Programming guide

Triage an API request failure

Reduce a failing request to method, URL, authentication, payload and response evidence without exposing secrets.

Estimated time: 20–45 minutesUpdated: 27 September 2026

Step by step

  1. Capture the complete exchange safely

    Record timestamp, environment, method, path, status code, response body and a request correlation ID. Redact tokens, cookies and personal data.

  2. Classify the failure

    Separate DNS or TLS, connection, authentication, permission, validation, rate limit, server error and client parsing problems.

  3. Reproduce the smallest request

    Use a known account and minimal payload in a non-production environment where possible. Compare a working request field by field.

  4. Confirm the contract

    Check current API documentation, content type, required headers, date formats, pagination and version. Treat retries carefully for non-idempotent operations.

Ready-to-use checklist

  • Secrets redacted
  • Status and response captured
  • Environment identified
  • Minimal reproduction built
  • Working request compared
  • Retry safety considered

Common problems

The server returns only a generic 500

Use correlation IDs and server logs; do not repeatedly change the client when the failure is clearly after request acceptance.

The same token works elsewhere

Compare audience, scopes, environment, account permissions, clock skew and resource ownership.