Skip to main content

Limits and Lockouts

Onflow Ads limits how often account actions can be attempted. The limits exist to stop guessing attacks, email bombing and abuse β€” but they are blunt, and the messages you get are deliberately vague, so you can hit one without knowing which. This page is the reference.

Nothing here can be lifted early by support, by starting over, or by using a different browser. The only thing that clears a limit is time.

The two messages you will actually see​

MessageHTTPWhat it means
Too many attempts. Please wait a minute and try again.429You hit one of the per-minute or per-hour caps in the tables below
Too many incorrect codes. For your security this is locked for 6 hours.429You exhausted a code-attempt budget. This is the hard lockout

Neither message tells you which cap you hit. That is intentional β€” naming the cap would tell an attacker how close they are.

Sign-up, sign-in and codes​

ActionLimitCounted per
Creating an account5 per hourIP address
Signing in with email and password10 per minuteIP address
Signing in with email and password5 wrong attempts per 15 minutesThe pair of email address and IP address
Sign-in attempts against one email, from anywhere40 per 15 minutes β€” then a human challenge is required where one is configured, and otherwise the attempt passes throughEmail address
Submitting a verification or reset code20 per minuteIP address
Submitting a two-factor code at sign-in20 per minuteIP address
Pressing Resend code8 per minuteIP address
Resend cooldown between codes60 secondsVerification session
Resends allowed in one verification4Verification session
Verification and reset emails sent to one address6 per hourEmail address
Requesting a password reset5 per hourIP address
Requesting a password reset3 per 15 minutesThe pair of email address and IP address
Password resets requested for one email, from anywhere12 per 15 minutes β€” after which the usual "if an account exists…" reply is returned without a code being sent, or a human challenge is required where one is configuredEmail address
Setting the new password at the end of a reset10 per hourIP address

Account and connection actions​

ActionLimitCounted per
Saving your profile name20 per hourIP address
Attaching a first email (Telegram-created accounts; a set email is permanent)10 per hourIP address
Starting a two-factor setup10 per hourIP address
Enabling or disabling two-factor, or using a recovery code, from your account page10 per 15 minutes per account, 20 per minute per IP addressAccount Β· IP address
Pressing Connect Telegram10 per 10 minutesAccount
Claiming a real email on the connection screen6 per 15 minutesAccount
Choosing your permanent marketplace role10 per hourIP address
Refreshing the Referral Programme page60 per hourAccount
Anything that changes something β€” a form, an order, a setting β€” on top of its own budget90 per minute per IP address, 240 per minute per signed-in account; tighter on sign-in (10 per minute per IP), money (30 per minute per account) and uploads (20 per minute)IP address Β· Account
Everything else on the site β€” a coarse burst limit over every page and request, static files, health checks and payment webhooks aside300 per minuteIP address

The complete table for every product action β€” money, forms, the AI tools, the links in ads, the Telegram bot β€” is on Security and rate limits.

A shared network shares the limit

The caps counted per IP address are counted per network, not per person. An office, a campus, a cafΓ© or a mobile carrier can put hundreds of people behind one address. If you hit a per-IP limit without doing anything unusual, someone else on your network almost certainly triggered it β€” switching to mobile data or another network clears it immediately.

Nobody can lock you out by typing your email

The five-attempts sign-in rule and the three-requests reset rule are counted on the pair of your email address and the network it came from. A stranger hammering your address fills their own bucket, not yours. The per-email backstops above them β€” 40 sign-in attempts, 12 reset requests, in 15 minutes from anywhere β€” never lock the account: sign-in asks for a human challenge instead, and a reset simply stops sending codes while still answering as if it had.

The three code-attempt counters​

Three separate counters guard the 6-digit codes, and they do different jobs. The second is the one people are surprised by.

CounterBudgetReset byWhat hitting zero does
Per code5 wrong triesA new verification sessionLocks the address and IP for 6 hours
Per email address10 wrong tries in a rolling hourTime onlyLocks the address and IP for 6 hours
Emails per address6 codes issued per hourTime onlySilently refuses to send more codes

The per-code counter tells you where you stand: "Incorrect code. 3 attempts left."

The 6-hour lock cannot be shortened, and it spreads

Once the lock is on, it is keyed to both your email address and your IP address for 6 hours. Starting over does not clear it: signing up again, opening a private window, or requesting a fresh code from the reset page all run into the same lock, because the count follows the address rather than the browser. It also silences new codes from every other flow β€” sign-up, password reset, first-email attachment and marketplace enlistment. Nobody can lift it early. Wait it out.

Running out of emails is invisible

The cap of 6 codes per address per hour is hit before either wrong-guess counter is involved, and the page cannot tell you which limit stopped it β€” you only see "We couldn't resend the email. Please try again shortly." If you have been re-requesting codes because none arrived, stop and check your spam folder rather than requesting a seventh: more requests will not produce more email.

Only the newest code works

Requesting a new code invalidates the previous one. If several arrive out of order, use the one from the newest email β€” an older code returns "That code expired. Tap Resend code to get a new one."

Two-factor sign-in​

The two-factor step at sign-in uses the same pair of counters as the email codes: 5 wrong codes in one sign-in, and 10 wrong codes per address in a rolling hour. Either one hitting zero produces the same 6-hour lock. Enabling or disabling two-factor from your account page, and using a recovery code there, share the same 10-wrong-codes-an-hour counter β€” so a stolen session cannot guess its way through your authenticator either β€” and are additionally limited to 10 tries per 15 minutes per account.

A recovery code is accepted anywhere an app code is, including here. Each recovery code works exactly once. See Two-Factor Authentication.

If every code is rejected, check your clock

Authenticator codes are derived from the time. We accept a code from the previous or next 30-second step to absorb small drift, but a phone whose clock has wandered further than that produces codes that are always wrong. Set the phone's time to automatic and try again β€” before you burn through your attempts.

Time-limited steps​

These are not rate limits β€” they are windows that close.

StepWindow
A verification or reset code stays valid10 minutes
A whole verification session stays open30 minutes
Choosing a new password after your reset code is accepted15 minutes
A two-factor setup panel stays valid before you confirm it10 minutes
A Connect Telegram deep link stays valid10 minutes
A Google, Apple or Telegram sign-in round trip10 minutes
A referral click stays attributable90 days
Limits never lock you out during an outage

Every limit here is enforced through a counter store, and every one of them fails open: if that store is unreachable, the request is allowed rather than refused. A limit will never be the reason the site is unusable during an incident.

If something goes wrong​

What you seeWhat it meansWhat to do
Too many attempts. Please wait a minute and try again. right after one tryA per-IP cap, most likely triggered by someone else on your networkSwitch network, or wait out the window in the tables above
Too many incorrect codes. For your security this is locked for 6 hours.A code-attempt counter hit zeroWait 6 hours. Do not sign up again β€” it will not help
We couldn't resend the email. Please try again shortly.Either the per-hour issuance cap, or a mail problem on our sideCheck spam first; wait an hour before requesting more
Your verification session expired. Please sign up again.The 30-minute session closedStart the flow again from the beginning
Your reset session expired. Please start again.The 15-minute window to pick a new password closedRequest a fresh reset code
Your setup expired. Start again. on the two-factor panelThe 10-minute setup window closedPress Enable two-factor again. A new key and a new set of recovery codes are generated β€” the old ones are void
A bare Forbidden. pageYour IP address is blocked, before any limit is even consultedThis is a ban, not a rate limit. Contact support from another network