Errors are returned as a list, so one response can report several problems at once:
message. Validation failures also carry the field the problem is on and a code, and some carry extra keys naming the offending values. A code is a stable slug on the errors that define one, and repeats the message text on the errors that do not, so branch on a code only where you have seen a slug come back. Endpoints that refuse a request without validating a record return a message alone:
duplicate_rule sibling of errors, so a client can read it without walking the entries. Its message ends with the existing rule’s effective period in parentheses, which the example above leaves off; read the period from duplicate_rule rather than parsing the text.
A 401 from an expired token carries a message saying so. A 401 from a token Mangrove does not recognise carries no body at all, which is how the two are told apart. See Authentication.