Rate limits
REST requests share rate limits at the account level. Using another API key or workspace does not give the account a separate REST allowance.
Default budgets
| Budget | Code default |
|---|---|
| REST reads | 60 requests per minute |
| REST writes, including AI requests | 15 requests per minute |
| Account budget shared with MCP | 1,000 requests per hour |
These are defaults; service configuration can change them. The response headers report the allowance that applies to your request. The read and write minute budgets are separate. The hourly account budget is shared with MCP.
The legacy GET /profile route does not use this limiter. Legacy POST /post does use the write limiter. There is no separate documented ten-second burst budget.
Response headers
| Header | Meaning |
|---|---|
RateLimit-Limit | Limit for the request's minute budget. |
RateLimit-Remaining | Requests left in that budget. |
RateLimit-Reset | Seconds until that budget resets, not a Unix timestamp. |
X-Account-RateLimit-Limit | Shared hourly account limit. |
X-Account-RateLimit-Remaining | Requests left in the account budget. |
X-Account-RateLimit-Reset | Seconds until the account budget resets. |
Retry-After | On 429, seconds to wait before trying again. |
If you receive 429
Example:
HTTP/1.1 429 Too Many Requests
Retry-After: 8
RateLimit-Limit: 60
RateLimit-Remaining: 0
RateLimit-Reset: 8
{"status": false, "message": "Rate limit exceeded. Retry in 8 seconds."}
Wait at least Retry-After seconds. If requests keep failing, increase the delay. For write requests, also follow the retry guidance.