Skip to content
xashadocs
Tab to a result · Enter to open · Esc to close

Guides

Errors and limits

Handle failures without revealing submitted values or assuming an uncertain request is safe to retry.

Error format#

json
{
  "error": {
    "code": "SECRET_UNAVAILABLE",
    "message": "This secret is no longer available."
  }
}

Status codes#

400INVALID_REQUEST
403ORIGIN_NOT_ALLOWED / PREFLIGHT_NOT_ALLOWED on restricted deployments
404SECRET_UNAVAILABLE / DELETE_UNAVAILABLE
405METHOD_NOT_ALLOWED
413PAYLOAD_TOO_LARGE
415UNSUPPORTED_MEDIA_TYPE
429RATE_LIMITED; Retry-After: 60
500INTERNAL_ERROR
503SERVICE_UNAVAILABLE

Limits#

Plaintext32 KiB UTF-8
Request48 KiB uncompressed JSON
Create10 attempts / IP / minute
Consume + delete120 attempts combined / IP / minute
Readiness60 attempts / IP / minute

Budgets are approximate and apply per Cloudflare location. Shared networks share budgets. All responses use Cache-Control: no-store. Compressed bodies are unsupported.

Retry handling#

Creation retries can create duplicates. Deletion retries can return 404 after an earlier success.