How the limit works
- The limit is per key, not per organisation. Two keys each get 120 a minute.
- It is a sliding window. A request stops counting exactly 60 seconds after it was made.
- Every authenticated request counts, whether it succeeds, fails or is refused with
429. Retrying straight away while limited keeps you limited. - A burst of requests sent at the same moment can overshoot the limit slightly.
Rate limit headers
Every response reports where you stand.When you are limited
The API answers429 with a Retry-After header in seconds.
Retry-After seconds, then send the request again. A rate-limited request is refused before anything happens, so it’s safe to retry.
Stay under the limit
Cache the catalogue
Plans and charges change rarely. Read them once and refresh on a schedule.
Use webhooks, not polling
Don’t poll invoices to see if they were paid. Webhooks tell you.
Filter your lists
Use
customer_code, status and subscription filters instead of paging through everything.Page in 100s
Set
limit=100 on large lists to use fewer requests.