> ## Documentation Index
> Fetch the complete documentation index at: https://docs.drime.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# Errors and Limits

> What each OAuth error means, when tokens stop working, and the rate limits

## OAuth errors

The token and revocation endpoints answer errors as JSON:

```json theme={null}
{
  "error": "invalid_grant",
  "error_description": "This authorization code is invalid or has expired."
}
```

Errors on the authorization screen come back to your redirect URL as `?error=...&error_description=...&state=...`, except when `client_id` or `redirect_uri` is wrong: those stay on a Drime page.

| `error` | What happened | What to do |
| - | - | - |
| `invalid_request` | A parameter is missing or malformed: most often `redirect_uri`, the PKCE challenge of a desktop, mobile or script application, or `code_challenge_method=plain` | Fix the request |
| `invalid_client` | Unknown `client_id`, wrong secret, a desktop, mobile or script application that sent a secret, or an application suspended by Drime | Check your credentials |
| `invalid_grant` | The code expired (60 seconds), was already used, belongs to another application, or was issued for another `redirect_uri`; the `code_verifier` does not match; or the refresh token is unknown, expired or was already used | Start a new authorization |
| `invalid_scope` | A scope that does not exist, is not available to applications, or is not ticked under **Permissions**; no `scope` at all; or a refresh that asked only for scopes you were not granted | Fix the `scope` parameter or your **Permissions** |
| `unsupported_grant_type` | `grant_type` missing, or something other than `authorization_code` and `refresh_token` | Use one of the two |
| `unsupported_response_type` | `response_type` other than `code`. The implicit grant does not exist here | Use `code` |
| `access_denied` | The user declined, or your application has reached its limit of 25 users in Development | Let the user try again, or [go to production](/oauth/going-to-production) |
| `server_error` | Something failed on Drime's side | Try again later |

## API errors

| Status | Message | Meaning |
| - | - | - |
| `401` | `Unauthenticated.` | The access token expired or was revoked. Refresh it; if the refresh fails with `invalid_grant`, authorize again |
| `403` | `This API key is missing the required scope: x` | Your token does not have scope `x`. See [Scopes](/oauth/scopes) |
| `403` | `This endpoint cannot be accessed with a restricted API key.` | This route is never open to applications |
| `403` | `This endpoint works on the whole Drive, so it is not available to an application that works inside its own folder.` | The sync API, for an [application folder](/oauth/app-folder) |
| `403` | `This application works inside its own folder, which lives in your personal Drive. It cannot be used in a team workspace.` | A `workspaceId` other than `0`, for an application folder |
| `404` | `No such entry inside this application's folder.` | An id or hash outside your application folder |
| `503` | `This application's folder could not be opened. Try again in a moment.` | Try again in a moment |

## Checking that a token still works

Call `GET /api/v1/users/me`. Every token can read it, whatever its scopes, and it answers `401` as soon as the token stops working.

```bash theme={null}
curl -o /dev/null -w '%{http_code}\n' \
  https://app.drime.cloud/api/v1/users/me \
  -H "Authorization: Bearer $ACCESS_TOKEN"
# 200: the token works. 401: refresh it.
```

## When tokens stop working early

An access token lasts one hour, but it can stop working sooner, without warning:

* you refreshed it: each refresh retires the access token you had;
* the user disconnected your application from **Devices & apps** in their Drime settings;
* you called [`/oauth/revoke`](/oauth/authorization-flow);
* a refresh token was presented twice. Drime treats it as stolen and revokes every token your application holds for that user;
* an authorization code was used twice, and the tokens it produced are revoked;
* Drime suspended your application, or you deleted it.

Handle `401` by refreshing once. If the refresh answers `invalid_grant`, the user has to authorize your application again.

## Rate limits

| | |
| - | - |
| `/oauth/token` and `/oauth/revoke`, together | 60 requests a minute per `client_id`, and 120 a minute per IP address |
| Data API | A much higher, general limit |

Beyond a limit, Drime answers `429`. Wait, then retry with an increasing delay.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.