> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wfa.team/llms.txt
> Use this file to discover all available pages before exploring further.

# Errors and retries

> Handle the exact errors returned by each endpoint.

## Check HTTP status and the JSON body

Check for `status: "error"` or `success: false`, even when HTTP status indicates success. Application error messages are endpoint-specific. Do not translate them into assumed HTTP 400, 401 or 404 codes.

## Message errors

| Endpoint | Returned message | What to do |
| - | - | - |
| Create / retrieve / update | `Invalid Auth` | Check your company token and environment. |
| Invite staff | `Invalid authorization token` | Check the company token and Bearer header. |
| Retrieve | `Not Found` | Check the assessment ID and environment. |
| Retrieve | `Pending` | Wait briefly, then retrieve the same ID again. |
| Update | `RWA not found for this company` | Use an assessment belonging to the authenticated company. |
| Invite staff | `Could not create pending user` | Check account details and existing users before retrying. |

```json theme={null}
{"status":"error","success":false,"message":"Pending"}
```

## Field-validation errors

These responses include an `errors` array, with the field name and a message describing the failed check.

```json theme={null}
{
  "status": "error",
  "success": false,
  "errors": [{"field": "employeeId", "message": "Employee ID is missing"}]
}
```

The [create endpoint](/api-reference/create-assessment#error-responses) lists all active field checks, including country names and hiring inputs. The [update endpoint](/api-reference/update-decision#error-responses) lists missing decision actors, inactive compliance staff and unsupported status errors.

## Before retrying

Only poll retrieve when the response is `Pending`, with a short delay and a bounded timeout. Do not repeatedly resend create or invitation requests after a timeout: the first request may have completed. Invitation requests can send emails. Retain your external event ID while investigating an update retry; duplicate-event handling has not been verified.

## Get help

Contact [support@wfa.team](mailto:support@wfa.team) with the endpoint, environment, request time and a redacted response. Never include your API token.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.