Skip to content

API Rate Limits ​

Rate limits protect the platform and ensure fair usage across all customers. Limits vary by plan and endpoint.

Rate Limit Headers ​

Every API response includes rate limit information:

HeaderDescription
X-RateLimit-Limit-RequestsMaximum requests allowed in the current window
X-RateLimit-Remaining-RequestsRequests remaining in the current window
X-RateLimit-Limit-TokensMaximum tokens allowed in the current window
X-RateLimit-Remaining-TokensTokens remaining in the current window
Retry-AfterSeconds to wait before retrying (only on 429 responses)

Rate Limit Response ​

When you exceed the rate limit, the API returns HTTP 429 Too Many Requests:

json
{
  "error": "rate_limit_exceeded",
  "message": "Too many requests. Please retry after 30 seconds.",
  "retryAfter": 30
}

Handling Rate Limits ​

javascript
async function callWithRateLimit(requestFn) {
  const response = await requestFn();

  if (response.status === 429) {
    // Use Retry-After header for precise timing
    const retryAfter = parseInt(response.headers.get('Retry-After') || '5');
    console.log(`Rate limited. Retrying in ${retryAfter}s...`);
    await new Promise(r => setTimeout(r, retryAfter * 1000));
    return callWithRateLimit(requestFn); // Retry
  }

  // Track remaining quota proactively
  const remaining = parseInt(response.headers.get('X-RateLimit-Remaining-Requests') || '-1');
  if (remaining >= 0 && remaining < 10) {
    console.warn(`Low quota: ${remaining} requests remaining`);
  }

  return response;
}

Best Practices ​

  • Monitor headers proactively - Slow down before hitting the limit by watching Remaining values.
  • Use exponential backoff - When retrying, increase delays: 1s, 2s, 4s, 8s (capped at 60s).
  • Cache repeated prompts - If you execute the same prompt frequently, cache the response.
  • Batch when possible - Group related operations rather than making many individual calls.
  • Use stored prompts - Store frequently-used prompts via the dashboard and execute by ID to reduce payload size.

Login Rate Limits ​

The authentication endpoint has a separate rate limit to prevent brute-force attacks. After too many failed login attempts, you must wait 15 minutes before retrying.