---
title: "Error handling"
description: "The errors the SDK throws while verifying, and the HTTP response each one deserves."
source: "/docs/errors"
updated: "2026-09-24"
---

# Error handling

The errors the SDK throws while verifying, and the HTTP response each one deserves.

## Error classes

Handle each error class specifically to return appropriate HTTP responses:

| Error Class                    | Thrown by                | HTTP | Cause                                                                |
| ------------------------------ | ------------------------ | ---- | -------------------------------------------------------------------- |
| `InvalidSignatureError`        | `verifyCallback`         | 401  | Callback HMAC does not match - possible tampering or wrong secret.   |
| `NonceMismatchError`           | `verifyCallback`         | 401  | Nonce in callback does not match the session nonce.                  |
| `ExpiredTimestampError`        | `verifyCallback`         | 401  | Callback timestamp is outside the accepted time window.              |
| `MalformedCallbackError`       | `verifyCallback`         | 400  | Required callback fields are missing or unparseable.                 |
| `InvalidAuthUrlSignatureError` | `verifyAuthUrlSignature` | 401  | Auth URL `sig` is missing or does not match - the URL was rewritten. |

## Error codes

Every class extends `VoiceAuthError` and carries a stable `.code` - `INVALID_SIGNATURE`, `NONCE_MISMATCH`, `EXPIRED_TIMESTAMP`, `MALFORMED_CALLBACK`, `INVALID_AUTH_URL_SIGNATURE` - so you can branch on the code instead of the class if you prefer.


## Sitemap

See the full [sitemap](https://helix.id/sitemap.md) for all pages.
