Skip to content

admin_step_up_required

HTTP 403§9.9 Non-customer surfacesInternal surface

This code is raised on a non-customer surface (the /internal voice-runtime audience or telephony provider callbacks). It is excluded from the customer OpenAPI document and is registered here so an operator reading a log line has one place to look.

The action requires a fresh proof of presence and the current one is absent, stale, or bound to a different session. Since ADR-0017 decision 4 the proof is the operator re-entering their password, and the same body answers every way a completion fails. Not an error condition - the console runs the re-auth flow and replays the request exactly once (18-admin-console.md §2, §10).

Problem shape

Every non-2xx response is an RFC 9457 application/problem+json body. The type URI below is stable and machine-matchable, so branch on the final path segment (the code) and treat the status as redundant confirmation. See the error-handling guide.

{
  "type": "https://docs.vocapable.com/errors/admin_step_up_required",
  "title": "…",
  "status": 403,
  "detail": "…",
  "instance": "/v1/…"
}

← Back to the error registry