Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

On this page

IDEMPOTENCY_KEY_REUSED

An Idempotency-Key was reused with another body.

An Idempotency-Key was reused with another body.

HTTP 422 · gRPC INVALID_ARGUMENT · the error body

#Returned by

MethodScopeWhat it does
access.orgs.createaccess:adminCreates an org. Access assigns the id.
access.orgs.updateaccess:adminUpdates an org.
access.orgs.deleteaccess:adminDeletes an org and everything in it. Deletion cascades through every service, so it returns an Operation.
access.projects.createaccess:adminCreates a project. Access assigns the id.
access.projects.updateaccess:adminUpdates a project.
access.projects.deleteaccess:adminDeletes a project.
access.envs.createaccess:adminCreates an environment. Access assigns the id.
access.envs.updateaccess:adminUpdates an environment.
access.envs.deleteaccess:adminDeletes an environment.
access.api_keys.createaccess:keys:writeCreates an API key. Access assigns the id.
access.api_keys.updateaccess:keys:writeUpdates an API key.
access.api_keys.deleteaccess:keys:writeDeletes an API key.
access.api_keys.revokeaccess:keys:writeRevokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data.
access.api_keys.rollaccess:keys:writeRolls an API key: returns a new key with the same spec and revokes the old one after the grace period.
artifacts.artifacts.createartifacts:writeRegisters an artifact whose bytes were pushed by digest; verification runs after.
artifacts.artifacts.deleteartifacts:writeDeletes an artifact; fails while a Release references it or a legal hold is active.
assets.assets.generateassets:writeRecords the recipes as assets and generates the variants that are missing. Each call is idempotent and works within a bounded time; call again until pending is 0.
assets.assets.approve_variantassets:writeApproves one variant and records who approved it.
assets.assets.reject_variantassets:writeRejects one variant. Its slot is freed and the next :generate fills it; the rejected file keeps serving at its URL.
assets.assets.retire_variantassets:writeRetires one variant. Its URL answers 404 from then on and its slot is freed.
auth.auth_configs.updateauth:writeUpdates an auth config.
auth.end_users.createauth:writeCreates an end user.
auth.end_users.updateauth:writeUpdates an end user.
auth.end_users.deleteauth:writeDeletes an end user.
auth.end_users.suspendauth:writeSuspends an end user: sessions are revoked and sign-in is refused.
auth.end_users.reactivateauth:writeReactivates a suspended end user.
auth.end_users.unlockauth:writeClears an end user's sign-in lock (repeated failed sign-ins) now.
auth.end_users.revoke_sessionsauth:writeRevokes every session of an end user.
auth.sessions.revokeauth:writeRevokes a session.
auth.customer_organizations.createauth:writeCreates a customer organization.
auth.customer_organizations.updateauth:writeUpdates a customer organization.
auth.customer_organizations.deleteauth:writeDeletes a customer organization.
auth.memberships.createauth:writeCreates a membership.
auth.memberships.updateauth:writeUpdates a membership.
auth.memberships.deleteauth:writeDeletes a membership.
auth.organization_roles.createauth:writeCreates an organization role.
auth.organization_roles.updateauth:writeUpdates an organization role.
auth.organization_roles.deleteauth:writeDeletes an organization role.
auth.invitations.createauth:writeCreates an invitation.
auth.invitations.revokeauth:writeRevokes a pending invitation.
auth.invitations.acceptauth:writeAccepts a pending invitation for an end user whose verified email is the invited address, and creates the membership.
auth.email_domains.createauth:writeCreates an email domain; the answer names the TXT record to publish.
auth.email_domains.deleteauth:writeDeletes an email domain.
auth.email_domains.verifyauth:writeLooks up the domain's TXT record now; found, the domain is verified.
auth.oauth_clients.createauth:writeCreates an OAuth client.
auth.oauth_clients.updateauth:writeUpdates an OAuth client.
auth.oauth_clients.deleteauth:writeDeletes an OAuth client.
auth.oauth_clients.roll_secretauth:writeIssues a new client secret, returned once; the old one verifies until grace_period ends.
billing.billing_accounts.updatebilling:adminUpdates a billing account: changes plan, spend limit, or billing email.
broker.trust_policies.createbroker:adminCreates a trust policy.
broker.trust_policies.updatebroker:adminUpdates a trust policy.
broker.trust_policies.deletebroker:adminDeletes a trust policy.
build.builds.createbuild:writeCreates a build. The Operation is done when the controller settles it.
build.builds.cancelbuild:writeCancels a queued or running Build; its lease is released and nothing is published.
build.build_caches.updatebuild:writeUpdates a build cache.
build.build_caches.deletebuild:writeDeletes a build cache.
config.config_flags.createconfig:writeCreates a config flag; the Operation is done when every cell serves it.
config.config_flags.updateconfig:writeUpdates a config flag; the change rolls out in waves and the Operation is done when every cell serves it.
config.config_flags.deleteconfig:writeDeletes a config flag; evaluators then get their compiled-in fallback.
config.config_segments.createconfig:writeCreates a config segment.
config.config_segments.updateconfig:writeUpdates a config segment; every flag naming it follows.
config.config_segments.deleteconfig:writeDeletes a config segment; refused while a flag names it.
connections.connection_providers.createconnections:adminCreates a connection provider.
connections.connection_providers.updateconnections:adminUpdates a connection provider.
connections.connection_providers.deleteconnections:adminDeletes a connection provider; it must have no connections.
connections.connections.createconnections:writeRecords an installation; the controller confirms it with the provider.
connections.connections.updateconnections:writeUpdates a connection's metadata.
connections.connections.deleteconnections:writeForgets a connection. The installation itself is removed at the provider.
data.databases.createdata:writeCreates a database. The Operation is done when the controller settles it.
data.databases.updatedata:writeUpdates a database.
data.databases.deletedata:writeDeletes a database. Fails while spec.deletion_protection is set.
data.databases.rotate_credentialsdata:writeReplaces the database's engine credentials; the old ones stop working once the new ones are served.
data.databases.restoredata:writeRestores the database in place to a point in time inside its retention window; the database is unavailable while it restores.
data.kv_namespaces.createdata:writeCreates a kv namespace. The Operation is done when the controller settles it.
data.kv_namespaces.updatedata:writeUpdates a kv namespace.
data.kv_namespaces.deletedata:writeDeletes a kv namespace. Fails while spec.deletion_protection is set.
data.kv_namespaces.rotate_credentialsdata:writeReplaces the KV namespace's engine credentials; the old ones stop working once the new ones are served.
data.buckets.createdata:writeCreates a bucket. The Operation is done when the controller settles it.
data.buckets.updatedata:writeUpdates a bucket.
data.buckets.deletedata:writeDeletes a bucket. Fails while spec.deletion_protection is set.
data.buckets.rotate_credentialsdata:writeReplaces the bucket's engine credentials; the old ones stop working once the new ones are served.
data.search_indexes.createdata:writeCreates a search index. The Operation is done when the controller settles it.
data.search_indexes.updatedata:writeUpdates a search index.
data.search_indexes.deletedata:writeDeletes a search index. Fails while spec.deletion_protection is set.
data.search_indexes.rotate_credentialsdata:writeReplaces the search index's engine credentials; the old ones stop working once the new ones are served.
events.topics.createevents:writeCreates a topic.
events.topics.updateevents:writeUpdates a topic.
events.topics.deleteevents:writeDeletes a topic.
events.subscriptions.createevents:writeCreates a subscription.
events.subscriptions.updateevents:writeUpdates a subscription.
events.subscriptions.deleteevents:writeDeletes a subscription.
events.queues.createevents:writeCreates a queue.
events.queues.updateevents:writeUpdates a queue.
events.queues.deleteevents:writeDeletes a queue.
events.queues.replayevents:writeMoves dead-lettered messages, optionally bounded by dead-letter time, back to ready.
events.webhook_endpoints.createevents:writeCreates a webhook endpoint.
events.webhook_endpoints.updateevents:writeUpdates a webhook endpoint.
events.webhook_endpoints.deleteevents:writeDeletes a webhook endpoint.
events.webhook_endpoints.replayevents:writeRedelivers every dead-lettered delivery to the endpoint created in a time range, each as a new attempt.
events.webhook_endpoints.rotate_secretevents:writeReplaces the endpoint's signing secret and returns the new one, once (status.signing_secret). For 24 hours deliveries carry a signature with each secret, so a receiver can switch without dropping one.
events.webhook_endpoints.testevents:writeSends a test event (type sylphx.webhook.test) to the endpoint alone, through the same signing, retries, and delivery log as any other event.
events.webhook_deliveries.replayevents:writeRedelivers one delivery now, as a new attempt.
events.inbound_endpoints.createevents:writeCreates an inbound endpoint.
events.inbound_endpoints.updateevents:writeUpdates an inbound endpoint.
events.inbound_endpoints.deleteevents:writeDeletes an inbound endpoint.
events.realtime_channels.createevents:writeCreates a realtime channel.
events.realtime_channels.updateevents:writeUpdates a realtime channel.
events.realtime_channels.publishevents:publishPublishes one message to the channel: it is appended to the channel's history and pushed to every connected client. A retry with the same Idempotency-Key returns the first message.
events.realtime_channels.deleteevents:writeDeletes a realtime channel.
hosting.services.createhosting:writeCreates a service. The Operation is done when the controller settles it.
hosting.services.updatehosting:writeUpdates a service.
hosting.services.deletehosting:writeDeletes a service.
hosting.service_rollouts.createhosting:writeCreates a rollout.
hosting.service_rollouts.pausehosting:writeHolds a Rollout at its current wave.
hosting.service_rollouts.resumehosting:writeResumes a paused Rollout.
hosting.service_rollouts.aborthosting:writeStops a Rollout; the cells it reached return to the previous Release.
hosting.previews.createhosting:writeCreates a preview. The Operation is done when the controller settles it.
hosting.previews.deletehosting:writeDeletes a preview.
hosting.source_links.createhosting:writeCreates a source link. The Operation is done when the controller settles it.
hosting.source_links.updatehosting:writeUpdates a source link.
hosting.source_links.deletehosting:writeDeletes a source link.
keys.keys.createkeys:writeCreates a key; the signer generates its first version.
keys.keys.updatekeys:writeUpdates a key's rotation period, deletion protection, or metadata.
keys.keys.deletekeys:writeDeletes a key and schedules every version's destruction.
keys.keys.rotatekeys:writeRotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed.
keys.key_versions.destroykeys:writeSchedules a key version's destruction after a 24-hour grace; the primary version cannot be destroyed.
localization.catalogs.createlocalization:writeCreates a catalog.
localization.catalogs.updatelocalization:writeUpdates a catalog.
localization.catalogs.deletelocalization:writeDeletes a catalog.
localization.catalogs.synclocalization:writeReads the source files and the committed translations into the catalog, then translates what is new or stale. Each call is idempotent and works within a bounded time; call again until pending is 0.
localization.entries.pin_translationlocalization:writeSets the text of one locale as a human override that AI never overwrites. QA runs on the text first; a text with a QA error is rejected with INVALID_FIELD, and the problem lists the findings.
localization.entries.unpin_translationlocalization:writeRemoves the human override of one locale; the next sync may translate it again.
localization.glossaries.createlocalization:writeCreates a glossary.
localization.glossaries.updatelocalization:writeUpdates a glossary.
localization.glossaries.deletelocalization:writeDeletes a glossary.
money.price_catalogs.updatebilling:writeUpdates the environment's catalog: its features and products, whole.
money.store_connections.createbilling:writeCreates a store connection; its credential is sealed and never returned.
money.store_connections.updatebilling:writeUpdates a store connection; a new credential replaces the stored one.
money.store_connections.deletebilling:writeDeletes a store connection and its sealed credential.
money.customer_subscriptions.update_quantitybilling:writeChanges the seat quantity of a web subscription, now, and syncs the processor's subscription item to it. A retry with the same Idempotency-Key (required) and the same request changes nothing twice.
money.checkout_sessions.createbilling:writeCreates a hosted checkout for a subject.
money.portal_sessions.createbilling:writeCreates a customer portal session for a subject.
network.domains.createnetwork:writeCreates a domain. The Operation is done when the controller settles it.
network.domains.updatenetwork:writeUpdates a domain.
network.domains.deletenetwork:writeDeletes a domain.
network.domains.verifynetwork:writeChecks the verification record now instead of at the next sweep.
network.routes.createnetwork:writeCreates a route. The Operation is done when the controller settles it.
network.routes.updatenetwork:writeUpdates a route.
network.routes.deletenetwork:writeDeletes a route.
network.egress_identities.createnetwork:writeCreates an egress identity. The Operation is done when the controller settles it.
network.egress_identities.updatenetwork:writeUpdates an egress identity.
network.egress_identities.deletenetwork:writeDeletes an egress identity.
network.private_links.createnetwork:writeCreates a private link. The Operation is done when the controller settles it.
network.private_links.updatenetwork:writeUpdates a private link.
network.private_links.deletenetwork:writeDeletes a private link.
notify.mail_domains.createnotify:writeCreates an email domain.
notify.mail_domains.updatenotify:writeUpdates an email domain.
notify.mail_domains.deletenotify:writeDeletes an email domain.
notify.mail_routes.createnotify:writeCreates a route.
notify.mail_routes.updatenotify:writeUpdates a route.
notify.senders.createnotify:writeCreates a sender.
notify.senders.updatenotify:writeUpdates a sender.
notify.senders.deletenotify:writeDeletes a sender.
notify.recipients.createnotify:writeCreates a recipient.
notify.recipients.updatenotify:writeUpdates a recipient.
notify.recipients.deletenotify:writeDeletes a recipient.
notify.preferences.updatenotify:writeUpdates a preference.
notify.preferences.deletenotify:writeDeletes a preference.
notify.suppressions.createnotify:writeCreates a suppression.
notify.suppressions.deletenotify:writeDeletes a suppression.
notify.templates.createnotify:writeCreates a template.
notify.templates.updatenotify:writeUpdates a template.
notify.templates.deletenotify:writeDeletes a template.
notify.messages.createnotify:sendSends a Message.
notify.messages.cancelnotify:sendCancels a Message whose deliveries have not been handed off.
notify.mailboxes.createnotify:writeCreates a mailbox.
notify.mailboxes.updatenotify:writeUpdates a mailbox.
notify.mailboxes.erase_addressnotify:writeRemoves an address's personal data from every inbound email of the mailbox that it sent or that names it, keeping the dedupe keys so a poll never brings the mail back.
notify.inbox_items.mark_readnotify:writeMarks an inbox item read.
notify.inbox_items.mark_unreadnotify:writeMarks an inbox item unread.
notify.inbox_items.archivenotify:writeArchives an inbox item.
notify.broadcasts.createnotify:writeCreates a broadcast.
notify.broadcasts.updatenotify:writeUpdates a broadcast.
notify.broadcasts.deletenotify:writeDeletes a broadcast.
notify.broadcasts.sendnotify:sendSends a Broadcast now.
notify.broadcasts.cancelnotify:sendCancels a Broadcast; messages already admitted still deliver.
observability.log_entries.writeobservability:ingestIngests a batch of log entries atomically. The same Idempotency-Key and digest replays the same batch; a different digest under the key conflicts.
observability.traces.write_spansobservability:ingestIngests a batch of spans atomically; a span's parent and time invariants are validated. Replay rules are those of WriteLogEntries.
observability.error_groups.captureobservability:ingestCaptures one error occurrence. It is grouped by fingerprint when the caller sets one, else by exception type and the symbolicated in-app stack; release is never part of the group. A new occurrence reopens a resolved group. Secrets and personal data are scrubbed by the environment's Scrubbing Policy before storage. A fingerprint-equal replay bills no second new-error unit. Under quota pressure the response says what to sample. Browsers call it with a publishable key that holds observability:ingest (CORS allowed, rate-limited per environment).
observability.error_groups.acknowledgeobservability:writeAcknowledges an error group.
observability.error_groups.resolveobservability:writeResolves an error group; a new occurrence reopens it.
observability.error_groups.reopenobservability:writeReopens a resolved or acknowledged error group.
observability.source_maps.createobservability:writeUploads a source map for one release and minified file. Uploading the same release and file again replaces it.
observability.scrubbing_policies.updateobservability:writeUpdates the environment's scrubbing policy.
release.releases.createrelease:writeCreates a release: admits it and rolls it out in waves. The Operation is done when the release is live or halted.
runners.scale_sets.createrunners:writeCreates a scale set. The Operation is done when the controller settles it.
runners.scale_sets.updaterunners:writeUpdates a scale set.
runners.scale_sets.deleterunners:writeDeletes a scale set.
sandboxes.pools.createsandboxes:writeCreates a pool. The Operation is done when the controller settles it.
sandboxes.pools.updatesandboxes:writeUpdates a pool.
sandboxes.pools.deletesandboxes:writeDeletes a pool.
sandboxes.leases.createsandboxes:writeCreates a lease: granted now and returned READY (or GRANTED when wait_ready is false), or refused with a typed error. There is no queue.
sandboxes.leases.renewsandboxes:writeExtends expire_time, never past the shape's longest lease. Does not change the generation.
sandboxes.leases.releasesandboxes:writeEnds a lease with END_REASON_RELEASED; the machine is destroyed and never leased again, and attached volumes are detached.
sandboxes.leases.pausesandboxes:writePauses a lease: its disk is kept and its machine destroyed; the generation increases. Process memory is not kept.
sandboxes.leases.resumesandboxes:writeResumes a paused lease on a machine granted now, or refuses it; the generation increases.
sandboxes.leases.set_networksandboxes:writeReplaces a running lease's outbound policy. The generation does not change; the new policy applies before the call returns.
sandboxes.leases.mint_tokensandboxes:execMints a lease token for the data plane, bound to the current generation. Hand it to a process that must not hold the Access key.
sandboxes.leases.execsandboxes:execRuns one command in the lease to completion and returns its output, capped at 1 MiB per stream. Long-running or interactive processes use the guest protocol at status.endpoints.guest_uri.
sandboxes.leases.write_filesandboxes:execWrites one file in the lease, at most 16 MiB, creating parent directories.
sandboxes.leases.remove_filesandboxes:execRemoves one file or directory tree in the lease.
sandboxes.leases.open_portsandboxes:execExposes a guest port.
sandboxes.leases.close_portsandboxes:execStops exposing a guest port.
sandboxes.volumes.createsandboxes:writeCreates a volume.
sandboxes.volumes.updatesandboxes:writeUpdates a volume: grows spec.size_gib and edits metadata.
sandboxes.volumes.deletesandboxes:writeDeletes a volume and destroys its data. Refused RESOURCE_IN_USE while it is attached.
sandboxes.snapshots.createsandboxes:writeCaptures a running lease's disk as a snapshot.
sandboxes.snapshots.deletesandboxes:writeDeletes a snapshot.
secrets.secrets.createsecrets:writeCreates a secret, without a value; add one with CreateSecretVersion.
secrets.secrets.updatesecrets:writeUpdates a secret.
secrets.secrets.deletesecrets:writeDeletes a secret and destroys every version.
secrets.secret_versions.createsecrets:writeAdds a value to a secret as its newest version. The value is never returned.
secrets.secret_versions.disablesecrets:writeDisables a secret version: bindings stop delivering it.
secrets.secret_versions.enablesecrets:writeEnables a disabled secret version.
secrets.secret_versions.destroysecrets:writeDestroys a secret version's value irrecoverably.
secrets.secret_bindings.createsecrets:writeCreates a secret binding.
secrets.secret_bindings.updatesecrets:writeUpdates a secret binding.
secrets.secret_bindings.deletesecrets:writeDeletes a secret binding.
workflows.workflows.createworkflows:writeCreates a workflow.
workflows.workflows.updateworkflows:writeUpdates a workflow.
workflows.workflows.deleteworkflows:writeDeletes a workflow.
workflows.schedules.createworkflows:writeCreates a schedule.
workflows.schedules.updateworkflows:writeUpdates a schedule.
workflows.schedules.deleteworkflows:writeDeletes a schedule.
workflows.schedules.pauseworkflows:writePauses a Schedule: no fire starts a Run until it is resumed.
workflows.schedules.resumeworkflows:writeResumes a paused Schedule; missed fires follow catchup_window.
workflows.runs.createworkflows:runStarts a Run of a Workflow.
workflows.runs.start_batchworkflows:runStarts a batch: a parent Run that fans out one child Run per item, each with a stable index and count.
workflows.runs.signalworkflows:runSends a named signal to a running Run; a wait op for that name resumes with its payload. A signal to a closed Run fails with INVALID_STATE.
workflows.runs.cancelworkflows:runRequests cancellation. Timers and waits stop; a running invocation is not interrupted: the handler receives one final invocation with cancel: true, and the Run ends cancelled when it answers.
workflows.jobs.createworkflows:writeCreates a job.
workflows.jobs.updateworkflows:writeUpdates a job. Runs already started keep the generation they pinned.
workflows.jobs.deleteworkflows:writeDeletes a job.
workflows.job_runs.createworkflows:runStarts a run of a Job now. The same Idempotency-Key returns the same run for 24h; a Schedule fire uses {job}:{intended time}. With concurrency forbid, a start while a run is active fails with INVALID_STATE.
workflows.job_runs.cancelworkflows:runCancels a job run: SIGTERM, then SIGKILL after 30s. A closed run fails with INVALID_STATE.
workflows.distributed_jobs.createworkflows:writeCreates a distributed job.
workflows.distributed_jobs.updateworkflows:writeUpdates a distributed job. Runs already started keep the generation they pinned.
workflows.distributed_jobs.deleteworkflows:writeDeletes a distributed job.
workflows.distributed_runs.createworkflows:runStarts a run of a distributed job. The same Idempotency-Key returns the same run for 24h.
workflows.distributed_runs.cancelworkflows:runCancels a distributed run: workers get SIGTERM and 30s, then leases are released; finished shards are kept. A closed run fails with INVALID_STATE.
workflows.distributed_runs.add_shardsworkflows:runAppends shards to a run started with an open manifest; close ends the manifest, and the run ends once those shards are done.