Skip to main content
Error bodies differ by surface, so branch on the HTTP status code, not on a body field.
  • Identification request (rest.shieldlabs.ai, sent by the snippet): an empty body for 400, 401, 402 and 409; { "error": "..." } for 429 and 503.
  • History API (account.shieldlabs.ai): { "error": "..." } for 401, 429 and 500.
  • Management API (api.shieldlabs.ai): an empty body for 401; { "error": "..." } for 429 and 503; on the deprecated history path only, a bare JSON string for 400 and 404.

HTTP status codes

429 is an infrastructure rate limit, separate from the Risk Score: it protects the gateway and never feeds the Risk Score. The Risk Score is 0 to 100; the only exception is the 999 ban marker, explained on the rate limits page along with the 512 KB request body limit.

Snippet results

The snippet methods return nothing and never throw. onInitialized receives { status: "initialized", requestID } when an identification starts, or { status: "not_initialized" } when none runs: a call within five minutes of the last identification for the same user in the same visit, an identification for that user already in progress, a malformed public key in the snippet URL, or an internal error. A call that does not run posts nothing and counts nothing.

Troubleshooting

Symptom-to-fix for snippet, webhook, signature, and scoring issues.

FAQ

Short answers on keys, identifications, identifiers, and a Risk Score of 0.

Rate limits

The infra limits behind 429 and 503, and why they never affect the Risk Score.

Webhooks

Register, receive, and verify webhooks, with the no-retry delivery model.