type and code fields, a
request_id, and a documentation link. The legacy error string remains for
compatibility; validation failures can also include an errors list.
The same id is in the
X-Request-Id response header.
Status codes
Do not retry
4xx except 429 after Scan extends the sandbox. Implement
exponential backoff on 429 and 5xx even when you are not currently hitting a
production RPS cap.
Common codes
unauthorized
HTTP401. The Authorization header is missing, the token is not a valid
Partner API token, or you sent a sandbox token to production (or the reverse).
Rotate or re-issue the token from the matching environment and retry.
api_token_expired
HTTP401. The 7-day sandbox window has elapsed.
Email [email protected] with the request_id for an extension,
or request a new sandbox.
sandbox_request_limit_reached
HTTP429. The 2,000-successful-request sandbox allowance is used up.
Email [email protected] with the request_id for an extension.
Access codes apply only when requesting the initial sandbox token.
endpoint_not_enabled
HTTP403. The permission matrix does not grant this operation for the
authenticated group.
Ask Scan to enable the capability. Changing the request body will not unblock it.
not_found
HTTP404. The id does not exist, or it belongs to another group.
Use an id returned to this token. Do not retry the same id.
unprocessable_entity
HTTP400 or 422. The body failed validation (errors lists the fields).
Fix the payload using the errors array and retry. Failed 4xx requests do not
count toward the sandbox allowance.
internal_error
HTTP5xx. Scan or an upstream dependency failed.
Retry with exponential backoff. Include the request_id if it persists.
Limits
Production Partner API tokens do not have an application-level RPS cap in this API today. Scan may introduce production rate limits; treat429 as retryable
with backoff regardless of environment. Today, a sandbox 429 means its request
allowance has been used up; it is not a general production rate limit.
The self-serve sandbox allows 2,000 successful requests or 7 days,
whichever comes first. Requests that return 4xx or 5xx do not count toward
the allowance, so correcting a validation error does not use it up.
GET list endpoints that return 200 do count.
When the cap is used up:
request_id for an
extension. Access codes are accepted only on the initial Get API keys
request. See Authentication.
