Skip to content

Validation

Two rules. The second is not intuitive.

  • required checks run only on submission — when the applicant submits the form, or when you call Submit server-side.
  • Format checks always run. Regex, type and checksum rules are enforced on every value you supply, even at creation.
Terminal window
curl --request POST \
'https://app.uppass.io/en/api/forms/{form_slug}/create/' \
--header 'Authorization: Bearer '"$UPPASS_API_TOKEN" \
--header 'Content-Type: application/json' \
--data '{ "answers": { "nid": "1234567890123" } }'
422 Unprocessable Entity
{
"error": {
"status_code": 422,
"message": "Unprocessable Entity",
"detail": { "nid": ["The ID Card Number is invalid (checksum)"] }
}
}

Nothing was submitted — this was a plain create.

Handle both shapes. This is the single most common integration bug in error handling.

POST .../create/ — wrapped in error.detail
{
"error": {
"status_code": 422,
"message": "Unprocessable Entity",
"detail": {
"ekyc_document": ["The ekyc_document field is required."]
}
}
}
POST .../submit/ — flat, no wrapper
{
"ekyc_document": ["The ekyc_document field is required."],
"ekyc_liveness": ["The field is required."]
}

The keys are field names and the values are arrays of messages, in both shapes. Read the messages for logging; branch on the keys, which are stable, rather than on message text.