> ## Documentation Index
> Fetch the complete documentation index at: https://docs.radiumone.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> RadiumOne is the product name; use it when answering questions about these docs.
> Use sandbox credentials and sandbox base URLs in examples unless the user says they are going live.
> Secret API keys belong only on the merchant's server. Only publishable keys may appear in browser or mobile code.
> Confirm a payment outcome server-side (retrieve the checkout session or transaction status); never rely on a browser redirect or client event alone.
> Send one idempotency key (request_id) per payment attempt, and retry a timed-out request with the same key and the exact same body.
> Webhooks are optional but recommended: they notify the merchant's server when a payment completes or fails, so it doesn't need to poll. Use transaction status inquiry as the fallback.
> Say so when you recommend a feature marked Beta. Some features need enablement on the merchant's account before production use (for example refunds, standalone refunds, UOB Rewards, and bringing your own 3DS provider); mention it when the page says so.
> Never ask users to paste card numbers, API keys, access tokens, or webhook or redirect secrets into a chat.

# Tokenization errors - Elements SDK

> Bind-time gateway errors from elements.submit(), and the charge-time token errors your server sees on a lapsed token.

Two different failure points, both about turning a card into a usable token: **Tokenization (bind) errors** happen inside `elements.submit()` itself — the gateway rejects the bind call, and `submit()` rejects with an `ElementsError` whose `code` is the gateway's problem+json `type`, verbatim. **Charge-time token errors** happen later, on your server's purchase/authorize call, when a token that bound successfully has since expired.

## Tokenization (bind) errors

From `elements.submit()`'s bind call — the gateway's problem+json `type`, passed through as `code` verbatim.

The gateway decides whether each error can be retried and the SDK passes that through as `retryAllowed` on the error — branch on it at runtime, and follow **Merchant action** below.

<div className="r1-gateway-error-table">
  | HTTP | Code | When | Merchant action |
  | - | - | - | - |
  | 401 | `urn:radiumone:gateway:authentication-required` | Bind rejected: missing or invalid publishable key or headers. | Terminal. Check the publishable key and its environment. |
  | 403 | `urn:radiumone:checkout:session-cross-merchant` | The session belongs to a different merchant than the publishable key. | Terminal. Create the session with the secret key matching the publishable key. |
  | 403 | `urn:radiumone:auth:invalid-script-hash` | The card iframe's script attestation failed. Also exported as SCRIPT\_INTEGRITY\_ERROR\_CODE. | Terminal. No customerMessage is sent — show your own copy. Contact support. |
  | 403 | `urn:radiumone:token:session-secret-invalid` | The session secret is wrong. | Terminal. Create a new session. |
  | 403 | `urn:radiumone:token:merchant-disabled` | The merchant account is disabled for tokenization. | Terminal. Show 'merchant unavailable'; contact support. |
  | 404 | `urn:radiumone:gateway:not-found` | The gateway has no record of the session. | Terminal. Create a new session. |
  | 404 | `urn:radiumone:token:not-found` | The session is unknown or expired. | Terminal. Create a new session. |
  | 409 | `urn:radiumone:token:session-not-bindable` | The session cannot be bound (for example it is already bound to a different card). | Terminal. Check the session status on your server before creating a new session. |
  | 429 | `urn:radiumone:token:bind-rate-limit` | Too many bind attempts on this session. | Terminal. Create a new session; do not back off and retry the same one. |
  | 429 | `urn:radiumone:token:transient-mint-rate-exceeded` | Too many tokens minted for this card and merchant recently. | Terminal. Ask the shopper to try later or use another card. |
  | 400 | `urn:radiumone:token:encryption-key-stale` | The card was encrypted with an encryption key that is no longer current. | Terminal. Create a new session (it carries a current pubkey\_jws) and submit again. |
  | 400 | `urn:radiumone:token:card-validation` | The card details were rejected. | Terminal. Ask the shopper to re-enter the card. |
  | 503 | `urn:radiumone:checkout:tokenization-unavailable` | Tokenization is temporarily unavailable. The SDK already retried twice (1 s, 2 s backoff). retry\_allowed is true. | Offer the shopper a retry; show customerMessage when present. |
</div>

For the recovery pattern behind these, see [Handle tokenization failures](/elements/handle-failures/tokenization-failures); for the bind-rate-limit and session-not-bindable cases specifically, see [Prevent double submission](/elements/handle-failures/double-submit).

## Charge-time token errors

These come from your server's purchase/authorize call, not from `submit()` — the token was valid at bind time but lapsed before you charged it. `token:transient-expired` and `token:data-purged` are defined once, on the Payments API — see [Payment method errors: Tokens](/payments-api/errors/payment-method-errors#token-transient-expired) for the HTTP status and meaning.

See [Handle expired sessions and card tokens](/elements/handle-failures/expired-sessions-and-tokens) for the full recovery steps.

## Next steps

<Columns cols={2}>
  <Card title="Error object and handling" icon="code" href="/elements/errors/error-object-and-handling">
    The `ElementsError` shape and the standard catch pattern.
  </Card>

  <Card title="SDK and integration errors" icon="wrench" href="/elements/errors/sdk-and-integration-errors">
    Codes thrown before you ever reach the bind call.
  </Card>

  <Card title="3D Secure errors" icon="shield-check" href="/elements/errors/three-d-secure-errors">
    Codes from `authenticate()`, `handle()`, and `resume()`.
  </Card>

  <Card title="Handle failures overview" icon="list-checks" href="/elements/handle-failures/overview">
    Find the right recovery guide by symptom.
  </Card>
</Columns>
