Too many attempts
What went wrong
Section titled “What went wrong”The sign-in page says “Too many attempts. Wait a moment and try again”, or an API request returns 429 Too Many Requests.
Why it happens
Section titled “Why it happens”Day Planner limits how often each visitor can call sensitive actions, to slow down password guessing:
| Action | Limit per visitor IP |
|---|---|
| Sign in | 3 per 10 seconds |
| Sign up, request a password reset | 3 per minute |
| Create an API key | 10 per minute |
| Each API key | 600 requests per minute |
If everyone hits the limit at once, Day Planner probably can’t see visitors’ real IPs and is counting them all as your reverse proxy.
How to fix it
Section titled “How to fix it”- One person: wait for the time in the table, then try again.
- Everyone: set
CLIENT_IP_HEADERandTRUSTED_PROXIESfor your proxy, as described in Reverse proxy and client IPs. - Several app containers: set
RATE_LIMIT_STORAGE=databaseso limits are shared correctly; see Running more than one instance.
See also
Section titled “See also”- API keys: per-key limits
- Reverse proxy and client IPs: how the visitor’s IP is found