Skip to main content

Errors and rate limits

Errors and status codes​

StatusCodeMeaning
400VALIDATION_ERROR (including a user.phone with no digit), CARD_NUMBER_DETECTED, NUL_CHARACTER_DETECTEDInvalid body. parameter names the field.
401AUTH_ERRORMissing or invalid key.
403SCOPE_ERROR, SANDBOX_KEY_FORBIDDEN, ACCOUNT_SHARED_ACROSS_PROJECTSKey lacks the scope, a sandbox key was used for an operation that needs a live one, or the account spans several projects.
404NOT_FOUNDUnknown event_id, account or case.
409EVENT_ID_CONFLICTevent_id reused with a different body.
413PAYLOAD_TOO_LARGEBody above the limit.
429RATE_LIMIT_EXCEEDEDSee rate limits.
500INTERNAL_ERRORScoring failed to persist. Safe to retry the same event_id and body.
503ASYNC_UNAVAILABLE, COMPILED_RULES_UNAVAILABLE, PROJECT_POLICY_UNAVAILABLE, RATE_LIMIT_UNAVAILABLEAsync ingestion, the compiled ruleset (sync only) or the project policy is unavailable, or the rate limiter is not ready. Nothing was scored or stored. Retry with backoff.

Per-endpoint status lists are in the API reference.

Rate limits​

Limits are counted per key, per method and route, in a fixed window (default 1m). Defaults of the service:

BucketDefault
Per key and route1000 requests / window
POST /v1/fp/collect, per key10 000 requests / window
POST /v1/fp/collect, per key and caller address60 requests / window
Failed key lookups (a well-formed key that does not exist or is inactive), per caller address60 / window

These are the service defaults; values configured for your deployment may differ. Once the failed-lookup limit is hit, further unknown keys from that address get 429 with Retry-After only. Other 429s carry Retry-After, RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset (all in seconds or counts as named); back off for Retry-After seconds.