Skip to content

Errors

Status Meaning
200 Success. Some management endpoints also return 200 for business failures. Check the body.
208 Already reported. The customer is already subscribed (ALREADY_SUBSCRIBED).
400 Invalid request: malformed JSON, validation error, card validation failed, product problem.
401 Missing or invalid API token.
403 Blocked, e.g. a blacklisted card BIN.
404 Resource not found or session expired.
409 No merchant account available to process the card.
5xx Unexpected error. Safe to retry idempotent GET requests.

When the buyer submits the checkout, the SDK reports the result in onMessage. Errors use the same shape as a successful result:

{
"sessionId": "3f6c2b8e-1d2a-4c55-9a3e-7b1f0c9d2e41",
"code": "SESSION_NOT_FOUND",
"message": "The requested session has expired or not exist",
"customerId": null
}
code HTTP Description What to do
OK 200 Success. —
ALREADY_SUBSCRIBED 208 Email + card already actively subscribed to this product. Tell the buyer; don’t retry.
JSON_ERROR 400 Malformed body or missing/invalid field. message lists the fields, e.g. email: Email is required. Fix the request.
CREDITCARD_VALIDATION 400 The card could not be validated with the gateway. Ask the buyer for another card.
PRODUCT_NOT_FOUND 400 The productId doesn’t exist for your account. Check the product ID.
PRODUCT_NOT_ACTIVE 400 The product is disabled. Contact CreditCore.
PRODUCT_ERROR 400 The product could not be loaded. Retry later.
BIN_BLACKLIST 403 The card’s BIN is blocked for this account or product. Ask for another card.
SESSION_NOT_FOUND 404 The session expired (5 min) or doesn’t exist. Create a new session and reload the checkout.
NO_MID_AVAILABLE 409 No merchant account accepts this card type for the product. Ask for another card brand or contact CreditCore.
Gateway code varies Error returned by the payment gateway. See message.
UNKNOWN_ERROR varies Unrecognized gateway error. Contact CreditCore with the sessionId.
{ "error": "UNAUTHORIZED", "status": 401 }

Management endpoints may return a plain-text ERROR body with status 500 for unexpected errors, or an empty body with 404 when a resource doesn’t exist.