Skip to content

Rate limits

Works on the Free plan. Options marked Pro below need a Pro plan.

Each API key has a request allowance per minute. Response headers show the remaining allowance and when it resets.

You need: an API key for the integration.

Plan Requests per minute, per key
Free 60
Pro 600

Each key has its own allowance. Give separate integrations separate keys to keep their request counts independent.

A higher allowance does not grant permissions or remove feature limits. Check the endpoint’s required scope and plan before calling it.

The limit is approximate: some requests above the listed allowance may succeed. Do not rely on that extra capacity. Pace requests using the response headers.

Responses to authenticated API requests include:

RateLimit-Limit: 60
RateLimit-Remaining: 58
RateLimit-Reset: 41
Header Meaning
RateLimit-Limit The allowance for this minute.
RateLimit-Remaining Requests remaining in the current window.
RateLimit-Reset Seconds until the allowance resets.

When RateLimit-Remaining reaches zero, wait RateLimit-Reset seconds before sending another request. The allowance resets at the next minute boundary, rather than one minute after your first request.

Conditional requests count towards the allowance, including those answered with 304 Not Modified. Use If-None-Match to avoid downloading unchanged data, and poll only as often as the integration needs.

Requests over the allowance return 429 Too Many Requests with a problem document:

{
"status": 429,
"title": "Too many requests",
"detail": "This key is over its limit of 60 requests per minute. Retry in 12 seconds, or spread the calls out: the RateLimit-Remaining header on every response says how much of the current window is left.",
"code": "rate_limited"
}
  1. Read Retry-After, which gives the wait in seconds.
  2. Wait at least that long before retrying. RateLimit-Reset gives the same wait; neither value is zero.
  3. If several workers share a key, stagger their retries so they do not all send at once.

Flood protection can refuse traffic from one network address before the API checks its key. These responses have code: "rate_limited" but no RateLimit-* headers.

Pause requests from that address for a minute and check for a retry loop or a burst across integrations sharing the address. This limit is shared by network address, not by key.

Request a larger page instead of making many small list requests. Reduce polling frequency when a delayed update is acceptable.

If the integration still needs more capacity, contact support with its request rate and the endpoints it uses.