> ## Documentation Index
> Fetch the complete documentation index at: https://learn.biq.li/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth errors

> Handle authorization, token, scope, and connection failures.

OAuth protocol endpoints return a machine-readable `error` and a short
`error_description`.

```json theme={null}
{
  "error": "invalid_grant",
  "error_description": "The authorization code is invalid, expired, or already used."
}
```

| Error | Meaning | Recovery |
| :- | :- | :- |
| `invalid_request` | A required field is missing, malformed, or inconsistent. | Correct the request; do not retry unchanged. |
| `invalid_client` | Client authentication failed or the client is inactive. | Verify the client ID and current secret, or use the configured public-client flow. |
| `invalid_grant` | A code or refresh token is expired, consumed, reused, revoked, or bound to different request data. | Start a new authorization. |
| `unsupported_grant_type` | The token request used an unsupported grant. | Use `authorization_code` or `refresh_token`. |
| `access_denied` | The user declined authorization. | Return the user to your application without creating a connection. |

Authenticated API endpoints can also return:

| Status | Meaning |
| :- | :- |
| `401` | The access token is missing, expired, invalid, revoked, or no longer belongs to an active connection. |
| `403` | The token lacks a required scope, the user lost permission, or the workspace plan does not allow the operation. |
| `404` | The resource is unavailable in the connected workspace. |
| `429` | The request exceeded the applicable rate limit. |

Do not replay authorization codes or older refresh tokens. Log the safe error
code, request ID, endpoint, and UTC time, but never log codes, access tokens,
refresh tokens, or client secrets.
