Parsers report facts and measures as fields, so rules score them like any other target. Parser-specific limits can emit the facts listed below and preserve parsed fields. Exhausting a transaction work budget stops further evaluation; the route’s enforcement mode determines the outcome.
ProtocolAnomaly
Name
Description
absolute-form-host-mismatch
An absolute-form request target named a host other than the Host header.
conflicting-content-length
Content-Length values were not unsigned decimal integers or differed in their text representation.
content-length-transfer-encoding-conflict
A request carried both Content-Length and Transfer-Encoding.
decompression-failed
A compressed body could not be decompressed, so its raw bytes were inspected. Requests emit ProtocolAnomaly with this value; responses emit ParserFact with this name. Decoded body inspection remains incomplete.
encoded-request-body
The body declared a Content-Encoding other than identity.
hop-by-hop-header-abuse
The Connection header named a token outside the supported connection-token allowlist.
malformed-cookie-header
A Cookie header segment had an empty name or no equals sign.
malformed-percent-encoding
The raw path or query contained an invalid percent escape.
malformed-query
The query string could not be parsed.
unsupported-charset
The body declared a charset Edge cannot decode, so it was inspected as bytes.
upgrade-h2c
The request asked for an h2c upgrade or carried an HTTP2-Settings header.
ParserFact
Name
Description
body-inspection-truncated
A request body, protobuf message or response was inspected only in part.
decompression-limit-exceeded
Decompression reached the size or ratio limit; the decompressed prefix is inspected.
duplicate-json-key
A JSON object repeated a property name.
duplicate-parameter-name
A query, URL-encoded form or multipart field name occurred more than once.
graphql-limit-exceeded
GraphQL parsing reached a structural limit; fields already parsed remain available within the work budget.
grpc-messages-uninspected
The gRPC per-request inspection count was reached; later messages are outside payload inspection.
json-limit-exceeded
JSON parsing reached a structural limit; fields already parsed remain available within the work budget.
jwt-empty-signature
A compact JWS had an empty signature segment.
jwt-zero-signature
A compact JWS had a signature of zero bytes only.
multipart-limit-exceeded
Multipart parsing or archive inspection reached a structural limit; retained fields remain available.
route-allowed-content-type
The request has one Content-Type header whose media type is in the route's additional allowed request content types. The value is the lowercase media type.
route-allowed-method
The route's additional allowed methods include the request method. The value is the method.
schema-validation-limit-exceeded
API schema validation could not finish within its input, estimated-work or runtime safety limits.
websocket-compressed-frame
A compressed WebSocket message was observed and its payload was not inspected.
websocket-message-too-large
A WebSocket message exceeded the configured cap, so only its retained prefix could be inspected.
xml-doctype
An XML body declared a document type.
xml-external-entity
An XML body declared an entity with a system or public identifier.
xml-limit-exceeded
XML parsing reached a structural limit or stopped inspecting an unsafe DTD subset; retained fields remain available.
Measure
Name
Description
archive-entries
The number of entries in an uploaded zip archive's central directory.
args-combined-size
The combined character length of query argument names and values, plus parsed body argument names or paths and values at the body stage.
args-count
The number of query arguments, plus parsed body argument values when inspecting the body.
body-length
The byte length seen by body inspection after applicable decompression and charset conversion.
files-combined-size
The combined size of every uploaded file part.
graphql-aliases
The number of GraphQL field aliases.
graphql-batch-size
The number of operations in a GraphQL batch.
graphql-depth
The deepest GraphQL selection nesting.
graphql-root-fields
The number of root fields in GraphQL operations.
grpc-messages
The one-based number of the gRPC message currently being inspected.
header-count
The number of request headers.
jwt-signature-length
The decoded length of a compact JWS signature.
protobuf-depth
The deepest protobuf message nesting the wire walker reached.
xml-depth
The deepest XML element nesting.
xml-entity-declarations
The number of entities declared in the DTD.
SchemaViolation
Name
Description
invalid-content-type
The content type is not one the operation accepts.
invalid-type
A parameter or JSON body failed schema validation other than a missing-required or forbidden-property check.
missing-required
A required parameter or property is missing.
unknown-operation
The path and method match no operation in the route's OpenAPI document.
unknown-parameter
A query parameter is not declared by the operation.
unknown-property
A JSON property is forbidden by additionalProperties false or unevaluatedProperties false.
Work limits
Profiles set these per ruleset; a transaction uses the largest value among applicable rulesets, capped by the engine maximum. Before merging, the local profile’s limits are capped at their defaults. JSON profile properties use camelCase, for example maximumJsonDepth.
Limit
Default
Engine maximum
Description
MaximumInspectedValues
4,096
32,768
Fields inspected in one transaction.
MaximumInspectedCharacters
2,500,000
8,388,608
Characters inspected in one transaction, names included.
MaximumTransformationSteps
4,096
131,072
Transformation steps in one transaction.
MaximumTransformationInputBytes
12,000,000
16,777,216
Bytes entering transformations in one transaction.
MaximumTransformationOutputBytes
12,000,000
16,777,216
Bytes produced by transformations in one transaction.
MaximumRegexInputCharacters
16,384
131,072
Characters of one value a regular expression may scan.
MaximumFindings
32
256
Findings kept per ruleset in one transaction.
MaximumBase64DecodedBytes
65,536
1,048,576
Bytes one base64 transformation may produce.
MaximumTargetCharacters
65,536
1,048,576
Characters in one field value or name.
MaximumTransformationCacheEntries
2,048
32,768
Cached transformation results in one transaction.
MaximumOperatorInvocations
4,096
131,072
Operator evaluations in one transaction.
MaximumOperatorInputValues
65,536
1,048,576
Values passed to operators in one transaction.
MaximumOperatorInputCharacters
320,000,000
536,870,912
Characters scanned by operators in one transaction.
MaximumRegexAttempts
256
4,096
Regular-expression evaluations in one transaction.
MaximumRegexWorkUnits
100,000,000
4,000,000,000
Estimated regular-expression work, based on input length and compiled pattern complexity, in one transaction.
MaximumJsonDepth
32
128
JSON nesting depth.
MaximumJsonTokens
4,096
131,072
JSON tokens in one body.
MaximumBodyFields
4,096
32,768
Fields produced by one body, message or response parser invocation.
MaximumMultipartSections
128
4,096
Parts in one multipart body.
MaximumMultipartHeaders
1,024
32,768
Part headers in one multipart body.
MaximumFieldNameCharacters
1,024
65,536
Characters in one body field name.
MaximumScalarCharacters
65,536
1,048,576
Characters permitted in a structured scalar value or parser text item.
MaximumArgumentNameSegments
32
256
Segments taken from one bracket or dot argument name.
MaximumJwtFields
64
1,024
Header fields and claims taken from one JWT.
MaximumArchiveEntries
1,024
65,535
Entries read from one zip central directory.
MaximumXmlDepth
64
256
XML element nesting depth.
MaximumXmlNodes
16,384
1,048,576
XML nodes in one body.
MaximumXmlAttributes
256
4,096
Attributes on one XML element.
MaximumXmlEntityDeclarations
64
4,096
Entity declarations read from one DTD.
MaximumGraphQlTokens
16,384
262,144
Tokens in one GraphQL document.
MaximumGraphQlDepth
16
128
GraphQL selection nesting depth.
MaximumGraphQlAliases
64
4,096
Aliases in one GraphQL document.
MaximumGraphQlBatchSize
16
256
Operations in one GraphQL batch.
MaximumProtobufDepth
16
64
Nested protobuf messages the wire walker descends into.
MaximumSchemaValidationSteps
16,384
1,048,576
Estimated schema-validation work shared by request parameters and the selected JSON body schema.
Resource settings
These system settings are under Settings → Firewall. They bound decompression, uploaded-file content and overlapping raw-body scans; see Inspected traffic for the route-level controls.
Setting
Default
Description
MaximumDecompressedBytes
16,777,216
Bytes decompression may produce for one body or value, a system setting.
MaximumDecompressionRatio
100
Output-to-input ratio decompression may reach, a system setting.
MaximumFileContentBytes
65,536
Bytes of each file part inspected, a system setting.
MaximumRawBodyWindowCharacters
65,536
Characters in each overlapping raw-body window, also bounded by MaximumTargetCharacters, a system setting.
MaximumRawBodyCharacters
1,048,576
Distinct decoded characters emitted as raw-body fields before scanning stops, a system setting.