Error codes

auth_failures_throttled

Too many failed authentications

HTTP 429

At launchSent from launch, once the origin lock and the partner security platform enforce.

Too many requests from your address (for IPv6, from its /64) failed authentication in the last minute, so this one is answered this way instead of with its 401: its key is missing or unknown, or it is a signed request that didn't verify or whose body doesn't match its Content-Digest. A signed request that doesn't verify can be, a revoked signed credential's included, since nothing about it is proven until it verifies. A bearer request whose key is valid, revoked or expired never is, unless it also carries Signature-Input, which makes it a signed request (401 signature_profile_invalid beside a bearer key); nor is a signed request that verified and whose body matched. Nor is one from an address many callers can share (a proxy or CDN range, a private network, carrier-grade NAT). Check the key or the signature, then retry after the seconds in Retry-After.

The problem body

Sent as application/problem+json, with the request id in request_id and the X-Request-Id header. Branch on code: the error and detail sentences can change, and some operations add members of their own.

Example problem
{
  "error": "Too many failed authentications",
  "code": "auth_failures_throttled",
  "type": "https://secondappraisal.com/developers/errors/auth_failures_throttled",
  "title": "Too many failed authentications",
  "status": 429,
  "detail": "Too many failed authentications",
  "instance": "/api/gap/v1/referrals",
  "request_id": "req_4f9a2c7e1b8d4a6f9c3e2b1a7d5f8e0c"
}

Operations that can send it