400 | Invalid input or an operation is not allowed in the resource’s current state | Correct the request. For payments, check the current status before retrying. |
401 | Key missing, invalid, or expired | Confirm the Authorization: Bearer gtw_sk_... header and environment. |
403 | Organization inactive or key lacks the required permission | Use a permitted key or update the key’s scopes in the dashboard. |
404 | Resource does not exist in the organization associated with the key | Confirm the ID and that sandbox and production data are not being mixed. |
409 | Duplicate unique value, such as a payment reference or customer email | Reuse the original resource or generate a new reference for a genuinely new operation. |
500 / 502 | Temporary server or upstream-provider problem | Record the request context and retry only after reconciling the operation. |