NAME

WWW::Authentik::Error::API - Raised when authentik answers with an HTTP error

VERSION

version 0.001

DESCRIPTION

authentik reports errors in four shapes, and all of them end up in "api_message":

{"detail": "..."}

Most of the API where no field is at fault: a refused token (403), something missing (404), a method that is not allowed (405), a body that is not JSON (400).

{"<field>": ["..."], "non_field_errors": ["..."]}

Validation, including a duplicate: authentik answers a second create with 400 and a field error, not with 409. There is deliberately no is_conflict here, because a duplicate cannot be told from any other validation error except by its text. "field_errors" carries the fields; nested shapes ({"grant_types": {"0": [...]}}) are flattened to grant_types.0.

{"error": "...", "error_description": "...", "request_id": "..."}

The token, device and revocation endpoints. "oauth_error" carries the bare code, so a device-flow poll can tell authorization_pending from a real failure.

An empty body with a WWW-Authenticate header

The userinfo endpoint. The code and the description are read out of the header into "oauth_error" and "api_message".

http_status

The HTTP status code as a number, for example 400.

api_message

What authentik said, if it said anything: the detail, the field errors joined to one line, or the OAuth code with its description.

field_errors

A hash of field name to the list of messages for it, empty when the error had no field. Nested field errors are flattened with a dot.

$error->field_errors->{username}      # [ 'This field must be unique.' ]
$error->field_errors->{'grant_types.0'}

oauth_error

The OAuth error code (invalid_grant, invalid_client, authorization_pending, invalid_token, ...) when the error came from an OAuth endpoint.

request_id

The request_id authentik puts into an OAuth error, for finding the request in authentik's log.

body

What came back, up to 500 characters, when it was not one of the shapes above: a proxy's HTML, plain text, a JSON array. Undef when the body was empty. This is where to look when base_url points at something that is not an authentik.

is_bad_request

is_unauthorized

is_forbidden

is_not_found

True for status 400, 401, 403 and 404. A refused API token is 403, not 401.

SUPPORT

Issues

Please report bugs and feature requests on GitHub at https://github.com/Getty/p5-www-authentik/issues.

IRC

Join #kubernetes on irc.perl.org or message Getty directly.

CONTRIBUTING

Contributions are welcome! Please fork the repository and submit a pull request.

AUTHOR

Torsten Raudssus <getty@cpan.org>

COPYRIGHT AND LICENSE

This software is copyright (c) 2026 by Torsten Raudssus <torsten@raudssus.de> https://raudssus.de/.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.