Guides
Errors and limits
Handle failures without revealing submitted values or assuming an uncertain request is safe to retry.
Error format#
{
"error": {
"code": "SECRET_UNAVAILABLE",
"message": "This secret is no longer available."
}
}Status codes#
| 400 | INVALID_REQUEST |
| 403 | ORIGIN_NOT_ALLOWED / PREFLIGHT_NOT_ALLOWED on restricted deployments |
| 404 | SECRET_UNAVAILABLE / DELETE_UNAVAILABLE |
| 405 | METHOD_NOT_ALLOWED |
| 413 | PAYLOAD_TOO_LARGE |
| 415 | UNSUPPORTED_MEDIA_TYPE |
| 429 | RATE_LIMITED; Retry-After: 60 |
| 500 | INTERNAL_ERROR |
| 503 | SERVICE_UNAVAILABLE |
Limits#
| Plaintext | 32 KiB UTF-8 |
| Request | 48 KiB uncompressed JSON |
| Create | 10 attempts / IP / minute |
| Consume + delete | 120 attempts combined / IP / minute |
| Readiness | 60 attempts / IP / minute |
Budgets are approximate and apply per Cloudflare location. Shared networks share budgets. All responses use Cache-Control: no-store. Compressed bodies are unsupported.
Retry handling#
Creation retries can create duplicates. Deletion retries can return 404 after an earlier success.