Login Attempts Exceeded
login_attempts_exceeded429
Too many failed sign-in attempts. Try again in 15 minutes, or reset your password.
What this means
Password sign-in is paused because of repeated wrong passwords: five for this email, or twenty from this network across any emails, within 15 minutes. Nothing about the account changed. Signing in with Google still works right away, and resetting the password lifts the pause for this email.
When you'll see this
- The password was mistyped several times in a row.
- A password manager filled an old password repeatedly.
- Many people behind one office or school network mistyped passwords around the same time.
- Someone else is trying to guess the account's password.
Learn more about how this works
Each sign-in attempt counts against two limits before the password is checked: one for the email and one for the network address. Counting first means guesses sent in parallel can't slip past the limit together. A successful sign-in clears the email's count. Attempts refused while paused don't add to it, so the pause ends 15 minutes after the first failure in the window.
The response is the same whether or not the email has an account, so the pause doesn't reveal which emails are registered.
Example response
{
"success": false,
"error": "login_attempts_exceeded",
"message": "Too many failed sign-in attempts. Try again in 15 minutes, or reset your password.",
"details": [],
"retry_after": 900,
"doc_url": "https://docs.asterwise.com/reference/errors/login_attempts_exceeded/",
"request_id": "req_01HXYZABCDEFGH",
"timestamp": "2026-05-25T12:34:56Z"
}
- Wait 15 minutes and try again with the correct password.
- Or use Forgot password: setting a new password from the email link lifts the pause, then sign in with it.
- If you signed up with Google, use Continue with Google instead of a password.
Only the sign-in page receives this error, with retry_after set to the seconds to wait. API keys never see it, and nothing in an integration needs to handle it.
Production handler
No code example provided.
Avoid this error by
- Use a password manager and update the saved password after a reset.
- Sign in with Google to avoid passwords altogether.
- If you didn't cause the failures, reset the password and check the account's sessions in the dashboard.