Validation
Two rules. The second is not intuitive.
requiredchecks run only on submission — when the applicant submits the form, or when you call Submit server-side.- Format checks always run. Regex, type and checksum rules are enforced on every value you supply, even at creation.
A draft create can still return 422
Section titled “A draft create can still return 422”curl --request POST \ 'https://app.uppass.io/en/api/forms/{form_slug}/create/' \ --header 'Authorization: Bearer '"$UPPASS_API_TOKEN" \ --header 'Content-Type: application/json' \ --data '{ "answers": { "nid": "1234567890123" } }'{ "error": { "status_code": 422, "message": "Unprocessable Entity", "detail": { "nid": ["The ID Card Number is invalid (checksum)"] } }}Nothing was submitted — this was a plain create.
The 422 envelope differs by endpoint
Section titled “The 422 envelope differs by endpoint”Handle both shapes. This is the single most common integration bug in error handling.
{ "error": { "status_code": 422, "message": "Unprocessable Entity", "detail": { "ekyc_document": ["The ekyc_document field is required."] } }}{ "ekyc_document": ["The ekyc_document field is required."], "ekyc_liveness": ["The field is required."]}The keys are field names and the values are arrays of messages, in both shapes. Read the messages for logging; branch on the keys, which are stable, rather than on message text.