Two Minute Reports Logo
API Reference

Errors

The Two Minute Reports API error envelope, status codes, and machine-readable error codes.

When a request fails, the API returns the standard envelope with success: false and an error object:

{
  "success": false,
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "name: String must contain at least 1 character(s)"
  }
}
  • code — a stable, machine-readable string. Branch on this in your code rather than parsing the message.
  • message — a human-readable description. For validation and business-rule errors it is specific; for authentication, authorization, and server errors it is intentionally generic to avoid leaking internal details.

Status codes

HTTP statuscodeWhen it happens
400BAD_REQUESTInvalid input — failed request validation or a business-rule violation
401UNAUTHORIZEDMissing, malformed, expired, or revoked token
403FORBIDDENAuthenticated, but lacking the required team role or access
403INSUFFICIENT_PERMISSIONSThe API key lacks the scope the endpoint requires — the message names the missing scope
404NOT_FOUNDThe resource does not exist or is not visible to you
409CONFLICTConflicts with current state (e.g. a duplicate invite)
413PAYLOAD_TOO_LARGERequest body exceeds the size limit
422VALIDATION_ERRORSemantic validation failure
429TOO_MANY_REQUESTSRate limit exceeded
402PAYMENT_REQUIREDThe team's plan is cancelled — reactivate to make changes
500INTERNAL_SERVER_ERRORAn unexpected error on our side

Permission and seat errors

These are separate codes rather than one FORBIDDEN, because each has a different fix and a client that cannot tell them apart cannot tell the caller what to do. See Roles & Permissions.

HTTP statuscodeWhat it meansHow to fix it
403SEAT_REQUIREDThe key holder's role allows this, but they have no seat in the team. Every permission that needs a seat is withheld.Ask an Admin to assign them a seat. Changing their role will not help.
403ROLE_NOT_ASSIGNABLEYou tried to assign a role that includes permissions you do not hold yourself.Ask someone with those permissions to assign it.
403CANNOT_ACT_ON_MEMBERThe member you are changing holds permissions you do not. Roles are only editable downwards, and an equal role counts as not-below.Ask an Admin.
403CANNOT_ACT_ON_SELFYou cannot change your own role or seat, not even to reduce it.Ask another Admin to do it.
403CANNOT_ACT_ON_OWNERThe team owner cannot be re-roled or removed by anybody.Contact support to change who the owner is.
402SEAT_LIMIT_REACHEDEvery seat on the plan is assigned.Un-assign a seat, or add seats to the plan.
429RATE_LIMITEDAn abuse cap on a specific endpoint, separate from the general rate limit. Invites are capped per team.Back off and retry.
SEAT_REQUIRED and FORBIDDEN look similar and are not the same problem. FORBIDDEN means the role does not include the action — somebody has to change the role. SEAT_REQUIRED means the role does include it and nobody has assigned a seat — somebody has to assign one. Telling a customer the wrong one sends them to the wrong colleague.

Examples

{
  "success": false,
  "error": {
    "code": "BAD_REQUEST",
    "message": "Invalid UUID: \"abc\""
  }
}
Copyright © 2026