Helix.ID
Sign In

Error handling · 2 min

v0.2.1 · Updated 17 Sep 2026View as Markdown

Error handling

The errors the SDK throws while verifying, and the HTTP response each one deserves.

Error classes

Handle each error class specifically to return appropriate HTTP responses:

Error ClassThrown byHTTPCause
InvalidSignatureErrorverifyCallback401Callback HMAC does not match — possible tampering or wrong secret.
NonceMismatchErrorverifyCallback401Nonce in callback does not match the session nonce.
ExpiredTimestampErrorverifyCallback401Callback timestamp is outside the accepted time window.
MalformedCallbackErrorverifyCallback400Required callback fields are missing or unparseable.
InvalidAuthUrlSignatureErrorverifyAuthUrlSignature401Auth URL sig is missing or does not match — the URL was rewritten.

Error codes

Every class extends VoiceAuthError and carries a stable .code — INVALID_SIGNATURE, NONCE_MISMATCH, EXPIRED_TIMESTAMP, MALFORMED_CALLBACK, INVALID_AUTH_URL_SIGNATURE — so you can branch on the code instead of the class if you prefer.