Rate limiting

​

API requests are rate limited per API key (falling back to per user). The default limit is 200 requests per 60-second window.

Every response includes headers describing your current limits:

Header Description
X-RateLimit-Limit Maximum requests allowed per window
X-RateLimit-Remaining Requests remaining in the current window
X-RateLimit-Reset Unix time, in seconds, when the current window resets

When you exceed the limit you receive a 429 Too Many Requests response with a Retry-After header giving the number of seconds to wait before retrying. The body uses the standard error envelope:

{
  "error": {
    "type": "rate_limit_error",
    "code": "rate_limited",
    "message": "Rate limit exceeded"
  }
}

The MCP endpoint shares the same per-key limit and headers, but answers 429 as a JSON-RPC error object instead:

{
  "jsonrpc": "2.0",
  "id": null,
  "error": { "code": -32000, "message": "Rate limit exceeded. Retry after 42 seconds." }
}