Gateway Gus saysGood error responses use the right status code plus a structured, actionable body.
An error should carry a correct HTTP status and a machine-readable body: a stable error code, a human message, and ideally which field failed. The application/problem+json standard formalizes this. Stable codes let clients branch on the error type; clear messages help developers fix it. Never return 200 with an error hidden inside.
Power-ups you unlock
Correct status + structured body
Stable machine code + human message
Point at the offending field when relevant
problem+json is the standard shape
Timeout Titan attacks — common mistakes
200 OK wrapping an error
Only a vague string, no stable code
Leaking stack traces/internal details to clients
Boss battleDesign an error body for a failed validation on the "email" field.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>422 Unprocessable Entity
{ "code": "invalid_email",
"message": "Email is not valid",
"field": "email" }</pre></body></html>