Limits and Lockouts
Onflow Ads limits how often account actions can be attempted. The limits exist to stop guessing attacks, email bombing and abuse β but they are blunt, and the messages you get are deliberately vague, so you can hit one without knowing which. This page is the reference.
Nothing here can be lifted early by support, by starting over, or by using a different browser. The only thing that clears a limit is time.
The two messages you will actually seeβ
| Message | HTTP | What it means |
|---|---|---|
| Too many attempts. Please wait a minute and try again. | 429 | You hit one of the per-minute or per-hour caps in the tables below |
| Too many incorrect codes. For your security this is locked for 6 hours. | 429 | You exhausted a code-attempt budget. This is the hard lockout |
Neither message tells you which cap you hit. That is intentional β naming the cap would tell an attacker how close they are.
Sign-up, sign-in and codesβ
| Action | Limit | Counted per |
|---|---|---|
| Creating an account | 5 per hour | IP address |
| Signing in with email and password | 10 per minute | IP address |
| Signing in with email and password | 5 wrong attempts per 15 minutes | The pair of email address and IP address |
| Sign-in attempts against one email, from anywhere | 40 per 15 minutes β then a human challenge is required where one is configured, and otherwise the attempt passes through | Email address |
| Submitting a verification or reset code | 20 per minute | IP address |
| Submitting a two-factor code at sign-in | 20 per minute | IP address |
| Pressing Resend code | 8 per minute | IP address |
| Resend cooldown between codes | 60 seconds | Verification session |
| Resends allowed in one verification | 4 | Verification session |
| Verification and reset emails sent to one address | 6 per hour | Email address |
| Requesting a password reset | 5 per hour | IP address |
| Requesting a password reset | 3 per 15 minutes | The pair of email address and IP address |
| Password resets requested for one email, from anywhere | 12 per 15 minutes β after which the usual "if an account existsβ¦" reply is returned without a code being sent, or a human challenge is required where one is configured | Email address |
| Setting the new password at the end of a reset | 10 per hour | IP address |
Account and connection actionsβ
| Action | Limit | Counted per |
|---|---|---|
| Saving your profile name | 20 per hour | IP address |
| Attaching a first email (Telegram-created accounts; a set email is permanent) | 10 per hour | IP address |
| Starting a two-factor setup | 10 per hour | IP address |
| Enabling or disabling two-factor, or using a recovery code, from your account page | 10 per 15 minutes per account, 20 per minute per IP address | Account Β· IP address |
| Pressing Connect Telegram | 10 per 10 minutes | Account |
| Claiming a real email on the connection screen | 6 per 15 minutes | Account |
| Choosing your permanent marketplace role | 10 per hour | IP address |
| Refreshing the Referral Programme page | 60 per hour | Account |
| Anything that changes something β a form, an order, a setting β on top of its own budget | 90 per minute per IP address, 240 per minute per signed-in account; tighter on sign-in (10 per minute per IP), money (30 per minute per account) and uploads (20 per minute) | IP address Β· Account |
| Everything else on the site β a coarse burst limit over every page and request, static files, health checks and payment webhooks aside | 300 per minute | IP address |
The complete table for every product action β money, forms, the AI tools, the links in ads, the Telegram bot β is on Security and rate limits.
The caps counted per IP address are counted per network, not per person. An office, a campus, a cafΓ© or a mobile carrier can put hundreds of people behind one address. If you hit a per-IP limit without doing anything unusual, someone else on your network almost certainly triggered it β switching to mobile data or another network clears it immediately.
The five-attempts sign-in rule and the three-requests reset rule are counted on the pair of your email address and the network it came from. A stranger hammering your address fills their own bucket, not yours. The per-email backstops above them β 40 sign-in attempts, 12 reset requests, in 15 minutes from anywhere β never lock the account: sign-in asks for a human challenge instead, and a reset simply stops sending codes while still answering as if it had.
The three code-attempt countersβ
Three separate counters guard the 6-digit codes, and they do different jobs. The second is the one people are surprised by.
| Counter | Budget | Reset by | What hitting zero does |
|---|---|---|---|
| Per code | 5 wrong tries | A new verification session | Locks the address and IP for 6 hours |
| Per email address | 10 wrong tries in a rolling hour | Time only | Locks the address and IP for 6 hours |
| Emails per address | 6 codes issued per hour | Time only | Silently refuses to send more codes |
The per-code counter tells you where you stand: "Incorrect code. 3 attempts left."
Once the lock is on, it is keyed to both your email address and your IP address for 6 hours. Starting over does not clear it: signing up again, opening a private window, or requesting a fresh code from the reset page all run into the same lock, because the count follows the address rather than the browser. It also silences new codes from every other flow β sign-up, password reset, first-email attachment and marketplace enlistment. Nobody can lift it early. Wait it out.
The cap of 6 codes per address per hour is hit before either wrong-guess counter is involved, and the page cannot tell you which limit stopped it β you only see "We couldn't resend the email. Please try again shortly." If you have been re-requesting codes because none arrived, stop and check your spam folder rather than requesting a seventh: more requests will not produce more email.
Requesting a new code invalidates the previous one. If several arrive out of order, use the one from the newest email β an older code returns "That code expired. Tap Resend code to get a new one."
Two-factor sign-inβ
The two-factor step at sign-in uses the same pair of counters as the email codes: 5 wrong codes in one sign-in, and 10 wrong codes per address in a rolling hour. Either one hitting zero produces the same 6-hour lock. Enabling or disabling two-factor from your account page, and using a recovery code there, share the same 10-wrong-codes-an-hour counter β so a stolen session cannot guess its way through your authenticator either β and are additionally limited to 10 tries per 15 minutes per account.
A recovery code is accepted anywhere an app code is, including here. Each recovery code works exactly once. See Two-Factor Authentication.
Authenticator codes are derived from the time. We accept a code from the previous or next 30-second step to absorb small drift, but a phone whose clock has wandered further than that produces codes that are always wrong. Set the phone's time to automatic and try again β before you burn through your attempts.
Time-limited stepsβ
These are not rate limits β they are windows that close.
| Step | Window |
|---|---|
| A verification or reset code stays valid | 10 minutes |
| A whole verification session stays open | 30 minutes |
| Choosing a new password after your reset code is accepted | 15 minutes |
| A two-factor setup panel stays valid before you confirm it | 10 minutes |
| A Connect Telegram deep link stays valid | 10 minutes |
| A Google, Apple or Telegram sign-in round trip | 10 minutes |
| A referral click stays attributable | 90 days |
Every limit here is enforced through a counter store, and every one of them fails open: if that store is unreachable, the request is allowed rather than refused. A limit will never be the reason the site is unusable during an incident.
If something goes wrongβ
| What you see | What it means | What to do |
|---|---|---|
| Too many attempts. Please wait a minute and try again. right after one try | A per-IP cap, most likely triggered by someone else on your network | Switch network, or wait out the window in the tables above |
| Too many incorrect codes. For your security this is locked for 6 hours. | A code-attempt counter hit zero | Wait 6 hours. Do not sign up again β it will not help |
| We couldn't resend the email. Please try again shortly. | Either the per-hour issuance cap, or a mail problem on our side | Check spam first; wait an hour before requesting more |
| Your verification session expired. Please sign up again. | The 30-minute session closed | Start the flow again from the beginning |
| Your reset session expired. Please start again. | The 15-minute window to pick a new password closed | Request a fresh reset code |
| Your setup expired. Start again. on the two-factor panel | The 10-minute setup window closed | Press Enable two-factor again. A new key and a new set of recovery codes are generated β the old ones are void |
| A bare Forbidden. page | Your IP address is blocked, before any limit is even consulted | This is a ban, not a rate limit. Contact support from another network |
Relatedβ
- Verifying your email β the flow most of the code limits belong to.
- Two-factor authentication β the counters at the sign-in code step.
- Sessions and staying signed in β what ends a session, as opposed to what blocks a request.
- Account FAQ and troubleshooting β the short answers.