Rate limiting
API requests are rate limited per API key (falling back to per user). The default limit is 200 requests per 60-second window.
Every response includes headers describing your current limits:
| Header | Description |
|---|---|
X-RateLimit-Limit |
Maximum requests allowed per window |
X-RateLimit-Remaining |
Requests remaining in the current window |
X-RateLimit-Reset |
Unix time, in seconds, when the current window resets |
When you exceed the limit you receive a 429 Too Many Requests response with a Retry-After header
giving the number of seconds to wait before retrying. The body uses the standard error envelope:
{
"error": {
"type": "rate_limit_error",
"code": "rate_limited",
"message": "Rate limit exceeded"
}
}
The MCP endpoint shares the same per-key limit and headers, but answers 429 as a JSON-RPC error object instead:
{
"jsonrpc": "2.0",
"id": null,
"error": { "code": -32000, "message": "Rate limit exceeded. Retry after 42 seconds." }
}