> ## Documentation Index
> Fetch the complete documentation index at: https://docs.novig.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Troubleshooting

> Find your symptom, then read its cause and fix.

export const COMPANION_WINDOW_DAYS = 3;

Find your symptom below.
For the full reference, see [Throttling](/api/throttling) for why we throttle a request, and [Errors](/api/errors) for every rejection and its fix.

## Signature problems

* **A <span className="st st-warn">401</span> on every call.** A header, the clock, the key, or the canonical string is wrong. Read `message`, then sign a published vector and diff your string against it on [Sign a request](/api/signing).
* **`GET` works, but `POST` fails.** Without `Content-Type: application/json`, the server hashed zero bytes. Send that header on every request with a body.
* **Every `POST` fails, and the body looks right.** Your client re-serialized the JSON after you hashed it. Send the exact bytes you hashed.
* **Every path fails.** You signed the URL, or dropped the mount prefix. Sign the path only, with the mount prefix included.
* **A P-256 signature never verifies.** You sent a raw `r‖s` signature. Send DER instead, as [Algorithms](/api/signing#algorithms) describes.
* **`api key not found`, but the key exists.** You're on the wrong environment, since a key works only in its own. Check the host on [Environments](/api/environments).

## Other problems

* **A <span className="st st-warn">403</span> after the <span className="st st-warn">401</span>s cleared.** Your signature verified, but the key's scope doesn't reach the route. See [403](/api/errors#403-forbidden).
* **A <span className="st st-warn">403</span> `KYC_REQUIRED` when you place an order, while cancels still work.** The key holder's KYC lapsed after the key was created. Finish verification in the app.
* **A <span className="st st-hold">429</span> while you're under your own limit.** Our servers share token counts with each other gradually. Wait `Retry-After` seconds, as [Throttling](/api/throttling#error-response) explains.
* **A <span className="st st-warn">451</span>.** The request came over a VPN, or the key holder's last geolocation is missing, failed, restricted, or, on a placement, older than {COMPANION_WINDOW_DAYS} days. Turn off the VPN and open the app, as [451](/api/errors#451-geolocation-unavailable) explains.
* **A <span className="st st-hold">423</span> `ACCOUNT_LOCKED` when you create a key, open a subaccount, or fund one.** The account is excluded or self-excluded. This won't clear on its own, so contact support ([423](/api/errors#423-locked)).
* **A <span className="st st-hold">423</span> `SELF_EXCLUDED` when you place an order, while cancels and reads still work.** The key holder is self-excluded. This won't clear on its own, so contact support ([423](/api/errors#423-locked)).
* **A <span className="st st-hold">423</span> with no `code` on every trading and catalog route, reads included.** The account is locked or excluded, or we've halted trading. This won't clear on its own, so contact support ([423](/api/errors#423-locked)).
* **A <span className="st st-ok">201</span>, but the order isn't on the book.** A `201` means queued, and the exchange answers on the private stream. Read the `reject` event on the [private stream](/api/streaming/private).
* **The <span className="st st-ok">201</span> never arrived.** We may have placed the order anyway. Match `clientId` on the [private stream](/api/streaming/private) before you resend, because a resend places it again ([Retries](/api/execution/orders#retries)).
* **A `seq` jumped.** You missed a message. Take a `snapshot`, as [Gaps](/api/streaming/connection#gaps) explains.
* **A <span className="st st-warn">403</span> with an HTML body.** Our edge refused the body before the exchange saw it. Split the batch.

## If nothing matches

1. Send the exact bytes to `POST /v3/echo`. A `200` confirms the host, key, clock, and canonical string at once.
2. Read `code`, which is stable. `message` can change.
3. Read the [private stream](/api/streaming/private) before you resend an order.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.