FLUX API 402, 403 and 503 errors, and Sume's equivalents

BFL returns 402 for credits, 403 for key permission, 503 for load. Sume returns 402 insufficient_credits and 503 provider_capacity_exceeded. What to do.

5 min readSume
All posts

BFL's FLUX API uses 402 when the account has too few credits, 403 when the key lacks permission for the resource, and 503 when the service is unavailable, usually from maintenance or high load. Sume returns 402 insufficient_credits when it cannot reserve the estimated cost from the workspace balance, 401 unauthorized for a missing or invalid key, and 503 provider_capacity_exceeded when its provider dispatch queue is full. Retry the 503; do not retry the 402 until the balance changes.

BFL's list is from its Errors page; Sume's is from its errors and rate limits page and the Image API page. All were read 2026-10-02.

How do the status codes line up?

They line up for 402 and 503, not for 403. BFL's 403 means the API key lacks permission for the resource. Sume's errors page has no 403 row; a missing or invalid key is 401 unauthorized, and a resource outside the workspace is 404 not_found.

BFL status codes from its Errors page against Sume's errors page, read 2026-10-02.
SituationBFLSume
Not enough credits402 Payment Required402 insufficient_credits
Key problem403 Forbidden (no permission for the resource)401 unauthorized
Bad request body400, and 422 for invalid body or parameters400 invalid_request, or 400 unsupported_parameter
Service busy503 Service Unavailable503 provider_capacity_exceeded
Too many requests429429 rate_limited or queue_full

What do I do on a 402 from each?

Both mean the money side blocked the call before an image was made. BFL tells you to add credits. Sume's admission page says the generation submit fails with 402 insufficient_credits before provider work starts, and tells you to wait for included Gen$ on your plan or submit a cheaper request. Retrying unchanged will fail the same way.

What do I do on a 503?

BFL says to try again in a few moments. Sume's errors page says to retry later with the same idempotency key for provider_capacity_exceeded, and not to retry unsafe submit requests without an Idempotency-Key. Back off when a retry-after header is present.

What about bad requests?

BFL separates 400 (format or content) from 422 (invalid body or parameters). Sume answers an unknown or unsupported field with 400 unsupported_parameter, the same status for a field that a model does not list, such as seed or output_compression today. Read the Image API page's capability descriptors, then send only fields the model lists.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume