Facts and limits

Parsers report facts and measures as fields, so rules score them like any other target. Parser-specific limits can emit the facts listed below and preserve parsed fields. Exhausting a transaction work budget stops further evaluation; the route’s enforcement mode determines the outcome.

ProtocolAnomaly

Name Description
absolute-form-host-mismatch An absolute-form request target named a host other than the Host header.
conflicting-content-length Content-Length values were not unsigned decimal integers or differed in their text representation.
content-length-transfer-encoding-conflict A request carried both Content-Length and Transfer-Encoding.
decompression-failed A compressed body could not be decompressed, so its raw bytes were inspected. Requests emit ProtocolAnomaly with this value; responses emit ParserFact with this name. Decoded body inspection remains incomplete.
encoded-request-body The body declared a Content-Encoding other than identity.
hop-by-hop-header-abuse The Connection header named a token outside the supported connection-token allowlist.
malformed-cookie-header A Cookie header segment had an empty name or no equals sign.
malformed-percent-encoding The raw path or query contained an invalid percent escape.
malformed-query The query string could not be parsed.
unsupported-charset The body declared a charset Edge cannot decode, so it was inspected as bytes.
upgrade-h2c The request asked for an h2c upgrade or carried an HTTP2-Settings header.

ParserFact

Name Description
body-inspection-truncated A request body, protobuf message or response was inspected only in part.
decompression-limit-exceeded Decompression reached the size or ratio limit; the decompressed prefix is inspected.
duplicate-json-key A JSON object repeated a property name.
duplicate-parameter-name A query, URL-encoded form or multipart field name occurred more than once.
graphql-limit-exceeded GraphQL parsing reached a structural limit; fields already parsed remain available within the work budget.
grpc-messages-uninspected The gRPC per-request inspection count was reached; later messages are outside payload inspection.
json-limit-exceeded JSON parsing reached a structural limit; fields already parsed remain available within the work budget.
jwt-empty-signature A compact JWS had an empty signature segment.
jwt-zero-signature A compact JWS had a signature of zero bytes only.
multipart-limit-exceeded Multipart parsing or archive inspection reached a structural limit; retained fields remain available.
route-allowed-content-type The request has one Content-Type header whose media type is in the route's additional allowed request content types. The value is the lowercase media type.
route-allowed-method The route's additional allowed methods include the request method. The value is the method.
schema-validation-limit-exceeded API schema validation could not finish within its input, estimated-work or runtime safety limits.
websocket-compressed-frame A compressed WebSocket message was observed and its payload was not inspected.
websocket-message-too-large A WebSocket message exceeded the configured cap, so only its retained prefix could be inspected.
xml-doctype An XML body declared a document type.
xml-external-entity An XML body declared an entity with a system or public identifier.
xml-limit-exceeded XML parsing reached a structural limit or stopped inspecting an unsafe DTD subset; retained fields remain available.

Measure

Name Description
archive-entries The number of entries in an uploaded zip archive's central directory.
args-combined-size The combined character length of query argument names and values, plus parsed body argument names or paths and values at the body stage.
args-count The number of query arguments, plus parsed body argument values when inspecting the body.
body-length The byte length seen by body inspection after applicable decompression and charset conversion.
files-combined-size The combined size of every uploaded file part.
graphql-aliases The number of GraphQL field aliases.
graphql-batch-size The number of operations in a GraphQL batch.
graphql-depth The deepest GraphQL selection nesting.
graphql-root-fields The number of root fields in GraphQL operations.
grpc-messages The one-based number of the gRPC message currently being inspected.
header-count The number of request headers.
jwt-signature-length The decoded length of a compact JWS signature.
protobuf-depth The deepest protobuf message nesting the wire walker reached.
xml-depth The deepest XML element nesting.
xml-entity-declarations The number of entities declared in the DTD.

SchemaViolation

Name Description
invalid-content-type The content type is not one the operation accepts.
invalid-type A parameter or JSON body failed schema validation other than a missing-required or forbidden-property check.
missing-required A required parameter or property is missing.
unknown-operation The path and method match no operation in the route's OpenAPI document.
unknown-parameter A query parameter is not declared by the operation.
unknown-property A JSON property is forbidden by additionalProperties false or unevaluatedProperties false.

Work limits

Profiles set these per ruleset; a transaction uses the largest value among applicable rulesets, capped by the engine maximum. Before merging, the local profile’s limits are capped at their defaults. JSON profile properties use camelCase, for example maximumJsonDepth.

Limit Default Engine maximum Description
MaximumInspectedValues 4,096 32,768 Fields inspected in one transaction.
MaximumInspectedCharacters 2,500,000 8,388,608 Characters inspected in one transaction, names included.
MaximumTransformationSteps 4,096 131,072 Transformation steps in one transaction.
MaximumTransformationInputBytes 12,000,000 16,777,216 Bytes entering transformations in one transaction.
MaximumTransformationOutputBytes 12,000,000 16,777,216 Bytes produced by transformations in one transaction.
MaximumRegexInputCharacters 16,384 131,072 Characters of one value a regular expression may scan.
MaximumFindings 32 256 Findings kept per ruleset in one transaction.
MaximumBase64DecodedBytes 65,536 1,048,576 Bytes one base64 transformation may produce.
MaximumTargetCharacters 65,536 1,048,576 Characters in one field value or name.
MaximumTransformationCacheEntries 2,048 32,768 Cached transformation results in one transaction.
MaximumOperatorInvocations 4,096 131,072 Operator evaluations in one transaction.
MaximumOperatorInputValues 65,536 1,048,576 Values passed to operators in one transaction.
MaximumOperatorInputCharacters 320,000,000 536,870,912 Characters scanned by operators in one transaction.
MaximumRegexAttempts 256 4,096 Regular-expression evaluations in one transaction.
MaximumRegexWorkUnits 100,000,000 4,000,000,000 Estimated regular-expression work, based on input length and compiled pattern complexity, in one transaction.
MaximumJsonDepth 32 128 JSON nesting depth.
MaximumJsonTokens 4,096 131,072 JSON tokens in one body.
MaximumBodyFields 4,096 32,768 Fields produced by one body, message or response parser invocation.
MaximumMultipartSections 128 4,096 Parts in one multipart body.
MaximumMultipartHeaders 1,024 32,768 Part headers in one multipart body.
MaximumFieldNameCharacters 1,024 65,536 Characters in one body field name.
MaximumScalarCharacters 65,536 1,048,576 Characters permitted in a structured scalar value or parser text item.
MaximumArgumentNameSegments 32 256 Segments taken from one bracket or dot argument name.
MaximumJwtFields 64 1,024 Header fields and claims taken from one JWT.
MaximumArchiveEntries 1,024 65,535 Entries read from one zip central directory.
MaximumXmlDepth 64 256 XML element nesting depth.
MaximumXmlNodes 16,384 1,048,576 XML nodes in one body.
MaximumXmlAttributes 256 4,096 Attributes on one XML element.
MaximumXmlEntityDeclarations 64 4,096 Entity declarations read from one DTD.
MaximumGraphQlTokens 16,384 262,144 Tokens in one GraphQL document.
MaximumGraphQlDepth 16 128 GraphQL selection nesting depth.
MaximumGraphQlAliases 64 4,096 Aliases in one GraphQL document.
MaximumGraphQlBatchSize 16 256 Operations in one GraphQL batch.
MaximumProtobufDepth 16 64 Nested protobuf messages the wire walker descends into.
MaximumSchemaValidationSteps 16,384 1,048,576 Estimated schema-validation work shared by request parameters and the selected JSON body schema.

Resource settings

These system settings are under Settings → Firewall. They bound decompression, uploaded-file content and overlapping raw-body scans; see Inspected traffic for the route-level controls.

Setting Default Description
MaximumDecompressedBytes 16,777,216 Bytes decompression may produce for one body or value, a system setting.
MaximumDecompressionRatio 100 Output-to-input ratio decompression may reach, a system setting.
MaximumFileContentBytes 65,536 Bytes of each file part inspected, a system setting.
MaximumRawBodyWindowCharacters 65,536 Characters in each overlapping raw-body window, also bounded by MaximumTargetCharacters, a system setting.
MaximumRawBodyCharacters 1,048,576 Distinct decoded characters emitted as raw-body fields before scanning stops, a system setting.