Membrane API Gateway reports errors as Problem Details (RFC 9457). In development mode, the error response contains a see field that links to one of the pages below. Each page explains what the error means, what usually causes it and how to fix it.
{
"type": "https://membrane-api.io/problems/user",
"title": "Invalid path or method",
"status": 404,
"detail": "The requested path or HTTP method is not supported.",
"see": "https://membrane-api.io/problems/user/routing"
}
{
"type": "https://membrane-api.io/problems/user",
"title": "Invalid path or method",
"status": 404,
"detail": "The requested path or HTTP method is not supported.",
"see": "https://membrane-api.io/problems/user/routing"
}
The type names the category of the error: user, security, gateway, internal or operation-error. The see link points to the page for that specific error. In production mode, see and most details are left out of the response.
The request or the gateway configuration caused the problem. These errors usually have a 4xx status.
A security plugin rejected the request, for example because of missing credentials, an invalid token or a CORS policy.
| Error | Path |
|---|---|
| 403 Access Denied | security/access-control/authorization-denied |
| 401/403 API Key Rejected | security/authorization-denied/api-key |
| 401 Basic Authentication Failed | security/basic-authenticator |
| 403 CORS Credentials Not Allowed | security/credentials-not-allowed/cors |
| 403 CORS Headers Not Allowed | security/headers-not-allowed/cors |
| 401 JWT Rejected | security/jwt-auth |
| 401 JWT Header Not JSON | security/jwt-auth/jwt-header-not-json |
| 401 JWT Validation Failed | security/jwt-auth/jwt-validation-failed |
| 401 Error Retrieving JWT | security/jwt-auth/retrieving-jwt |
| 500 JWT Signing Failed | security/jwt-sign/crypto |
| 500 Message Is Too Large | security/limit-interceptor |
| 403 CORS Method Not Allowed | security/method-not-allowed/cors |
| 500 OAuth2 Error from Authentication Server | security/oauth2-callback-request-handler/oauth2-error-from-authentication-server |
| 403 CORS Origin Not Allowed | security/origin-not-allowed/cors |
| 400/502 SQL Injection Blocked | security/sql-injection-protection |
| 400 XML Security Policy Violated | security/xml-protection |
Membrane could not reach the backend or received an invalid response from it.
| Error | Path |
|---|---|
| 502 Could Not Connect to Backend | gateway/http-client/connect |
| 401 Protocol Upgrade Denied | gateway/http-client/denied-protocol-upgrade |
| 502 Invalid Response Framing | gateway/http-client/invalid-framing |
| 502 Unknown Backend Host | gateway/http-client/unknown-host |
| 502 Could Not Obtain OAuth2 Token | gateway/oauth2-client/oauth2-token |
| 502 Upstream Proxy Rejected CONNECT | gateway/proxy/connect |
A failure inside the gateway, in a plugin, a script or the processing of a message.
The backend reported a failed operation, for example a SOAP fault.
| Error | Path |
|---|---|
| 500 Operation Failed in wsdl2openapi | operation-error/wsdl2openapi |
Some errors can occur in any plugin. Their path ends in or contains the name of the plugin that raised the error. Plugins that have a page of their own for the same path are listed in the tables above.
A plugin threw an exception that it did not turn into an error response itself.
A plugin could not read the request body, because it was incomplete or broken.
A plugin could not decode a gzip, deflate or br request body.
A plugin could not read a message body, usually the response of the backend.
Still stuck? See the troubleshooting guide or ask on GitHub Issues. For commercial support, contact info@predic8.de.