# Errors

Every error code the submit endpoint returns, what causes it and how to fix it.

Rejected submissions answer with an HTTP status and, for JSON requests, a body like this:

```json
{ "ok": false, "error": "rate_limited", "message": "Too many requests. Try again shortly" }
```

Branch on `error`, which never changes. `message` is written for the people filling in your form, so you can show it to them as is. Browser form posts get the same outcome as a page with a link back to your site.

Errors from the API that manages forms and submissions look different. See [API errors](/docs/api#errors).

## Error codes

| Status | `error`                    | Message                                                         | What to do                                                                                                                            |
| ------ | -------------------------- | --------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- |
| `400`  | `too_many_files`           | Too many files attached                                         | Send at most 5 files per submission.                                                                                                  |
| `402`  | `quota_exceeded`           | This form has reached its monthly submission limit              | The team used its monthly submissions. [Upgrade](/docs/account/billing) or wait for next month.                                       |
| `403`  | `origin_not_allowed`       | This form does not accept submissions from this website         | Add the site to the form's [allowed websites](/docs/protection/access-rules).                                                         |
| `403`  | `captcha_failed`           | Captcha verification failed. Complete the captcha and try again | Send a valid Turnstile token. See [Cloudflare Turnstile](/docs/protection/turnstile).                                                 |
| `404`  | `form_not_found`           | Form not found                                                  | Check the key in your endpoint. It may have been rotated or the form deleted.                                                         |
| `405`  | `method_not_allowed`       | This is a nisuform form endpoint...                             | Send a `POST` request.                                                                                                                |
| `413`  | `payload_too_large`        | Submission too large                                            | Keep the request under 200 KB, or 25 MB with file uploads.                                                                            |
| `413`  | `attachment_too_large`     | A file exceeds the upload size limit                            | Send smaller files, or raise **Size limit per file**.                                                                                 |
| `415`  | `unsupported_media_type`   | Unsupported content type                                        | Send JSON, URL-encoded or multipart data, and valid JSON.                                                                             |
| `415`  | `attachment_type_rejected` | A file type is not allowed                                      | Send JPEG, PNG, WebP, GIF or PDF files.                                                                                               |
| `422`  | `empty_submission`         | The submission is empty. Fill in the form and try again         | Send at least one non-empty field or a file.                                                                                          |
| `423`  | `form_closed_manual`       | This form is closed and not accepting submissions               | The form is paused. Resume it in **Settings**, **General**.                                                                           |
| `423`  | `form_max_submissions`     | This form has reached its maximum number of submissions         | Raise or clear **Maximum submissions**.                                                                                               |
| `423`  | `form_auto_close`          | This form closed automatically on its scheduled date            | Clear or move the **Close on** date.                                                                                                  |
| `429`  | `rate_limited`             | Too many requests. Try again shortly                            | Wait a minute, or the seconds in the `Retry-After` header when you can read it. See [rate limits](/docs/protection/spam#rate-limits). |
| `500`  | `upload_failed`            | Uploading your attachment failed. Please try again              | Nothing was stored. Try again.                                                                                                        |
| `500`  | `internal_error`           | Something went wrong                                            | Try again. If it keeps happening, contact support with the `x-request-id` header.                                                     |

On Pro, the three `423` errors use your own **Closed message** when you set one. See [Pause and close a form](/docs/forms/closing).

## Errors that look like success

Some submissions are dropped on purpose but still answer `200` with `{ "ok": true }` and no `submissionId`, so bots can't tell they were caught:

* The `_gotcha` honeypot had a value.
* `_elapsed` was under 2 seconds.
* The sender's IP address or country is blocked for the form.

If your own test submissions are missing from the inbox, check these first. See [Troubleshooting](/docs/reference/troubleshooting).

## Validation problems are not errors

Answers that don't match your form's fields don't cause an error. The submission is stored and marked in the inbox. See [Fields and validation](/docs/forms/fields).
