The API uses rate limiting to ensure service stability for all users. Limits are enforced using a token bucket algorithm.
| Client type | Limit | Window | Partition |
|---|---|---|---|
| Authenticated | 100 requests | 60 seconds | Per account |
| Unauthenticated | 10 requests | 60 seconds | Per IP address |
The bucket replenishes fully at the start of each 60-second window.
When you exceed the rate limit, the API returns a 429 Too Many Requests response with a Retry-After header indicating how many seconds to wait before retrying:
HTTP/1.1 429 Too Many Requests
Content-Type: application/problem+json
Retry-After: 60{
"type": "https://docs.apiera.io/problems/rate-limit-exceeded",
"title": "Too Many Requests",
"status": 429,
"detail": "Rate limit exceeded. Please retry after the specified time.",
"instance": "/v1/products",
"correlationId": "550e8400-e29b-41d4-a716-446655440000"
}Always respect the Retry-After header value before retrying.
Spread requests evenly. Avoid bursting all requests at once. Distribute them across the window.
Cache responses. Avoid re-fetching data that hasn't changed. Use the hydration system to fetch related data in a single request instead of making multiple calls.
Use bulk endpoints. Where available, prefer bulk operations over individual requests.
Implement backoff. If you receive a 429, wait for the Retry-After duration before retrying. Do not retry immediately in a tight loop.
Contact support to discuss enterprise rate limits for your organization.