Skip to content

Errors and rate limits

Status codes, error codes and the limits on how often you can call the API.

Status codes

FieldTypeDescription
200 / 201successIt worked (201: created)
204successIt worked; nothing to return
400errorSomething in the request is wrong
401errorMissing, invalid or expired key or token (see WWW-Authenticate)
403errorMissing permission, address not in the IP allowlist, key blocked, or your plan doesn't include the API
404errorNot found (also anything that isn't yours)
409errorDuplicate (e.g. same invitation twice)
413errorThe request body is too large
415errorWrong Content-Type (send application/json)
429errorToo many requests
500errorOur problem; safe to retry

Error codes

FieldTypeDescription
invalid_key401The key is missing, wrong or revoked
invalid_token401The access token is missing, wrong or revoked
key_expired401The key has expired: create or rotate a key
token_expired401The access token has expired: request a new one
key_blocked403Our team blocked the key; the owner was emailed why
ip_not_allowed403The request came from an address outside the key's IP allowlist
https_required403The request came over plain HTTP
plan_required403The company's plan doesn't include the API
insufficient_scope403The key doesn't have the permission this request needs
invalid_request400A field is missing or wrong (see fields)
credentials_in_url400A key or token was sent in the address or body; only the Authorization header is accepted
business_required400Your key can use more than one business: name one
not_found404No such thing, or not yours
duplicate_invitation409This customer was invited in the last 30 days, or this order already has an invitation
unsubscribed409The customer unsubscribed from your invitations
idempotency_conflict409The Idempotency-Key was used with a different request
payload_too_large413The body is over 64 KB
unsupported_media_type415The body isn't Content-Type: application/json
rate_limited429Over the per-second limit; see Retry-After
too_many_auth_failures429Too many failed authentications from this address; wait a minute
monthly_limit_reached429Over the monthly limit until the next month
internal_error500Something went wrong on our side

Rate limits

10 requests per second per key, and a monthly total per company (Pro 100,000, Enterprise 1,000,000 or custom). Every response includes these headers.

FieldTypeDescription
RateLimit-LimitheaderRequests allowed per second for this key
RateLimit-RemainingheaderRequests left in this second
RateLimit-ResetheaderSeconds until the limit resets
RateLimit-Monthly-LimitheaderRequests allowed this month
RateLimit-Monthly-RemainingheaderRequests left this month
Retry-AfterheaderOn 429: seconds to wait
Request-IdheaderQuote it when you contact support
WWW-AuthenticateheaderOn 401 and insufficient_scope: what went wrong (RFC 6750)
HTTP/1.1 429 Too Many Requests
Retry-After: 1
RateLimit-Limit: 10
RateLimit-Remaining: 0
RateLimit-Reset: 1

{
  "error": {
    "code": "rate_limited",
    "message": "Too many requests. Try again in 1 second.",
    "request_id": "req_4Hq1x2"
  }
}
HTTP/1.1 400 Bad Request

{
  "error": {
    "code": "invalid_request",
    "message": "Something in the request is wrong.",
    "request_id": "req_9Tz0k1",
    "fields": [
      "email"
    ]
  }
}

Cookie settings

EssentialLog in, security and fraud checks
PreferencesRemember your country
AnalyticsNot used. We'll ask before we ever add any.