Skip to main content

Errors and limits

Match the HTTP status and the response's error code. Additional fields describe the failure; validation responses can also include a detail list.

{ "error": "rate_limited", "retry_after_seconds": 21 }

Errors by status​

StatusCommon codesAction
400invalid_input, invalid_content_length, field_type_conflict, missing_link_ids, too_many_link_ids, unknown_query_parameterCorrect the named field or reduce the request.
401auth_failedStop requests and correct the API key or environment.
403insufficient_scope, tenant_disabled, live_ingest_not_entitled, plan_upgrade_requiredStop requests and resolve the missing scope or account access.
404predictions_not_enabledConfirm prediction serving is enabled in the deployment.
411length_requiredSend Content-Length with the request body.
413request_too_large, batch_too_largeSplit the payload before retrying.
422validation_error, endpoint-specific validation codesCorrect the input. Inspect detail and the endpoint reference.
429auth_lockout, rate_limitedFollow the distinct recovery steps below.
500internal_errorRecord the incident_id, if present, for support.
503telemetry_unavailable, tenant_unavailable, prediction_store_unavailable, ingest_buffer_full, entitlement_unavailableRespect the retry delay. Contact support if the failure persists.

Endpoint-specific errors are listed under Telemetry, Topology, and Predictions.

Failed-auth lockout​

HTTP authentication lockout is separate from request rate limiting. The server defaults are:

ScopeFailure thresholdLockout duration
Client IP and credential pair5 failures within 300 seconds300 seconds
Client IP50 failures within 300 seconds900 seconds

A locked IP-and-credential pair or client IP receives 429 auth_lockout. The pair lock affects that credential from that IP. An IP-wide lock also blocks a corrected key until it expires. Thresholds can vary by environment.

Stop the client producing authentication failures, fix its credential, and wait the full Retry-After delay. Clients sharing an outbound IP can be affected by the same IP lockout. Do not keep probing a rejected key.

Rate limits​

The HTTP server defaults are:

ScopeLimit
Client IP300 requests/minute
Authenticated account or tenant300 requests/minute sustained
Authenticated account or tenant burst20 requests/second

Limits can vary by environment. HTTP middleware limits and lockouts are separate from gRPC ingest handling. /health and /health/* are exempt. Other unauthenticated requests and failed authentication attempts consume the client-IP budget.

Exceeding a traffic limit returns 429 rate_limited. Pause requests that share the affected budget and honor Retry-After. Batch requests and reduce polling frequency if the limit recurs.

Body limits​

HTTP limitMaximum
Request body1 MiB (1,048,576 bytes)
Telemetry batch1,000 records

Both limits apply; split by encoded body size as well as record count. Body-carrying requests require Content-Length. The gRPC telemetry contract has its own batch limits.

Retry guidance​

ResultClient behavior
401 or 403Stop automated requests. Correct the credential, scope, or access configuration before resuming.
429 auth_lockoutStop the failing client, fix authentication, and wait the full retry delay.
429 rate_limitedWait the full retry delay and reduce the request rate if it recurs.
503 or a failed readUse bounded exponential backoff with jitter. Honor a server-provided retry delay.
Other 4xxCorrect the request before retrying; reconcile any store-side partial write.
Ambiguous telemetry writeReconcile the batch before replaying it.

Retry-After can be a number of seconds or an HTTP date. If it is absent, use a valid retry_after_seconds response field; otherwise use bounded exponential backoff. Add jitter after the required wait, and never shorten a server-provided delay with a local backoff cap.

Telemetry writes have no request idempotency key. If a connection drops or a write times out after submission, the batch may already have been accepted. Check delivery before replaying it. On partial acceptance, inspect the rejection details and resend only corrected rejected records. See Telemetry.