# invalid_parameter

Source: https://capacms.com/docs/errors/invalid_parameter

400 invalid_request. A request parameter is missing or out of range: first outside 1 to 200, more than 3 sort values, a non-UUID id, bad JSON in variables.

| HTTP status | `type`            | Surfaces      |
| ----------- | ----------------- | ------------- |
| 400         | `invalid_request` | REST, GraphQL |

## What it means

A request parameter is missing or out of range: first outside 1 to 200, more than 3 sort values, a non-UUID id, bad JSON in variables.

| When                                                                                                                                                                                    | What the `hint` tells you                                                                                                                                        |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| a query parameter the route does not read, `limit` or `count` malformed, a malformed `sort` or more than three sort keys, a repeated query key, or a paging parameter on a single entry | for a legacy parameter, the `/api/` form; for any other name, the parameters there are; the accepted range, the sort grammar, or that only `select` applies here |

## What to do

Change the argument the message names to a value the hint allows.

## The response

HTTP 400:

```json
{
  "error": {
    "type": "invalid_request",
    "code": "invalid_parameter",
    "message": "limit was sent more than once.",
    "param": "limit",
    "docs": "https://docs.capacms.com/errors/invalid_parameter"
  },
  "meta": {
    "version": "2026-10-01",
    "contract": 1,
    "requestId": "req_0f3c…"
  }
}
```

## On GraphQL

`/api/graphql` answers the same `code` inside `errors[].extensions`. The status depends on the `Accept` header you send ([status codes](https://capacms.com/docs/api/graphql#status-codes)):

| `application/json` | `graphql-response+json` | When                                                                                                                                                                                                                                                                                                                               |
| ------------------ | ----------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 400                | 400                     | the request itself: no `query`; a body that is not JSON; a batch; wrong content type; a body, URL or variables over the limit; `variables` that is not an object; a malformed `extensions.persistedQuery`; an `extensions.capa` that is not `true` or `false`; a `Capa-Persist` other than `pin` or `pin; release=<id>; env=<env>` |
| 200                | 400                     | the document: variables that do not match their types; `operationName` missing or unknown with several operations; `first`, `last` or `sort` out of range; `first` with `before`, or `last` without `before`, with `first` or with `after`; an id that is not a UUID                                                               |

## See also

* [Entries](https://capacms.com/docs/api/entries)
* [Limits](https://capacms.com/docs/api/limits)
