
- AUTH-006Too many attempts. Wait before trying again.HTTP 429
- AUTH-007That link is no longer valid.HTTP 400
- AUTH-008Your account is suspended.HTTP 403
- AUTH-009That verification code has expired. Request a new one.HTTP 400
- AUTH-010This sign-in method is already linked.HTTP 409
- AUTH-011Removing this would leave no way to sign in.HTTP 400
- AUTH-012Cross-site request blocked.HTTP 403
- AUTH-013This session was signed out.HTTP 401
- AUTH-014Password does not meet the requirements.HTTP 400
- AUTH-015ShiftGraph is currently invite-only.HTTP 403
- AUTH-016Invalid or revoked API token.HTTP 401
- AUTH-017This token lacks the required scope.HTTP 403
The full error reference, or write to support@shiftgraph.dev with the trace id.