Skip to content
Published

Last reviewed: 2026-09-15

Credits and 402 responses

Resolve CodeCleared 402 responses for credits, payment failure, or exhausted MAU licenses.

Purpose

A 402 tells you that the requested work lacks applicable credits, payment is failing, or no active license (MAU) remains for the user this month.

Who

Organization and billing owners, plus engineers operating an integration.

Prerequisites

Keep the scan ID, requested scan types, and organization available for diagnosis. Check the response code field.

How it works

  1. Read code on the 402 body:
    • seat_license_required — MAU pool exhausted for this user/month (app redirects to /license-required).
    • payment_failed — unresolved subscription payment failure; open Billing (fix card / subscription invoice). Auto-recharge pack charge failures do not set this code — use insufficient-credits flow or wait for auto-recharge retry (see Billing).
    • other / credits — core or SAST balance (or PAYG) insufficient.
  2. Open Billing (admins) or ask an admin to purchase licenses / credits.
  3. Identify whether the request uses core or SAST credits when the code is credit-related.
  4. Check the plan gate: Free and Starter do not include API access.
  5. On Starter and above, enable or add PAYG if appropriate.
  6. Retry only after a credit, license, or entitlement change.
  7. If auto-recharge is enabled (paid plan, default card on file), members may see an amber auto-recharge in progress banner while a core pack purchase runs, or a SAST auto-recharge in progress banner for SAST; retry once credits land (see Billing).

Business rules

Free cannot use PAYG. Core and SAST pools are distinct. API usage requires an eligible plan. Active licenses (MAU) are consumed on first use in the calendar month and are independent of yearly vs monthly payment.

Scenarios & edge cases

Balance looks sufficient: verify the pool for the requested scan type. API request on Starter: a credit purchase alone does not enable API access. seat_license_required: buying credits does not help — purchase more licenses (Team) or wait for next month. Auto-recharge pack failed but subscription is current: you may get a credit-related 402 (depleted core), not payment_failed; billing admins see auto-recharge status under Settings → Billing → Plan → Advanced options. Unexpected free support scan: CodeCleared platform administrator scans are credit-free — see Credits and Audit logs. Evidence refresh at launch: insufficient credits for the estimated bulk ensure returns 402 and does not create a failed refresh job; mid-flight races can still mark individual units failed (partial / failed on the Evidence refresh job).

Limits

Do not loop retries: repeated 402 requests do not change balance or entitlement.

Common errors

  • Treating 402 as malformed JSON.
  • Retrying before changing Billing, licenses, or plan access.
  • Confusing credit 402 with seat_license_required.

Links