Rate limits

The limits a key meets and the RateLimit and Retry-After headers.

Limits keep one busy system from slowing the others. The portal keeps a burst bucket for each key in front of the service, and the service keeps the limits that count across the whole platform. Whichever limit refuses a request, the answer is 429 rate_limited with a Retry-After header.

The limits

LimitAllowanceBucketCounts
Failed sign-ins per address10 per minuteportal:authRequests from one network address whose key is missing or refused. Once reached, every request from that address answers 429 until the minute is over, before its key is read.
Burst per key60 per minuteportal:keyA bucket of 60 requests per key that refills at one a second. The RateLimit-* headers of every answer report it.
Calls per key600 per 10 minuteskey:{prefix}Every call a key makes, over REST and MCP together, counted across every instance of the portal.
Writes per key120 per minutew:{prefix}Every call that records something: acknowledgements, affidavits, show certificates and applied log matches.
Log uploads per affiliation20 per dayup:a:{affiliation id}Uploaded logs for one affiliation in a day, whoever sends them.
Log uploads per key10 per hourup:p:{prefix}Uploaded logs one key sends in an hour.
Log reading per network2,000,000 per dayllm:n:{network cloud}The reading budget of the network's stations for uploaded logs in a day, in units of text read. When it runs out, an upload answers that the reading limit for today is reached; type the times instead.

Each endpoint page lists the buckets its calls count against. {prefix} is the key's public prefix, the part of the key before its secret.

The headers

HeaderMeaning
RateLimit-LimitThe size of the key's burst bucket: 60.
RateLimit-RemainingRequests left in the burst bucket. On every 429 it is 0.
RateLimit-ResetSeconds until the burst bucket is full again. On a 429 it equals Retry-After.
Retry-AfterOn every 429: the seconds to wait before trying again.

The RateLimit-* headers report the burst bucket as the REST API sees it; calls the same key makes over MCP or through downloads are not in that count, and the platform limits are counted by the service. Treat the headers as a guide and a 429 as the answer.

Staying clear of them

  • Pace with RateLimit-Remaining: slow down as it nears 0 instead of waiting for a 429.
  • Report in batches. One report-affidavits call takes up to 2,000 items and counts once.
  • Use webhooks to hear about new versions and arrived audio instead of polling for them.
  • After a 429, wait Retry-After seconds, then retry once. Do not retry in a tight loop.