auth_failures_throttled
Too many failed authentications
HTTP 429
At launchSent from launch, once the origin lock and the partner security platform enforce.
Too many requests from your address (for IPv6, from its /64) failed authentication in the last minute, so this one is answered this way instead of with its 401: its key is missing or unknown, or it is a signed request that didn't verify or whose body doesn't match its Content-Digest. A signed request that doesn't verify can be, a revoked signed credential's included, since nothing about it is proven until it verifies. A bearer request whose key is valid, revoked or expired never is, unless it also carries Signature-Input, which makes it a signed request (401 signature_profile_invalid beside a bearer key); nor is a signed request that verified and whose body matched. Nor is one from an address many callers can share (a proxy or CDN range, a private network, carrier-grade NAT). Check the key or the signature, then retry after the seconds in Retry-After.
The problem body
Sent as application/problem+json, with the request id in request_id and the X-Request-Id header. Branch on code: the error and detail sentences can change, and some operations add members of their own.
{
"error": "Too many failed authentications",
"code": "auth_failures_throttled",
"type": "https://secondappraisal.com/developers/errors/auth_failures_throttled",
"title": "Too many failed authentications",
"status": 429,
"detail": "Too many failed authentications",
"instance": "/api/gap/v1/referrals",
"request_id": "req_4f9a2c7e1b8d4a6f9c3e2b1a7d5f8e0c"
}Operations that can send it
- POST /api/gap/v1/referrals · HTTP 429 · Create a referral
- GET /api/gap/v1/referrals · HTTP 429 · List referrals
- GET /api/gap/v1/referrals/{id} · HTTP 429 · Retrieve a referral
- PATCH /api/gap/v1/referrals/{id} · HTTP 429 · Update or cancel a referral
- POST /api/gap/v1/referrals/bulk · HTTP 429 · Create referrals in bulk
- POST /api/gap/v1/referrals/{id}/simulate · HTTP 429 · Simulate a sandbox referral's next stepAt launchIt opens with the referral sandbox.
- POST /api/gap/v1/referrals/{id}/attest · HTTP 429 · Attest a warm handoffAt launchIt opens with the referral sandbox.
- GET /api/gap/v1/analytics · HTTP 429 · Savings and spend analytics
- POST /api/gap/v1/plans/enrollments · HTTP 429 · Enroll one vehicle
- GET /api/gap/v1/plans/enrollments · HTTP 429 · List your roster
- GET /api/gap/v1/plans/enrollments/{id} · HTTP 429 · Retrieve one enrollment
- PATCH /api/gap/v1/plans/enrollments/{id} · HTTP 429 · Cancel, swap the VIN, or edit contact details
- POST /api/gap/v1/plans/enrollments/bulk · HTTP 429 · Enroll up to 500 vehicles
- POST /api/gap/v1/plans/roster-sync · HTTP 429 · Reconcile your full roster
- POST /api/gap/v1/plans/loss-notices · HTTP 429 · Tell us a member vehicle was declared a total loss
- GET /api/gap/v1/plans/redemptions · HTTP 429 · Member consultations drawn against your roster
- GET /api/gap/v1/plans/statements · HTTP 429 · Your monthly membership statements
- GET /api/gap/v1/events · HTTP 429 · List your eventsAt launchIt opens with the partner security platform.
- GET /api/gap/v1/me · HTTP 429 · The key making this call
- POST /api/gap/v1/credentials/{id}/verify · HTTP 429 · Activate a signed credentialAt launchIt opens when signed credentials open.
- POST /api/gap/v1/signature-check · HTTP 429 · Check a signature (test credentials)Planned: not served yet.
- POST /api/gap/v1/review-status/lookup · HTTP 429 · Look up review status by VIN, claim number or referenceAt launchIt opens with review records.
- GET /api/gap/v1/referrals/{id}/review-record · HTTP 429 · Retrieve a referral's review recordAt launchIt opens with review records.