Blocked, challenged or rate limited

What to do when a visitor, integration or your own team gets a 403, a 429 or a browser check page.

Every environment checks incoming traffic before it reaches Magento. Legitimate shoppers rarely notice it, but integrations, monitoring tools, scripts and heavy internal testing sometimes get caught. This page helps you find out what happened and fix it.

Symptoms

What you seeWhat it means
403 ForbiddenThe request was blocked.
429 Too Many RequestsThe IP sent more requests than the rate limit allows.
A short "checking your browser" pageThe visitor was challenged. Browsers pass it automatically; scripts and API clients that can't run JavaScript stay stuck on it.

Confirm it on the VM

SSH into the environment as app and look at the security verdicts in the nginx log:

docker logs nginx --since 1h 2>&1 | grep -E '"security_action": "(block|ban|challenge|rate_limited)"'

Each line shows the client IP, the requested path and the verdict. Filter for one IP with an extra grep '<ip>'.

To see whether CrowdSec has an active decision for an IP:

cscli decisions list --ip <ip>

Fixes

A trusted integration or monitoring service is blocked. Add its IP addresses to NGINX__NGINX_WHITELIST in the environment file (.env), then in the Hub open Containers, choose ⋯ → Install on the nginx container to apply it. Allowlisted IPs are never challenged or rate limited, so only add IPs you control or fully trust, such as your office, uptime monitoring or a payment provider's callback addresses.

Your own IP was banned after testing. Remove the decision:

cscli decisions delete --ip <ip>

A legitimate client regularly hits 429. If an integration genuinely needs more throughput, allowlist it as above. For site-wide changes, raise NGINX__RATELIMIT_RPS and NGINX__RATELIMIT_BURST in .env and reinstall the nginx container. The defaults are 150 requests per second per IP with a burst of 900.

API clients see the browser check. Server-to-server integrations can't solve it. Allowlist the integration's IPs.

Search engines. Verified search engine crawlers are never challenged. If a crawler that calls itself Googlebot or Bingbot is being blocked, it is most likely an impostor.

If none of this helps, file a support ticket with the IP address, the URL and the time of the request.

On this page