Skip to main content
The API reports errors with the HTTP status code and a JSON body.

Status codes

Invalid input

Most 400 bodies name the problem per field:
A wrong email or password at login comes back under non_field_errors:
A reported-metrics push that is not a non-empty list returns a message:
A push with an invalid organization, asset, metric or interval in any item fails the whole request, and nothing is written. The body is a list with one object per item, empty for the valid ones:

Two-factor login

A wrong code at POST /v1/totp/login/ returns 400 with a message field; a missing code returns 400 under the code field. After too many wrong codes the account is locked, and the next POST /v1/login/ returns 429 with a message field.

Other errors

401, 403 and 404 return a detail message, as does a 429 from the login rate limit:
A wrong URL returns 404 with an HTML page instead of JSON.