Errors

Every non-2xx response carries exactly one shape:

{
  "error": {
    "code": "validation",
    "message": "The request body has invalid fields.",
    "status": 400,
    "details": [
      { "field": "date", "message": "must be a date formatted YYYY-MM-DD" },
      { "field": "label", "message": "is required" }
    ]
  }
}
Status code When
400 validation A body field, query parameter, filter or id is malformed. details names every offending field, not just the first.
401 unauthenticated No bearer, or one that is unknown, expired or revoked. Native clients treat this as "clear the session and sign in again".
403 forbidden The token's roles lack the capability. The message names it.
404 not_found No such record, or no such endpoint.
409 conflict A unique constraint (the same product twice on one gig), or a delete refused because other records still reference the row.
413 validation The body is larger than 5 MB.
500 internal Something on our side. Try again; if it persists, tell us.

A reference to a row that does not exist (say, a venueId nobody has) is a 400 on the field, not a 409. 409 is reserved for the case where the record you are touching is in the way of something else.

Malformed JSON is a 400 with the message The request body is not valid JSON.