Pricing, limits, errors
You pay for answers, not for requests. The first 1,000 every month are free.
What counts§
| Billed | |
|---|---|
A scan AllowID recognised (resolved) | yes, 1 |
| A sign-in the person approved, the first time your server collects it | yes, 1 |
The same code again within a minute (repeat) | no |
Codes that are unknown, invalid or replayed | no |
| Starting a sign-in, checking its status, collecting it again | no |
| A sign-in nobody approved, or one that was declined | no |
usage, health | no |
The allowance§
- Free: 1,000 answers a calendar month (UTC), for every company, without signing anything.
- Licence: more answers a month. Contact AllowID; your licence shows in the console as soon as it is set.
- Grace: above your allowance the API keeps answering for another 20 %. With the free tier it pauses at 1,200; with a licence of 50,000, at 60,000.
- Paused: past the grace, scans and new sign-ins answer
quota_exceeded(HTTP 429) until 00:00 UTC on the 1st, or until the allowance is raised. A sign-in that had already started can still be collected.
The company console shows the month so far under API, and every billed answer carries
usage, so your own software can watch it too.
Usage emails§
The owners and administrators of your company get an email when the month reaches 80 % of the allowance, at 100 % (grace starts), and at 120 % (the API pauses). One each per month. The mail holds your company name, the numbers and a link to the console. Nothing about who scanned.
Rate limits§
1,200 requests a minute per key; above that, rate_limited (HTTP 429) with
Retry-After: 60. A busy site with several readers can use one key per reader to stay well clear.
Error codes§
| code | HTTP | What to do |
|---|---|---|
missing_key | 401 / — | Set ALLOWID_API_KEY where the code runs. |
invalid_key | 401 | The key is mistyped or was revoked. Make a new one in the console. |
rate_limited | 429 | Wait a minute; spread readers over several keys. |
quota_exceeded | 429 | The month's allowance and grace are used. usage says by how much. |
invalid_request | 400 | Read detail, for example an unknown attribute name. |
not_found | 404 | No such session for your company. |
network_error | — | Raised by the SDKs when AllowID could not be reached. Decide what your door does then. |
internal_error | 500 | Ours. Retry once; if it persists, send us the X-Request-Id. |