Skip to main content
Every response includes standard rate-limit headers. Integrations should honor them before retrying.

Headers

On HTTP 429:
API/OAuth error bodies use the nested error envelope; the payload may also include retryAfter / violation metadata depending on the path.

Defaults

  • Default: about 1000 requests per minute per authenticated principal (user+IP) or IP for unauthenticated probes.
  • Individual routes may declare stricter decorators (for example auth email send, or high-cost writes).
  • Workspace plan-based hourly caps exist for some product features; curated Broad traffic is primarily gated by the per-route / default limiters above.
Backoff with jitter after 429s. Do not spin on Retry-After: 0.