Rate limits
How many API requests you can make, and how to tell when you are close.
Authenticated API requests are limited to 3600 requests per hour per project. All API tokens of a project share this budget, so creating more tokens does not raise it. Requests from a console session count against a separate budget per user.
Every authenticated response tells you where you stand:
| Header | Meaning |
|---|---|
RateLimit-Limit | Requests allowed per window (3600) |
RateLimit-Remaining | Requests left in the current window |
RateLimit-Reset | Seconds until the window resets |
HTTP/1.1 200 OK
RateLimit-Limit: 3600
RateLimit-Remaining: 3542
RateLimit-Reset: 1834When the budget is used up, the API answers 429 Too Many Requests with the code rate_limit_exceeded and a
Retry-After header (seconds). Wait that long before retrying. The odx CLI and the Terraform provider do this for you.
Some endpoints have their own, stricter limits:
- Reverse DNS changes: 60 per hour per project.
- Sign-up, login, two-factor codes, password reset and verification emails are limited per IP address and per account to stop abuse. These only concern the console.
Polling efficiently
Most requests in scripts are polls of actions. Poll every second or two rather than in a tight
loop, and list resources with per_page=50 (the maximum) to need fewer pages.