Integrations

Errors and limits

What an error looks like, how many calls you can make, which addresses calls may come from, and how to retry safely and read a long list.

This page is for the developer writing the code that calls InMyWords and handles its answers.

It lists every error code, the limits on calls and on the addresses they come from, the rules for retrying a change safely, and how to read a list page by page.

Errors

An error answers an HTTP status and a body:

{
  "error": {
    "code": "scope_missing",
    "message": "This connection does not hold cases:write."
  }
}

code is stable, and it is what your program should read. message is written for a person and may change.

Every answer, error or not, carries an X-Request-Id header of 16 hex characters. Quote it when you ask us about a call.

StatusCodeMeaning
400invalid_requestthe request cannot be read: malformed JSON, a wrong type, or a bad limit, cursor or updated_since
401unauthorisedthe key is missing, malformed or revoked
403module_offthe Integrations module is off for your organisation, or its integrations data policy has not been accepted
403ip_not_allowedyour organisation allows calls only from the addresses it has listed, and this is not one
403scope_missingthe connection does not hold the scope the call needs
403permission_not_grantablethe call would give a group Manage users, Manage billing, Manage integrations or Manage groups, or put a person in a group that holds one
404not_foundthere is no such thing, or it belongs to another organisation
409named per endpointthe change conflicts with the state of your organisation, for example last_people_manager, group_holds_cases, in_another_organisation
409idempotency_key_in_usea request with the same Idempotency-Key is still being answered; retry after Retry-After seconds
422validation_failedthe request was read but a value is not allowed; the message names the field
422unknown_permissiona permission code that does not exist
422idempotency_key_reusedan Idempotency-Key already used for a different request: another body, address or method
429rate_limitedthe connection has made more calls this minute than it is allowed, or too many refused calls came from one address
500server_errora fault at InMyWords; nothing was changed unless the answer says otherwise

How many calls you can make

A connection can make 120 calls a minute by default. InMyWords sets the figure.

Calls are counted per clock minute, from second 0 to second 59. A call over the limit answers 429 rate_limited with a Retry-After header, in seconds.

HTTP/1.1 429 Too Many Requests
Retry-After: 23
X-Request-Id: 3f9a1c0e7b2d4e6f
{
  "error": {
    "code": "rate_limited",
    "message": "Too many calls this minute."
  }
}

Calls refused with 429 still count towards the minute.

Calls from one address that are refused 401 are counted too. After 60 in a minute, every call from that address, with any key, answers 429 rate_limited until the minute ends.

Which addresses calls may come from

Your organisation can list the addresses its people may reach InMyWords from. Its connections are held to the same list.

  1. Where your organisation enforces its list, a call from an address not on it answers 403 ip_not_allowed.
  2. Where it only reports, the call is answered, and your organisation's audit trail records the address under the connection's name.

Ask for the addresses your other software calls from to be added to the list.

Sending a change only once

Every POST takes an Idempotency-Key header of up to 255 characters. A random UUID makes a good key.

  1. The key is kept for 24 hours, per connection.
  2. Same key, same address, same body. Within 24 hours you get the first result back, with its status and an Idempotent-Replayed: true header, and nothing changes.
  3. Same key, different body, address or method. This answers 422 idempotency_key_reused.
  4. Same key while the first is still being answered. This answers 409 idempotency_key_in_use with Retry-After: 1. Only one of the two is carried out.
  5. A request that failed with a 5xx keeps nothing. You can send the same key again, and it is carried out.
  6. Something shown once is not shown again. An answer that showed something once, such as a webhook's secret, is replayed without it.
  7. No key. The POST is carried out every time it is sent.
curl -X POST https://app.inmywords.chat/api/integrations/v1/cases \
  -H "Authorization: Bearer imw_3f9a0c2e7b1d4a6f8e0c2b4d6f8a0c2e4b6d8f0a2c4e6b8d0f2a4c6e8b0d2f4a" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 6d1f0b7a-2c44-4f0e-9a3b-1e5c7d9f2a10" \
  -d '{"title": "Housing claim", "external_ref": "CMS-20931"}'

When to retry

AnswerRetry
429yes, after Retry-After seconds
500, or no answeryes, with the same Idempotency-Key for a POST
409 idempotency_key_in_useyes, after Retry-After seconds, with the same key
400, 401, 403, 404, other 409, 422no; the same request gets the same answer

Reading a long list

A list answers {"data": [...], "next_cursor": "..."}, newest first. limit is 50 by default and 100 at most, and a larger value is reduced to 100. A limit that is not a whole number from 1 answers 400 invalid_request.

To read the next page, pass next_cursor back as cursor. A null cursor means you have the last page. A cursor is opaque, so do not build or change one.

To fetch only what has changed, give updated_since an ISO 8601 UTC time, for example 2026-10-03T14:05:00Z, and you get back only what changed after it. Each list says what counts as a change. A list that does not offer updated_since answers 400 invalid_request.

A bad cursor or updated_since answers 400 invalid_request.

curl "https://app.inmywords.chat/api/integrations/v1/conversations?limit=100&cursor=eyJiIjo4ODEyfQ&updated_since=2026-10-01T00:00:00Z" \
  -H "Authorization: Bearer imw_3f9a0c2e7b1d4a6f8e0c2b4d6f8a0c2e4b6d8f0a2c4e6b8d0f2a4c6e8b0d2f4a"

What is logged

Every call is logged against the connection, with its method, address, status and time taken. Your organisation can read the log on the connection's page.

Every change, and every read of a conversation's words, is also written on your organisation's audit trail under the connection's name.