Skip to main content
Start with the HTTP status:
  • 200 with no rows: the query worked but matched nothing.
  • 400: the query was rejected.
  • 422 or 429: the query ran and hit a limit.
  • 412: analytics isn’t turned on.
  • 403: the root key is missing a permission.

No rows came back

Check the time filter. Raw tables store time in milliseconds, so WHERE time >= now() - INTERVAL 1 DAY matches nothing. Write time >= toUnixTimestamp64Milli(now() - INTERVAL 1 DAY) instead. Rollup tables take DateTime or Date values directly. Check IDs. key_space_id is the keyspace’s ks_ ID, not the api_ ID. namespace_id is an rlns_ ID, not the namespace name. Values are case-sensitive, and outcome values are upper case (VALID, not valid). Check retention. Data older than your plan’s log retention is left out, often without an error. See Working with time. Check the root key. If it has read_analytics for specific keyspaces or namespaces only, rows outside them are left out without an error.

The query was rejected (400)

The query ran but failed (422 or 429)

Analytics isn’t configured (412)

err:unkey:data:analytics_not_configured means analytics isn’t turned on for your workspace. Email support@unkey.com with your workspace ID to turn it on. A 503 with analytics_connection_failed is different: analytics was briefly unavailable, so retry with backoff.

Permission denied (403)

insufficient_permissions names the permission the root key needs: api.*.read_analytics or api.<api_id>.read_analytics for verifications, ratelimit.*.read_analytics or ratelimit.<namespace_id>.read_analytics for rate limits. Grant it under Settings > Root Keys. See Root key permissions.

Numbers that look wrong

  • A rollup total is far too low. You probably wrote count() instead of sum(count). Each rollup row sums many verifications.
  • A percentage is null. It divided by zero.
  • external_id is empty for many rows. Those keys have no identity. Group by key_id instead, or attach identities when you create keys.
Last modified on September 29, 2026