429 Too Many Requests and the request is not executed.
Limits
Limits are keyed in one of three ways:- per key: the bucket belongs to the API key making the request. Two keys in the same organization have separate budgets.
- per organization: every key in the organization shares one bucket.
- per IP: the bucket belongs to the caller’s source address.
Content
Chats and Agent
GEO
GEO limits span all projects in the organization: four scans per hour is the total across every project, not four per project.
Feedback
POST /v1/feedback/{organizationSlug} is the one endpoint agents call without credentials, so it is limited per source IP address and per organization. Both limits apply at the same time. See Agent Feedback.Response headers
Every response from a rate-limited endpoint, successful or not, includes both the IETF draft header names and the legacyX- names:
Endpoints that are not rate limited do not send these headers.
429 response
When a request is rejected, the API returns:reset is a Unix timestamp in milliseconds. The Retry-After header gives the same moment as a number of seconds to wait and is the simplest field to act on.
A
429 with error: "API key rate limit exceeded" and a code field comes from the authentication layer rather than an endpoint bucket. It means the key itself is throttled. See Authentication.Best practices
- Read
RateLimit-Remainingproactively and slow down before you hit zero. - On
429, wait forRetry-Afterseconds before retrying. Do not retry immediately. - Use exponential backoff with jitter for
5xxresponses; treat429as a hard wait, not a retry signal. - GEO scans are the most expensive thing a key can trigger. Poll
GET /v1/projects/{projectId}/geo/scans/{scanId}for the result instead of re-triggering. - For bulk work (for example backfilling many posts), space requests evenly across the window rather than bursting.
Need higher limits?
If your workload genuinely needs higher limits, reach out via GitHub and describe the use case and expected volume.Next Steps
Getting Started
Explore the endpoint groups
Authentication
Scopes and auth errors