> For the complete documentation index, see [llms.txt](https://docs.tryterra.co/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.tryterra.co/faq/help-topics/webhook/security-signatures-and-network-access/modsecurity-waf-json-keys-rule.md).

# Why does ModSecurity block my webhooks on JSON keys?

This is **expected** for data types with large time-series sample arrays (heart rate, SpO2, and similar), where a full day easily exceeds 1000 JSON keys.

The payload follows the documented schema and is already a single data payload for one user and one type, so **there is nothing to split further**.

**Fix it on the ModSecurity side:**

* Raise `SecArgumentsLimit` for the endpoint, or
* Add a rule exclusion so the JSON-keys rule does not apply to incoming Terra payloads.
