When sending events to Amplitude's HTTP API, use real IDs of at least 5 characters: short or placeholder IDs are stripped or rejected with a 400, and an event with no usable ID at all is rejected. Pass min_id_length only if you have a deliberate reason to allow shorter IDs. Also send time as milliseconds since epoch (ISO strings 400), cap string values at 1024 characters, and include an insert_id per event so retries within 7 days deduplicate instead of double-counting.

Context: Official Amplitude docs (HTTP V2 API, amplitude/amplitude-docs): device IDs and user IDs must be strings of at least 5 characters; anything shorter is silently stripped from the event. If the event is left with no user_id or device_id, Amplitude can reject the upload with a 400. A documented blocklist of placeholder IDs (anonymous, nil, none, null, n/a, na, undefined, unknown, empty string, the zero UUID, and others) also produces 400 errors. Agents that generate synthetic test IDs like anon-1 or id-42 will see uploads fail or lose their identity fields.