TikTok spam_risk_too_many_posts vs reached_active_user_cap
Two daily TikTok 403s: spam_risk_too_many_posts is the per-user API post cap, reached_active_user_cap is your client quota. Hold videos till tomorrow.

Both are 403 errors from TikTok Direct Post, and both are daily limits. spam_risk_too_many_posts means the daily post cap from the API is reached for the current user. reached_active_user_cap means the daily quota for active publishing users from your client is reached. Neither is fixed by retrying today; hold the finished Sume videos and publish them on a later day.
TikTok's definitions are from its Direct Post reference; Sume's batch facts from Bulk runs and Structured output, read 2026-10-01.
What is the difference between the two errors?
| Error code | Meaning | Scope |
|---|---|---|
spam_risk_too_many_posts | Daily post cap from the API reached | The current user |
reached_active_user_cap | Daily quota for active publishing users reached | Your client |
spam_risk_user_banned_from_posting | User is banned from making new posts | The user |
Why does a Sume queue make this more likely?
A Sume bulk queue accepts up to 100 items, so one request can produce a day's worth of videos at once. Generation has no TikTok-side cap, but publishing does. Producing 100 videos for one account does not mean you can post 100 that day.
What do I do with the videos that wait?
Keep them. A finished run keeps its generated media with a durable URL and metadata, and media.sume.com URLs do not expire, so the files are there tomorrow. Store each URL against your own record with the date you plan to post, then publish a number you know is under the cap. TikTok's text here gives no number for the cap, so measure what your own client reaches.
How do I avoid the client-wide cap?
reached_active_user_cap is about how many distinct users your client publishes for in a day, so spreading posts across more accounts can hit it sooner. Keep a per-day list of the users you have published for, and defer the rest.
Also avoid reposting near-identical files; see reused content and batches. For per-token pacing see the 6 per minute limit.
Sources
Related posts
More in Developers
- TikTok unaudited_client_can_only_post_to_private_accounts
TikTok returns a 403 when an unaudited client posts to a non-private account. Test with private posts until the audit passes; Sume only supplies the file.
- TikTok url_ownership_unverified with a media.sume.com URL
PULL_FROM_URL needs a TikTok-verified domain or prefix, so a media.sume.com URL fails with 403. Upload the bytes with FILE_UPLOAD or host a copy on your domain.
- TikTok photo post API: 35 image URLs, PULL_FROM_URL, cover index
TikTok's photo post endpoint takes up to 35 public image URLs by PULL_FROM_URL and a photo_cover_index. How to plan the generated-image batches that feed it.
- TikTok photo post API: is_aigc label and auto_add_music
Set is_aigc to true on a TikTok photo post of generated images to add the AI-generated tag. auto_add_music is direct post only. And the audit rule.
Written by Sume