Check register / Errors-Validation-Security

ERR-003

A requirement the spck.dev suite checks on UCP servers. The quoted text is the normative requirement; the citation links to the exact line of the pinned spec source it was taken from.

2026-01-11:

The error code field MUST be a string; defined values include missing, invalid, out_of_stock, payment_declined, requires_sign_in, requires_3ds, requires_identity_linking, with freeform codes also allowed.

2026-01-23:

The error code field MUST be a string; defined values include missing, invalid, out_of_stock, payment_declined, requires_sign_in, requires_3ds, requires_identity_linking, with freeform codes also allowed.

2026-04-08:

Error message severity MUST be one of recoverable, requires_buyer_input, requires_buyer_review, unrecoverable.
Keyword
MUST
Area
Errors-Validation-Security
Versions
2026-01-11 2026-01-23 2026-04-08
Testability
testable
Spec source
ucp:source/schemas/shopping/types/message_error.json#L18-L21 2026-01-11
ucp:source/schemas/shopping/types/message_error.json#L18-L21 2026-01-23
ucp:source/schemas/shopping/types/message_error.json#L40 2026-04-08

How this is graded

A deviation on a MUST fails the run and shows the requirement next to the actual response. Checks the suite cannot validate soundly are reported inconclusive or not-tested — never a silent pass. The full verdict semantics are on the grading rubric.

Run it against your store

The hosted check covers the read-only surface; the CLI and GitHub Action run the full suite, including this check when your store declares the capability it belongs to.