Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
On this page
IDEMPOTENCY_KEY_REUSED
An Idempotency-Key was reused with another body.
An Idempotency-Key was reused with another body.
HTTP 422 · gRPC INVALID_ARGUMENT · the error body
#Returned by
| Method | Scope | What it does |
|---|---|---|
access.orgs.create | access:admin | Creates an org. Access assigns the id. |
access.orgs.update | access:admin | Updates an org. |
access.orgs.delete | access:admin | Deletes an org and everything in it. Deletion cascades through every service, so it returns an Operation. |
access.projects.create | access:admin | Creates a project. Access assigns the id. |
access.projects.update | access:admin | Updates a project. |
access.projects.delete | access:admin | Deletes a project. |
access.envs.create | access:admin | Creates an environment. Access assigns the id. |
access.envs.update | access:admin | Updates an environment. |
access.envs.delete | access:admin | Deletes an environment. |
access.api_keys.create | access:keys:write | Creates an API key. Access assigns the id. |
access.api_keys.update | access:keys:write | Updates an API key. |
access.api_keys.delete | access:keys:write | Deletes an API key. |
access.api_keys.revoke | access:keys:write | Revokes an API key immediately; revocation propagates on its own fast path, ahead of the bulk key data. |
access.api_keys.roll | access:keys:write | Rolls an API key: returns a new key with the same spec and revokes the old one after the grace period. |
artifacts.artifacts.create | artifacts:write | Registers an artifact whose bytes were pushed by digest; verification runs after. |
artifacts.artifacts.delete | artifacts:write | Deletes an artifact; fails while a Release references it or a legal hold is active. |
assets.assets.generate | assets:write | Records the recipes as assets and generates the variants that are missing. Each call is idempotent and works within a bounded time; call again until pending is 0. |
assets.assets.approve_variant | assets:write | Approves one variant and records who approved it. |
assets.assets.reject_variant | assets:write | Rejects one variant. Its slot is freed and the next :generate fills it; the rejected file keeps serving at its URL. |
assets.assets.retire_variant | assets:write | Retires one variant. Its URL answers 404 from then on and its slot is freed. |
auth.auth_configs.update | auth:write | Updates an auth config. |
auth.end_users.create | auth:write | Creates an end user. |
auth.end_users.update | auth:write | Updates an end user. |
auth.end_users.delete | auth:write | Deletes an end user. |
auth.end_users.suspend | auth:write | Suspends an end user: sessions are revoked and sign-in is refused. |
auth.end_users.reactivate | auth:write | Reactivates a suspended end user. |
auth.end_users.unlock | auth:write | Clears an end user's sign-in lock (repeated failed sign-ins) now. |
auth.end_users.revoke_sessions | auth:write | Revokes every session of an end user. |
auth.sessions.revoke | auth:write | Revokes a session. |
auth.customer_organizations.create | auth:write | Creates a customer organization. |
auth.customer_organizations.update | auth:write | Updates a customer organization. |
auth.customer_organizations.delete | auth:write | Deletes a customer organization. |
auth.memberships.create | auth:write | Creates a membership. |
auth.memberships.update | auth:write | Updates a membership. |
auth.memberships.delete | auth:write | Deletes a membership. |
auth.organization_roles.create | auth:write | Creates an organization role. |
auth.organization_roles.update | auth:write | Updates an organization role. |
auth.organization_roles.delete | auth:write | Deletes an organization role. |
auth.invitations.create | auth:write | Creates an invitation. |
auth.invitations.revoke | auth:write | Revokes a pending invitation. |
auth.invitations.accept | auth:write | Accepts a pending invitation for an end user whose verified email is the invited address, and creates the membership. |
auth.email_domains.create | auth:write | Creates an email domain; the answer names the TXT record to publish. |
auth.email_domains.delete | auth:write | Deletes an email domain. |
auth.email_domains.verify | auth:write | Looks up the domain's TXT record now; found, the domain is verified. |
auth.oauth_clients.create | auth:write | Creates an OAuth client. |
auth.oauth_clients.update | auth:write | Updates an OAuth client. |
auth.oauth_clients.delete | auth:write | Deletes an OAuth client. |
auth.oauth_clients.roll_secret | auth:write | Issues a new client secret, returned once; the old one verifies until grace_period ends. |
billing.billing_accounts.update | billing:admin | Updates a billing account: changes plan, spend limit, or billing email. |
broker.trust_policies.create | broker:admin | Creates a trust policy. |
broker.trust_policies.update | broker:admin | Updates a trust policy. |
broker.trust_policies.delete | broker:admin | Deletes a trust policy. |
build.builds.create | build:write | Creates a build. The Operation is done when the controller settles it. |
build.builds.cancel | build:write | Cancels a queued or running Build; its lease is released and nothing is published. |
build.build_caches.update | build:write | Updates a build cache. |
build.build_caches.delete | build:write | Deletes a build cache. |
config.config_flags.create | config:write | Creates a config flag; the Operation is done when every cell serves it. |
config.config_flags.update | config:write | Updates a config flag; the change rolls out in waves and the Operation is done when every cell serves it. |
config.config_flags.delete | config:write | Deletes a config flag; evaluators then get their compiled-in fallback. |
config.config_segments.create | config:write | Creates a config segment. |
config.config_segments.update | config:write | Updates a config segment; every flag naming it follows. |
config.config_segments.delete | config:write | Deletes a config segment; refused while a flag names it. |
connections.connection_providers.create | connections:admin | Creates a connection provider. |
connections.connection_providers.update | connections:admin | Updates a connection provider. |
connections.connection_providers.delete | connections:admin | Deletes a connection provider; it must have no connections. |
connections.connections.create | connections:write | Records an installation; the controller confirms it with the provider. |
connections.connections.update | connections:write | Updates a connection's metadata. |
connections.connections.delete | connections:write | Forgets a connection. The installation itself is removed at the provider. |
data.databases.create | data:write | Creates a database. The Operation is done when the controller settles it. |
data.databases.update | data:write | Updates a database. |
data.databases.delete | data:write | Deletes a database. Fails while spec.deletion_protection is set. |
data.databases.rotate_credentials | data:write | Replaces the database's engine credentials; the old ones stop working once the new ones are served. |
data.databases.restore | data:write | Restores the database in place to a point in time inside its retention window; the database is unavailable while it restores. |
data.kv_namespaces.create | data:write | Creates a kv namespace. The Operation is done when the controller settles it. |
data.kv_namespaces.update | data:write | Updates a kv namespace. |
data.kv_namespaces.delete | data:write | Deletes a kv namespace. Fails while spec.deletion_protection is set. |
data.kv_namespaces.rotate_credentials | data:write | Replaces the KV namespace's engine credentials; the old ones stop working once the new ones are served. |
data.buckets.create | data:write | Creates a bucket. The Operation is done when the controller settles it. |
data.buckets.update | data:write | Updates a bucket. |
data.buckets.delete | data:write | Deletes a bucket. Fails while spec.deletion_protection is set. |
data.buckets.rotate_credentials | data:write | Replaces the bucket's engine credentials; the old ones stop working once the new ones are served. |
data.search_indexes.create | data:write | Creates a search index. The Operation is done when the controller settles it. |
data.search_indexes.update | data:write | Updates a search index. |
data.search_indexes.delete | data:write | Deletes a search index. Fails while spec.deletion_protection is set. |
data.search_indexes.rotate_credentials | data:write | Replaces the search index's engine credentials; the old ones stop working once the new ones are served. |
events.topics.create | events:write | Creates a topic. |
events.topics.update | events:write | Updates a topic. |
events.topics.delete | events:write | Deletes a topic. |
events.subscriptions.create | events:write | Creates a subscription. |
events.subscriptions.update | events:write | Updates a subscription. |
events.subscriptions.delete | events:write | Deletes a subscription. |
events.queues.create | events:write | Creates a queue. |
events.queues.update | events:write | Updates a queue. |
events.queues.delete | events:write | Deletes a queue. |
events.queues.replay | events:write | Moves dead-lettered messages, optionally bounded by dead-letter time, back to ready. |
events.webhook_endpoints.create | events:write | Creates a webhook endpoint. |
events.webhook_endpoints.update | events:write | Updates a webhook endpoint. |
events.webhook_endpoints.delete | events:write | Deletes a webhook endpoint. |
events.webhook_endpoints.replay | events:write | Redelivers every dead-lettered delivery to the endpoint created in a time range, each as a new attempt. |
events.webhook_endpoints.rotate_secret | events:write | Replaces the endpoint's signing secret and returns the new one, once (status.signing_secret). For 24 hours deliveries carry a signature with each secret, so a receiver can switch without dropping one. |
events.webhook_endpoints.test | events:write | Sends a test event (type sylphx.webhook.test) to the endpoint alone, through the same signing, retries, and delivery log as any other event. |
events.webhook_deliveries.replay | events:write | Redelivers one delivery now, as a new attempt. |
events.inbound_endpoints.create | events:write | Creates an inbound endpoint. |
events.inbound_endpoints.update | events:write | Updates an inbound endpoint. |
events.inbound_endpoints.delete | events:write | Deletes an inbound endpoint. |
events.realtime_channels.create | events:write | Creates a realtime channel. |
events.realtime_channels.update | events:write | Updates a realtime channel. |
events.realtime_channels.publish | events:publish | Publishes one message to the channel: it is appended to the channel's history and pushed to every connected client. A retry with the same Idempotency-Key returns the first message. |
events.realtime_channels.delete | events:write | Deletes a realtime channel. |
hosting.services.create | hosting:write | Creates a service. The Operation is done when the controller settles it. |
hosting.services.update | hosting:write | Updates a service. |
hosting.services.delete | hosting:write | Deletes a service. |
hosting.service_rollouts.create | hosting:write | Creates a rollout. |
hosting.service_rollouts.pause | hosting:write | Holds a Rollout at its current wave. |
hosting.service_rollouts.resume | hosting:write | Resumes a paused Rollout. |
hosting.service_rollouts.abort | hosting:write | Stops a Rollout; the cells it reached return to the previous Release. |
hosting.previews.create | hosting:write | Creates a preview. The Operation is done when the controller settles it. |
hosting.previews.delete | hosting:write | Deletes a preview. |
hosting.source_links.create | hosting:write | Creates a source link. The Operation is done when the controller settles it. |
hosting.source_links.update | hosting:write | Updates a source link. |
hosting.source_links.delete | hosting:write | Deletes a source link. |
keys.keys.create | keys:write | Creates a key; the signer generates its first version. |
keys.keys.update | keys:write | Updates a key's rotation period, deletion protection, or metadata. |
keys.keys.delete | keys:write | Deletes a key and schedules every version's destruction. |
keys.keys.rotate | keys:write | Rotates a key: adds a version and makes it primary. Older versions keep verifying and decrypting until destroyed. |
keys.key_versions.destroy | keys:write | Schedules a key version's destruction after a 24-hour grace; the primary version cannot be destroyed. |
localization.catalogs.create | localization:write | Creates a catalog. |
localization.catalogs.update | localization:write | Updates a catalog. |
localization.catalogs.delete | localization:write | Deletes a catalog. |
localization.catalogs.sync | localization:write | Reads the source files and the committed translations into the catalog, then translates what is new or stale. Each call is idempotent and works within a bounded time; call again until pending is 0. |
localization.entries.pin_translation | localization:write | Sets the text of one locale as a human override that AI never overwrites. QA runs on the text first; a text with a QA error is rejected with INVALID_FIELD, and the problem lists the findings. |
localization.entries.unpin_translation | localization:write | Removes the human override of one locale; the next sync may translate it again. |
localization.glossaries.create | localization:write | Creates a glossary. |
localization.glossaries.update | localization:write | Updates a glossary. |
localization.glossaries.delete | localization:write | Deletes a glossary. |
money.price_catalogs.update | billing:write | Updates the environment's catalog: its features and products, whole. |
money.store_connections.create | billing:write | Creates a store connection; its credential is sealed and never returned. |
money.store_connections.update | billing:write | Updates a store connection; a new credential replaces the stored one. |
money.store_connections.delete | billing:write | Deletes a store connection and its sealed credential. |
money.customer_subscriptions.update_quantity | billing:write | Changes the seat quantity of a web subscription, now, and syncs the processor's subscription item to it. A retry with the same Idempotency-Key (required) and the same request changes nothing twice. |
money.checkout_sessions.create | billing:write | Creates a hosted checkout for a subject. |
money.portal_sessions.create | billing:write | Creates a customer portal session for a subject. |
network.domains.create | network:write | Creates a domain. The Operation is done when the controller settles it. |
network.domains.update | network:write | Updates a domain. |
network.domains.delete | network:write | Deletes a domain. |
network.domains.verify | network:write | Checks the verification record now instead of at the next sweep. |
network.routes.create | network:write | Creates a route. The Operation is done when the controller settles it. |
network.routes.update | network:write | Updates a route. |
network.routes.delete | network:write | Deletes a route. |
network.egress_identities.create | network:write | Creates an egress identity. The Operation is done when the controller settles it. |
network.egress_identities.update | network:write | Updates an egress identity. |
network.egress_identities.delete | network:write | Deletes an egress identity. |
network.private_links.create | network:write | Creates a private link. The Operation is done when the controller settles it. |
network.private_links.update | network:write | Updates a private link. |
network.private_links.delete | network:write | Deletes a private link. |
notify.mail_domains.create | notify:write | Creates an email domain. |
notify.mail_domains.update | notify:write | Updates an email domain. |
notify.mail_domains.delete | notify:write | Deletes an email domain. |
notify.mail_routes.create | notify:write | Creates a route. |
notify.mail_routes.update | notify:write | Updates a route. |
notify.senders.create | notify:write | Creates a sender. |
notify.senders.update | notify:write | Updates a sender. |
notify.senders.delete | notify:write | Deletes a sender. |
notify.recipients.create | notify:write | Creates a recipient. |
notify.recipients.update | notify:write | Updates a recipient. |
notify.recipients.delete | notify:write | Deletes a recipient. |
notify.preferences.update | notify:write | Updates a preference. |
notify.preferences.delete | notify:write | Deletes a preference. |
notify.suppressions.create | notify:write | Creates a suppression. |
notify.suppressions.delete | notify:write | Deletes a suppression. |
notify.templates.create | notify:write | Creates a template. |
notify.templates.update | notify:write | Updates a template. |
notify.templates.delete | notify:write | Deletes a template. |
notify.messages.create | notify:send | Sends a Message. |
notify.messages.cancel | notify:send | Cancels a Message whose deliveries have not been handed off. |
notify.mailboxes.create | notify:write | Creates a mailbox. |
notify.mailboxes.update | notify:write | Updates a mailbox. |
notify.mailboxes.erase_address | notify:write | Removes an address's personal data from every inbound email of the mailbox that it sent or that names it, keeping the dedupe keys so a poll never brings the mail back. |
notify.inbox_items.mark_read | notify:write | Marks an inbox item read. |
notify.inbox_items.mark_unread | notify:write | Marks an inbox item unread. |
notify.inbox_items.archive | notify:write | Archives an inbox item. |
notify.broadcasts.create | notify:write | Creates a broadcast. |
notify.broadcasts.update | notify:write | Updates a broadcast. |
notify.broadcasts.delete | notify:write | Deletes a broadcast. |
notify.broadcasts.send | notify:send | Sends a Broadcast now. |
notify.broadcasts.cancel | notify:send | Cancels a Broadcast; messages already admitted still deliver. |
observability.log_entries.write | observability:ingest | Ingests a batch of log entries atomically. The same Idempotency-Key and digest replays the same batch; a different digest under the key conflicts. |
observability.traces.write_spans | observability:ingest | Ingests a batch of spans atomically; a span's parent and time invariants are validated. Replay rules are those of WriteLogEntries. |
observability.error_groups.capture | observability:ingest | Captures one error occurrence. It is grouped by fingerprint when the caller sets one, else by exception type and the symbolicated in-app stack; release is never part of the group. A new occurrence reopens a resolved group. Secrets and personal data are scrubbed by the environment's Scrubbing Policy before storage. A fingerprint-equal replay bills no second new-error unit. Under quota pressure the response says what to sample. Browsers call it with a publishable key that holds observability:ingest (CORS allowed, rate-limited per environment). |
observability.error_groups.acknowledge | observability:write | Acknowledges an error group. |
observability.error_groups.resolve | observability:write | Resolves an error group; a new occurrence reopens it. |
observability.error_groups.reopen | observability:write | Reopens a resolved or acknowledged error group. |
observability.source_maps.create | observability:write | Uploads a source map for one release and minified file. Uploading the same release and file again replaces it. |
observability.scrubbing_policies.update | observability:write | Updates the environment's scrubbing policy. |
release.releases.create | release:write | Creates a release: admits it and rolls it out in waves. The Operation is done when the release is live or halted. |
runners.scale_sets.create | runners:write | Creates a scale set. The Operation is done when the controller settles it. |
runners.scale_sets.update | runners:write | Updates a scale set. |
runners.scale_sets.delete | runners:write | Deletes a scale set. |
sandboxes.pools.create | sandboxes:write | Creates a pool. The Operation is done when the controller settles it. |
sandboxes.pools.update | sandboxes:write | Updates a pool. |
sandboxes.pools.delete | sandboxes:write | Deletes a pool. |
sandboxes.leases.create | sandboxes:write | Creates a lease: granted now and returned READY (or GRANTED when wait_ready is false), or refused with a typed error. There is no queue. |
sandboxes.leases.renew | sandboxes:write | Extends expire_time, never past the shape's longest lease. Does not change the generation. |
sandboxes.leases.release | sandboxes:write | Ends a lease with END_REASON_RELEASED; the machine is destroyed and never leased again, and attached volumes are detached. |
sandboxes.leases.pause | sandboxes:write | Pauses a lease: its disk is kept and its machine destroyed; the generation increases. Process memory is not kept. |
sandboxes.leases.resume | sandboxes:write | Resumes a paused lease on a machine granted now, or refuses it; the generation increases. |
sandboxes.leases.set_network | sandboxes:write | Replaces a running lease's outbound policy. The generation does not change; the new policy applies before the call returns. |
sandboxes.leases.mint_token | sandboxes:exec | Mints a lease token for the data plane, bound to the current generation. Hand it to a process that must not hold the Access key. |
sandboxes.leases.exec | sandboxes:exec | Runs one command in the lease to completion and returns its output, capped at 1 MiB per stream. Long-running or interactive processes use the guest protocol at status.endpoints.guest_uri. |
sandboxes.leases.write_file | sandboxes:exec | Writes one file in the lease, at most 16 MiB, creating parent directories. |
sandboxes.leases.remove_file | sandboxes:exec | Removes one file or directory tree in the lease. |
sandboxes.leases.open_port | sandboxes:exec | Exposes a guest port. |
sandboxes.leases.close_port | sandboxes:exec | Stops exposing a guest port. |
sandboxes.volumes.create | sandboxes:write | Creates a volume. |
sandboxes.volumes.update | sandboxes:write | Updates a volume: grows spec.size_gib and edits metadata. |
sandboxes.volumes.delete | sandboxes:write | Deletes a volume and destroys its data. Refused RESOURCE_IN_USE while it is attached. |
sandboxes.snapshots.create | sandboxes:write | Captures a running lease's disk as a snapshot. |
sandboxes.snapshots.delete | sandboxes:write | Deletes a snapshot. |
secrets.secrets.create | secrets:write | Creates a secret, without a value; add one with CreateSecretVersion. |
secrets.secrets.update | secrets:write | Updates a secret. |
secrets.secrets.delete | secrets:write | Deletes a secret and destroys every version. |
secrets.secret_versions.create | secrets:write | Adds a value to a secret as its newest version. The value is never returned. |
secrets.secret_versions.disable | secrets:write | Disables a secret version: bindings stop delivering it. |
secrets.secret_versions.enable | secrets:write | Enables a disabled secret version. |
secrets.secret_versions.destroy | secrets:write | Destroys a secret version's value irrecoverably. |
secrets.secret_bindings.create | secrets:write | Creates a secret binding. |
secrets.secret_bindings.update | secrets:write | Updates a secret binding. |
secrets.secret_bindings.delete | secrets:write | Deletes a secret binding. |
workflows.workflows.create | workflows:write | Creates a workflow. |
workflows.workflows.update | workflows:write | Updates a workflow. |
workflows.workflows.delete | workflows:write | Deletes a workflow. |
workflows.schedules.create | workflows:write | Creates a schedule. |
workflows.schedules.update | workflows:write | Updates a schedule. |
workflows.schedules.delete | workflows:write | Deletes a schedule. |
workflows.schedules.pause | workflows:write | Pauses a Schedule: no fire starts a Run until it is resumed. |
workflows.schedules.resume | workflows:write | Resumes a paused Schedule; missed fires follow catchup_window. |
workflows.runs.create | workflows:run | Starts a Run of a Workflow. |
workflows.runs.start_batch | workflows:run | Starts a batch: a parent Run that fans out one child Run per item, each with a stable index and count. |
workflows.runs.signal | workflows:run | Sends a named signal to a running Run; a wait op for that name resumes with its payload. A signal to a closed Run fails with INVALID_STATE. |
workflows.runs.cancel | workflows:run | Requests cancellation. Timers and waits stop; a running invocation is not interrupted: the handler receives one final invocation with cancel: true, and the Run ends cancelled when it answers. |
workflows.jobs.create | workflows:write | Creates a job. |
workflows.jobs.update | workflows:write | Updates a job. Runs already started keep the generation they pinned. |
workflows.jobs.delete | workflows:write | Deletes a job. |
workflows.job_runs.create | workflows:run | Starts a run of a Job now. The same Idempotency-Key returns the same run for 24h; a Schedule fire uses {job}:{intended time}. With concurrency forbid, a start while a run is active fails with INVALID_STATE. |
workflows.job_runs.cancel | workflows:run | Cancels a job run: SIGTERM, then SIGKILL after 30s. A closed run fails with INVALID_STATE. |
workflows.distributed_jobs.create | workflows:write | Creates a distributed job. |
workflows.distributed_jobs.update | workflows:write | Updates a distributed job. Runs already started keep the generation they pinned. |
workflows.distributed_jobs.delete | workflows:write | Deletes a distributed job. |
workflows.distributed_runs.create | workflows:run | Starts a run of a distributed job. The same Idempotency-Key returns the same run for 24h. |
workflows.distributed_runs.cancel | workflows:run | Cancels a distributed run: workers get SIGTERM and 30s, then leases are released; finished shards are kept. A closed run fails with INVALID_STATE. |
workflows.distributed_runs.add_shards | workflows:run | Appends shards to a run started with an open manifest; close ends the manifest, and the run ends once those shards are done. |