OAuth token endpoint
POST /oauth/token returns standard OAuth 2.0 error envelopes per RFC 6749 §5.2 with the codes invalid_request, invalid_client, and invalid_grant.
See Authentication → Error responses for the full table and remediation notes.
Unsubscribe API
/api/v1/unsubscribe* endpoints return 400, 401, 403, or 429 with the shared RestErrorResponse envelope (described below).
See Unsubscribe API → Error responses for status codes, sub-codes (bad_request, invalid_item, default_group_not_configured, invalid_cursor, unauthorized_organization, rate_limited), and per-endpoint failure modes.
Response body shape
REST API endpoints share this JSON envelope:error — it is stable and machine-readable. Log error_description for humans; its wording may change without notice. Some errors carry additional fields alongside the pair (e.g. item_index / item_error on batch rejections, or an echoed org_slug / group_id on authorization failures) — see Unsubscribe API → Error responses.
POST /oauth/token uses the RFC 6749 §5.2 envelope, which carries the same error + error_description field names. See Authentication → Error responses for the OAuth-specific codes.

