404 Tenant not found. | Patient login/start and register; practitioner login/token and register | The tenantCode is wrong. | Find your tenant code. |
400 Username or password is incorrect. | Both login/start | A wrong email or password, an account that does not exist, an account without a password, or an account of the other type or another tenant. Deliberately one answer. | Check the audience: patients use the patient routes, practitioners the practitioner routes. |
403 Login is not enabled. | Patient login/start | PATIENT_LOGIN_ENABLED is false. | Set it to true. |
403 Login is not enabled for this project. | Practitioner login/token | PRACTITIONER_LOGIN_ENABLED is false for the chosen project. | Set it to true, or let the user choose another tenant. |
403 Registration is not enabled for this project. | Patient register | The switch is false, or the project has no default patient AccessPolicy. The message is the same. | Check PATIENT_REGISTRATION_ENABLED and the AccessPolicy. |
403 Registration is not enabled for this project. | Practitioner register | PRACTITIONER_REGISTRATION_ENABLED is not true. It is off when unset. | Set it to true after setting the default policy. |
409 with error practitioner_registration_not_configured | Practitioner register | Registration is on, but DEFAULT_PRACTITIONER_ACCESS_POLICY is missing, unreadable or from another project. | Set a valid policy. |
409 | Practitioner register | Another registration for the same email is running. | Retry. |
400 Registration failed. | Both register | The email already has an account. For patients, in this project; for practitioners, in any project. | Sign in instead, or invite the practitioner. |
400 Invalid MFA token. | Patient login/mfa | The code is wrong, or the loginId is unknown. | Ask for a fresh code. |
400 Invalid MFA token or user. | Practitioner login/mfa | The same. | Ask for a fresh code. |
400 Code verification failed. | Both login/token | The sessionCode or codeVerifier is wrong. | Check that you send the verifier whose hash you sent as codeChallenge, and a session code from the same attempt. |
404 Login not found. | Practitioner login/token | The session code is unknown. | Start sign-in again. |
404 Account not found. | Practitioner login/token | The practitioner has no membership in the chosen tenant. | Choose a tenantCode from the profiles list. |
400 Invalid user profile. | Both login/token | The session belongs to another type of account. | Use the other audience's routes. |
400 The continue-as-patient link is invalid or has expired. | Patient register | The continueAsPatientToken is wrong, expired (7 days), or for another email or project. | Use the link from the invitation email, within 7 days of it being sent. |
422 and a list of fields | Any | A field is missing or invalid: mfaToken shorter than 6 characters, loginId not a UUID, an empty practitioner password, and so on. | Fix the fields named by path. |
429 | Any | Too many requests from one IP address. | Wait a minute. See the limits. |