Appearance
API Rate Limits
Rate limits protect the platform and ensure fair usage across all customers. Limits vary by plan and endpoint.
Rate Limit Headers
Every API response includes rate limit information:
| Header | Description |
|---|---|
X-RateLimit-Limit-Requests | Maximum requests allowed in the current window |
X-RateLimit-Remaining-Requests | Requests remaining in the current window |
X-RateLimit-Limit-Tokens | Maximum tokens allowed in the current window |
X-RateLimit-Remaining-Tokens | Tokens remaining in the current window |
Retry-After | Seconds to wait before retrying (only on 429 responses) |
Rate Limit Response
When you exceed the rate limit, the API returns HTTP 429 Too Many Requests:
json
{
"error": "rate_limit_exceeded",
"message": "Too many requests. Please retry after 30 seconds.",
"retryAfter": 30
}Handling Rate Limits
javascript
async function callWithRateLimit(requestFn) {
const response = await requestFn();
if (response.status === 429) {
// Use Retry-After header for precise timing
const retryAfter = parseInt(response.headers.get('Retry-After') || '5');
console.log(`Rate limited. Retrying in ${retryAfter}s...`);
await new Promise(r => setTimeout(r, retryAfter * 1000));
return callWithRateLimit(requestFn); // Retry
}
// Track remaining quota proactively
const remaining = parseInt(response.headers.get('X-RateLimit-Remaining-Requests') || '-1');
if (remaining >= 0 && remaining < 10) {
console.warn(`Low quota: ${remaining} requests remaining`);
}
return response;
}Best Practices
- Monitor headers proactively - Slow down before hitting the limit by watching
Remainingvalues. - Use exponential backoff - When retrying, increase delays: 1s, 2s, 4s, 8s (capped at 60s).
- Cache repeated prompts - If you execute the same prompt frequently, cache the response.
- Batch when possible - Group related operations rather than making many individual calls.
- Use stored prompts - Store frequently-used prompts via the dashboard and execute by ID to reduce payload size.
Login Rate Limits
The authentication endpoint has a separate rate limit to prevent brute-force attacks. After too many failed login attempts, you must wait 15 minutes before retrying.
