Skip to main content
Kyren Pay uses conventional HTTP status codes to indicate the success or failure of an API request.

HTTP Status Codes

Error Response Format

Application errors handled by the API use this JSON structure. Authentication middleware and proxy errors may have an empty or different body; check the HTTP status before parsing JSON.
error is optional. It is included when a field detail is available; field and reason may also be omitted independently. Do not depend on exact message text.

Application Error Codes

These codes identify the error condition. Business errors can use HTTP 400; do not infer the HTTP status from the first digits of code.

Common Errors

400 Bad Request

Returned when the request body or parameters are invalid.

401 Unauthorized

Returned when the API key is missing or rejected. The authentication entrypoint does not guarantee a JSON body. If an application-level unauthorized error returns JSON, its code is 40101.

404 Not Found

Returned when the requested resource does not exist.

429 Too Many Requests

Returned when a configured rate limit is exceeded. Defaults are 100 requests per minute per IP for general API requests and 60 checkout creations per minute per authenticated merchant for POST /v1/checkouts. These limits are configurable and are not a guaranteed production quota.
Implement exponential backoff in your integration to handle rate limiting gracefully.

Success Response Format

Public merchant JSON API success responses include code: 0 and message: "success". Epay compatibility responses and file downloads follow their endpoint-specific formats.
For paginated endpoints, the data field contains items and pagination: