Some API requests may be blocked by Cloudflare when they use a User-Agent that Cloudflare identifies as belonging to an automated script, bot, or other potentially unwanted traffic.


This is a security feature provided by Cloudflare called Browser Integrity Check (BIC). BIC helps protect our API infrastructure from automated traffic that may be associated with malicious activity, such as spam or denial-of-service attacks.


What does the error mean?

If your request is blocked by BIC, you may receive a Cloudflare 1010 error or a response indicating that the request was blocked by the Browser Integrity Check.

This means the request was blocked by Cloudflare before it reached our API. It does not necessarily indicate a problem with your API request, authentication, or the API itself.

For example, Cloudflare may block requests using a User-Agent associated with certain automated HTTP libraries, such as:


Python-urllib/3.x


How Can I Resolve This?

If your API requests are being blocked, we recommend using a different User-Agent that clearly identifies your application or integration.


Example:


User-Agent: MyApplication/1.0


If you are using an HTTP library that automatically sets the User-Agent, check its documentation to determine how to provide a custom value.

Using a descriptive User-Agent helps identify your application and may prevent Cloudflare from incorrectly identifying the request as potentially unwanted automated traffic.


Why Doesn't Lulu Disable This Security Check?

Browser Integrity Check is part of the security protections we use to help protect our infrastructure and API services from unwanted automated traffic.

While some API paths have specific Cloudflare exceptions for automated requests, we do not disable these protections for all API endpoints. This allows us to maintain security controls while still supporting known automated workflows.

If changing the User-Agent does not resolve the issue, please contact Lulu Support and provide the following information:

  • The API endpoint you are requesting
  • The HTTP method being used
  • The User-Agent included with the request
  • The Cloudflare error or response you received
  • The approximate date and time of the failed request

This information will help us determine whether the request is being blocked by Cloudflare or if there is another issue with the API request.