NAME
WWW::Authentik::Error::API - Raised when authentik answers with an HTTP error
VERSION
version 0.001
DESCRIPTION
authentik reports errors in four shapes, and all of them end up in "api_message":
{"detail": "..."}-
Most of the API where no field is at fault: a refused token (403), something missing (404), a method that is not allowed (405), a body that is not JSON (400).
{"<field>": ["..."], "non_field_errors": ["..."]}-
Validation, including a duplicate: authentik answers a second create with 400 and a field error, not with 409. There is deliberately no
is_conflicthere, because a duplicate cannot be told from any other validation error except by its text. "field_errors" carries the fields; nested shapes ({"grant_types": {"0": [...]}}) are flattened togrant_types.0. {"error": "...", "error_description": "...", "request_id": "..."}-
The token, device and revocation endpoints. "oauth_error" carries the bare code, so a device-flow poll can tell
authorization_pendingfrom a real failure. - An empty body with a
WWW-Authenticateheader -
The userinfo endpoint. The code and the description are read out of the header into "oauth_error" and "api_message".
http_status
The HTTP status code as a number, for example 400.
api_message
What authentik said, if it said anything: the detail, the field errors joined to one line, or the OAuth code with its description.
field_errors
A hash of field name to the list of messages for it, empty when the error had no field. Nested field errors are flattened with a dot.
$error->field_errors->{username} # [ 'This field must be unique.' ]
$error->field_errors->{'grant_types.0'}
oauth_error
The OAuth error code (invalid_grant, invalid_client, authorization_pending, invalid_token, ...) when the error came from an OAuth endpoint.
request_id
The request_id authentik puts into an OAuth error, for finding the request in authentik's log.
body
What came back, up to 500 characters, when it was not one of the shapes above: a proxy's HTML, plain text, a JSON array. Undef when the body was empty. This is where to look when base_url points at something that is not an authentik.
is_bad_request
is_unauthorized
is_forbidden
is_not_found
True for status 400, 401, 403 and 404. A refused API token is 403, not 401.
SUPPORT
Issues
Please report bugs and feature requests on GitHub at https://github.com/Getty/p5-www-authentik/issues.
IRC
Join #kubernetes on irc.perl.org or message Getty directly.
CONTRIBUTING
Contributions are welcome! Please fork the repository and submit a pull request.
AUTHOR
Torsten Raudssus <getty@cpan.org>
COPYRIGHT AND LICENSE
This software is copyright (c) 2026 by Torsten Raudssus <torsten@raudssus.de> https://raudssus.de/.
This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.