← Back to blog

Oracle Fusion REST API Error Code Reference: 400, 401, 403, 404, 412, 429, 500

By Mostafa Mansour 5 min read Oracle Fusion CloudREST APIError CodesReference

Oracle doesn’t publish one list of what its REST API error codes mean. Each module documents its own status codes separately — Procurement’s Status_Codes.html isn’t Project Management’s, isn’t Risk Management’s — so you end up stitching codes together from memory, forum threads, and trial and error. This site already has a deep-dive guide for each of the seven codes you’ll actually hit in practice. This page is the index: one table, every code, the one-line cause, and the guide with the full fix.

The error codes

CodeMeaningMost common causeFull guide
400 Bad RequestMalformed requestBad q syntax, missing required POST fields, wrong REST-Framework-Version, a DFF context/segment mismatch400 Bad Request guide
401 UnauthorizedFusion doesn’t know who you areWrong password, an expired OAuth access token, clock skew on iat/exp, a malformed Authorization headerAuthentication guide (401 vs 403 table) · OAuth token refresh guide (invalid_grant, token expiry mid-integration)
403 ForbiddenFusion knows exactly who you are and says noMissing job/duty role for that resource and method, or a data role that doesn’t cover the record’s business unit/legal entity — works fine in the Fusion UI, fails over RESTAuthentication guide
404 Not FoundResource or record doesn’t exist at that pathMissing version segment, a deprecated resource name, a wrong composite-key path — or, on a few resources, an authorization failure that returns 404 instead of 403404 Not Found guide
412 Precondition FailedYour If-Match ETag is staleSomeone else updated the record between your GET and your PATCHETag and If-Match guide
429 Too Many RequestsIdentity-domain rate limit hitToo many calls in the window for your identity domain, usually from a tight polling loop with no backoffRate limits guide
500 Internal Server ErrorSomething failed server-sideA transient platform failure (retry) vs. an endpoint-specific bug (won’t retry away) — the guide below covers telling them apart500 Internal Server Error guide

401 vs. 403 vs. 404 — the one mix-up worth memorizing

These three get confused constantly because they can all look like “it’s just not working”:

See the authentication guide’s full 401-vs-403 table for the complete breakdown with real Cloud Customer Connect thread examples.

First thing to check on any error

Before chasing the specific code, confirm what shape you actually got. Oracle’s error payload itself depends on your REST-Framework-Version — pre-v4 you get a plain error string, v4 and later gives you a structured object with o:errorCode, o:errorPath, and o:errorDetails you can branch on programmatically. See the framework versions guide if your error-handling code is still parsing a raw string.


This page indexes the error-code coverage across this site. For the base URLs, authentication, q filters, and finders that prevent most of these errors in the first place, see the Oracle Fusion API guide.

Explore Oracle Fusion APIs offline

OPAL bundles 59,000+ Oracle Fusion REST endpoints, fully searchable offline, with a visual Q Builder and Finder Builder that only offer fields the endpoint actually accepts — so your filter can't 400.

Free, no account required. Pro adds live requests and multi-step Flows.