[{"data":1,"prerenderedAt":384},["ShallowReactive",2],{"navigation":3,"\u002Freference\u002Fheaders-errors-limits":53,"\u002Freference\u002Fheaders-errors-limits-surround":379},[4,13,28,46],{"title":5,"path":6,"stem":7,"children":8,"icon":12},"Getting Started","\u002Fgetting-started","1.getting-started\u002F1.index",[9],{"title":10,"path":6,"stem":7,"icon":11},"Concepts","i-lucide-house",false,{"title":14,"path":15,"stem":16,"children":17,"page":12},"Guides","\u002Fguides","2.guides",[18,23],{"title":19,"path":20,"stem":21,"icon":22},"Server webhooks","\u002Fguides\u002Fserver-webhooks","2.guides\u002F1.server-webhooks","i-lucide-server",{"title":24,"path":25,"stem":26,"icon":27},"Signed webhooks","\u002Fguides\u002Fsigned-webhooks","2.guides\u002F2.signed-webhooks","i-lucide-shield-check",{"title":29,"path":30,"stem":31,"children":32,"page":12},"Reference","\u002Freference","3.reference",[33,37,41],{"title":34,"path":35,"stem":36,"icon":22},"POST \u002Fapi\u002Fv1\u002Fingest","\u002Freference\u002Fingest","3.reference\u002F1.ingest",{"title":38,"path":39,"stem":40,"icon":27},"POST \u002Fapi\u002Fv1\u002Fingest\u002F:slug","\u002Freference\u002Fingest-slug","3.reference\u002F2.ingest-slug",{"title":42,"path":43,"stem":44,"icon":45},"Headers, errors & limits","\u002Freference\u002Fheaders-errors-limits","3.reference\u002F3.headers-errors-limits","i-lucide-list-checks",{"title":47,"path":48,"stem":49,"children":50,"icon":52},"Changelog","\u002Fchangelog","4.changelog\u002F1.index",[51],{"title":47,"path":48,"stem":49,"icon":52},"i-lucide-history",{"id":54,"title":42,"body":55,"description":372,"extension":373,"links":374,"meta":375,"navigation":376,"path":43,"seo":377,"sitemap":374,"stem":44,"__hash__":378},"docs\u002F3.reference\u002F3.headers-errors-limits.md",{"type":56,"value":57,"toc":359},"minimark",[58,74,79,192,196,199,246,251,280,284,287,317,326,330,337,341],[59,60,61,62,68,69,73],"p",{},"Applies to both ",[63,64,65],"a",{"href":35},[66,67,34],"code",{}," (Surface 1a) and ",[63,70,71],{"href":39},[66,72,38],{}," (Surface 1b).",[75,76,78],"h2",{"id":77},"request-headers","Request headers",[80,81,82,101],"table",{},[83,84,85],"thead",{},[86,87,88,92,95,98],"tr",{},[89,90,91],"th",{},"Header",[89,93,94],{},"Surface",[89,96,97],{},"Required",[89,99,100],{},"Value",[102,103,104,123,138,160,176],"tbody",{},[86,105,106,112,115,118],{},[107,108,109],"td",{},[66,110,111],{},"Authorization",[107,113,114],{},"1a only",[107,116,117],{},"Yes",[107,119,120],{},[66,121,122],{},"Bearer ingt_srv_\u003Ctoken>",[86,124,125,130,133,135],{},[107,126,127],{},[66,128,129],{},"X-BGL-Timestamp",[107,131,132],{},"1b only",[107,134,117],{},[107,136,137],{},"Unix seconds, within ±5 minutes of server time",[86,139,140,145,147,149],{},[107,141,142],{},[66,143,144],{},"X-BGL-Signature",[107,146,132],{},[107,148,117],{},[107,150,151,152,155,156,159],{},"Hex ",[66,153,154],{},"HMAC-SHA256(secret, \"{timestamp}.{rawBody}\")",", optional ",[66,157,158],{},"sha256="," prefix",[86,161,162,167,170,173],{},[107,163,164],{},[66,165,166],{},"X-BGL-Idempotency-Key",[107,168,169],{},"Both",[107,171,172],{},"No",[107,174,175],{},"1–255 char string, dedups retries for 24h",[86,177,178,183,185,187],{},[107,179,180],{},[66,181,182],{},"Content-Type",[107,184,169],{},[107,186,117],{},[107,188,189],{},[66,190,191],{},"application\u002Fjson",[75,193,195],{"id":194},"response-shapes","Response shapes",[59,197,198],{},"Both surfaces return exactly one of two shapes — there is no third status code:",[80,200,201,214],{},[83,202,203],{},[86,204,205,208,211],{},[89,206,207],{},"Status",[89,209,210],{},"Body",[89,212,213],{},"When",[102,215,216,231],{},[86,217,218,223,228],{},[107,219,220],{},[66,221,222],{},"202 Accepted",[107,224,225],{},[66,226,227],{},"{ \"submission_id\": \"\u003Cuuid>\" }",[107,229,230],{},"The submission was accepted and scored.",[86,232,233,238,243],{},[107,234,235],{},[66,236,237],{},"200 OK",[107,239,240],{},[66,241,242],{},"{ \"status\": \"rejected\" }",[107,244,245],{},"Anything went wrong — auth, rate limit, signature, form state, body validity.",[247,248,250],"h3",{"id":249},"why-rejections-are-opaque","Why rejections are opaque",[59,252,253,254,257,258,261,262,265,266,269,270,274,275,279],{},"A distinguishable response per failure mode (",[66,255,256],{},"401"," for a bad token, ",[66,259,260],{},"429"," for rate limiting, ",[66,263,264],{},"400"," for a bad signature) would let an attacker enumerate valid tokens or form slugs by watching which status code comes back. Every rejection reason — no matter how different internally — collapses to the same ",[66,267,268],{},"200 { \"status\": \"rejected\" }"," on the wire. If you need to know ",[271,272,273],"em",{},"why"," a specific submission was rejected, the real reason is logged and visible in ",[276,277,278],"strong",{},"Settings → Ingest tokens → Diagnostics",", scoped to your own workspace.",[75,281,283],{"id":282},"rate-limits","Rate limits",[59,285,286],{},"Per workspace, tracked separately per surface (a burst on 1a doesn't count against 1b's bucket):",[80,288,289,299],{},[83,290,291],{},[86,292,293,296],{},[89,294,295],{},"Window",[89,297,298],{},"Limit",[102,300,301,309],{},[86,302,303,306],{},[107,304,305],{},"Per minute",[107,307,308],{},"1,000 submissions",[86,310,311,314],{},[107,312,313],{},"Per day",[107,315,316],{},"50,000 submissions",[59,318,319,320,322,323,325],{},"Exceeding either limit returns the same opaque ",[66,321,268],{}," — there's no ",[66,324,260],{},".",[75,327,329],{"id":328},"body-limits","Body limits",[59,331,332,333,336],{},"Both surfaces cap the raw request body at ",[276,334,335],{},"128 KB",". Oversized bodies are rejected before any parsing happens.",[75,338,340],{"id":339},"legacy-endpoint-sunset","Legacy endpoint sunset",[59,342,343,344,347,348,351,352,358],{},"The pre-v1 ",[66,345,346],{},"\u002Fapi\u002Fingest\u002F:slug"," endpoint (optional signature, no replay protection) was deprecated on 2026-05-26 and permanently retired on 2026-06-25 — every request now returns ",[66,349,350],{},"410 Gone",". If you're still pointed at it, migrate to one of the two endpoints on this page; see the in-app ",[63,353,357],{"href":354,"rel":355},"https:\u002F\u002Fapp.blackglassleads.com\u002Fdocs\u002Fmigration",[356],"nofollow","migration notes"," for the full cutover checklist.",{"title":360,"searchDepth":361,"depth":362,"links":363},"",1,2,[364,365,369,370,371],{"id":77,"depth":362,"text":78},{"id":194,"depth":362,"text":195,"children":366},[367],{"id":249,"depth":368,"text":250},3,{"id":282,"depth":362,"text":283},{"id":328,"depth":362,"text":329},{"id":339,"depth":362,"text":340},"The shared header, response-shape, and rate-limit contract across both server ingest surfaces.","md",null,{},{"icon":45},{"title":42,"description":372},"QyVo7azQtqcwGlYmgEvFNXm1r8sAA9jkawLkCgFQCPo",[380,382],{"title":38,"path":39,"stem":40,"description":381,"icon":27,"children":-1},"Reference for the HMAC-signed slug ingest endpoint — Surface 1b.",{"title":47,"path":48,"stem":49,"description":383,"icon":52,"children":-1},"What's changed on the Black Glass Leads developer docs site.",1786814658630]