HTTP 403, authentication and identity
AUTH-005
This action needs a fresh verification.
What it means
A sensitive action was attempted with a second factor verified more than five minutes ago. Creating credentials, changing security settings, and deleting a workspace all require a fresh one.
What to do
The application raises the verification prompt and retries the action for you. If you cancelled it, repeat the action.
The response
Every failure arrives in this shape. The trace_id is worth keeping: it identifies the request in our logs and carries nothing about your data.
{
"type": "https://shiftgraph.dev/errors/AUTH-005",
"title": "This action needs a fresh verification.",
"status": 403,
"code": "AUTH-005",
"trace_id": "01J8Z…"
}Related codes
Sessions, second factors, sign-in methods, and the credentials that reach the API. A second factor is required of every account, so several of these have no bypass by design.
- AUTH-001Invalid email or password.HTTP 401
- AUTH-002Your session has expired. Sign in again.HTTP 401
- AUTH-003Second factor required.HTTP 401
- AUTH-004That code didn't match. Try again.HTTP 401
- AUTH-006Too many attempts. Wait before trying again.HTTP 429
- AUTH-007That link is no longer valid.HTTP 400
- AUTH-008Your account is suspended.HTTP 403
- AUTH-009That verification code has expired. Request a new one.HTTP 400
- AUTH-010This sign-in method is already linked.HTTP 409
- AUTH-011Removing this would leave no way to sign in.HTTP 400
- AUTH-012Cross-site request blocked.HTTP 403
- AUTH-013This session was signed out.HTTP 401
- AUTH-014Password does not meet the requirements.HTTP 400
- AUTH-015ShiftGraph is currently invite-only.HTTP 403
- AUTH-016Invalid or revoked API token.HTTP 401
- AUTH-017This token lacks the required scope.HTTP 403
The full error reference, or write to support@shiftgraph.dev with the trace id.