message. The HTTP status is the machine-readable part;
the string is for a person reading a log.
The order the checks run in
This decides which error you see when a request is wrong in more than one way, and it is the reason a malformed payload can come back as an authentication problem.1
Authentication
Before the body is parsed at all.
2
Authorisation
IP allow list, then login type.
3
Content negotiation
The
Accept header.4
Parsing
JSON well-formedness, then field names, then field values.
5
Business rules
Sender ID, template, credit, rate limit.
Authentication and authorisation
401 means “you did not identify yourself”; 403 means “you did, and it was not accepted.” The
distinction is worth wiring into your alerting: a sudden 401 is usually a deployment that lost its
environment variable, while a sudden 403 is usually a password rotation or an IP that moved.
Content negotiation
Omitting
Accept entirely is fine. Sending Accept: text/plain is not, and this is the one error a
browser address bar will reliably produce.
Parsing
Business rules
Which of these should you retry?
Related
REST API overview
The envelope, authentication and the field-name rule.
Send one message
Every field, with its default and its refusal.