Skip to content
TUMR DOCS
DocsguidesErrors, pagination and retries

Errors, pagination and retries

Handle API responses according to the actual endpoint contract.

Validation failures normally use HTTP 400 and include field errors or a detail message. Missing or inaccessible tenant resources return 404. Authentication failures return 401; insufficient permissions return 403. Throttling returns 429. Payment provider unavailability may return 503.

DRF list endpoints commonly return count, next, previous and results with a default page size of 20. Some console endpoints return their own results and summary shape. Follow next where present; do not assume all lists use one envelope.

Retry GET requests with bounded exponential backoff. Retry a mutating call only when its endpoint documents an idempotency contract or when you have checked the resulting resource first. Distribution store provisioning uses idempotency_key; reusing one key with a different payload is a conflict. Webhook consumers should deduplicate event IDs and verify signatures before processing.

Production throttle defaults include 20 anonymous requests per minute and 200 authenticated requests per minute. Specific actions can have separate limits. Do not rely on a universal rate limit header.