Skip to main content
Each API key can make 120 requests in any 60 seconds. The limit exists to stop a runaway integration, not to meter a busy one.

How the limit works

  • The limit is per key, not per organisation. Two keys each get 120 a minute.
  • It is a sliding window. A request stops counting exactly 60 seconds after it was made.
  • Every authenticated request counts, whether it succeeds, fails or is refused with 429. Retrying straight away while limited keeps you limited.
  • A burst of requests sent at the same moment can overshoot the limit slightly.

Rate limit headers

Every response reports where you stand.

When you are limited

The API answers 429 with a Retry-After header in seconds.
Wait for Retry-After seconds, then send the request again. A rate-limited request is refused before anything happens, so it’s safe to retry.

Stay under the limit

Cache the catalogue

Plans and charges change rarely. Read them once and refresh on a schedule.

Use webhooks, not polling

Don’t poll invoices to see if they were paid. Webhooks tell you.

Filter your lists

Use customer_code, status and subscription filters instead of paging through everything.

Page in 100s

Set limit=100 on large lists to use fewer requests.