Reference

Rate limits and quotas

Every limit, what it is keyed on, the headers that report it, and how to back off.

Limits keep one runaway loop from hurting everyone else. They are never a CAPTCHA: every limited response says how long to wait, in headers an agent can read.

Request rate limits

Fixed windows
WhatLimitCounted per
Agent endpoints (/v1/execute, /v1/recommend, receipts, jobs, disputes, approvals, /mcp)600 requests a minuteagent key
Org endpoints (/v1/orgs/{orgId}/…)300 requests a minuteorg key or signed-in session (IP when neither)
Public data (/v1/tools, /v1/scores, /v1/pricing, …)120 requests a minuteIP address
Sign-in links (POST /auth/email/start)20 an hourIP address (and at most 5 emails an hour to one address)
Waitlist (POST /v1/waitlist)10 an hourIP address

Headers

Every limited endpoint answers with these headers, on success too, so you can pace yourself before you hit the wall:

Rate-limit headers
HeaderValue
RateLimit-LimitRequests allowed in the window.
RateLimit-RemainingRequests left in this window.
RateLimit-ResetSeconds until the window resets.
RateLimit-PolicyThe limit and window, e.g. 600;w=60.
Retry-AfterOnly on a 429: seconds to wait before trying again.
429 response
HTTP/1.1 429 Too Many Requests
RateLimit-Limit: 600
RateLimit-Remaining: 0
RateLimit-Reset: 17
RateLimit-Policy: 600;w=60
Retry-After: 17

{ "error": { "code": "rate_limited", "message": "Too many requests from this agent. Try again in 17s.", "doc_url": "…/docs/errors#rate_limited", "retryable": true } }

Daily quotas

POST /v1/recommend counts against a daily quota per org, by plan: every call is a score lookup, and a call with free text (task) instead of a task_type also counts one free-text lookup. Over the quota: 429 plan_limit. Quotas reset at 00:00 UTC.

Recommend quotas per day
PlanScore lookupsFree-text lookups
Pay as you go1,000100
Pro10,000500
Maxno fixed limitno fixed limit

Size limits

Size limits
WhatLimitOver it
Request body1 MB413 payload_too_large
Inputs in one execute1,000400 invalid_input
Items run straight away25; more runs as a job—
Job run time2 hours; items not yet run are released as expired—
Webhook endpoints per org10402 plan_limit

Backing off

Updated 2026-09-30 · This page as Markdown · JSON