Errors and rate limits

Woven and the API gateway both return machine-readable bodies that name the exact problem. HTTP clients that raise on status alone discard that text, and the status codes on their own are ambiguous. Always read the response body. In Python, print response.text before calling raise_for_status().

401 - Access denied due to missing subscription key

No Subscription-Key header. Add it. This applies to the login call as well as every other request.

401 - Access denied due to invalid subscription key

Wrong key, or the right key for the wrong environment. Keys are per-environment. Copy it again from Profile on the portal you are calling.

401 - Unauthorized

Missing, expired or malformed AccessToken. Get a new token. A freshly issued one lasts 7 days.

200 with a null AccessToken

Your Woven username or password is wrong. Note this is a 200, not a 401. Check that AccessToken is non-null and FailedLoginAttempt is false on every login before using the token.

400 - Model state is invalid

A field failed to bind. The message names the field and the value it received. Sending an empty string or null for a field that expects a GUID is the usual cause. Omit the field instead of sending an empty value.

429 - Rate limit is exceeded

You have gone over 100 requests in a minute. The message names the number of seconds until the window resets. Wait that long, then retry.

Rate limit

100 requests per minute per subscription key. The limit is counted on the key, so every process sharing a key shares the budget.

If you are running a scheduled bulk load that needs more headroom, contact support@startwoven.com with your subscription name and the window you run in.