Input Validation

Path parameters: All URL path parameters named id or ending in ID (e.g., networkID, deviceID) are validated as UUID format. Invalid โ€” including empty โ€” values return 400 Bad Request (an empty segment like /networks//evpn/instances never reaches a handler).

String length limits: Text inputs are validated on creation/update endpoints:

Field type Max length
Names (name, username) 255 characters
Display names 255 characters
Descriptions 2,000 characters

WebSocket: Client subscribe messages limited to 4 KB.