Skip to content

What am I missing?

“Which capability am I missing” is the most common integration question. Every refusal names what is missing; this page says how to get it.

Code What it means What to do
capability_not_granted Your organization, or this application, does not hold the capability the operation needs. The error names it. An administrator grants it to the application in the console, within what your organization holds. If your organization does not hold it, ask NCC.
unauthenticated The token or the client certificate was not accepted, or they name different applications. Use the certificate whose key signed the token request. Check the certificate is active and the token has not expired.
organization_not_active Your organization cannot act: not yet verified, or suspended. See its status in the console.
verification_lapsed Your organization’s verification has expired. An administrator submits revalidation from the console.
Code What it means What to do
role_not_permitted Your role does not allow this. Ask an administrator to change your role.
production_requires_administrator Developers change sandbox only. An administrator makes the change in production.
reauthentication_required The change needs a fresh sign-in. The console asks you to sign in again, then retries.
organization_not_verified Production is waiting for verification. An administrator submits the verification under Going live.
organization_suspended NCC has suspended the organization. You can read it; changes wait for reinstatement.
not_available_to_members This is your systems’ work, not something done through the portal. Call it from your application with its credentials.
last_administrator The organization must keep an administrator. Make someone else an administrator first.

Every response carries a Request-Id. The console’s Activity tab lists your requests with theirs. Quote it when you contact support, so the request can be found without sending logs.