Rate limits
How public API request limits, headers, and retries work.
View as MarkdownAuthenticated public API requests are rate limited per workspace. Requests made with any valid key for the same workspace share the same bucket, so creating more keys does not increase the limit. The public OpenAPI schema at /api/v1/openapi.json is not rate limited.
Current default limits:
| Window | Limit |
|---|---|
| Per minute | 60 requests |
| Per day | 1,000 requests |
Repeated failed authentication attempts are limited separately to 120 requests per minute and 10,000 requests per day per source IP.
Response headers
Successful limited requests include headers for the currently binding window:
| Header | Meaning |
|---|---|
X-RateLimit-Limit | The request limit for the active window |
X-RateLimit-Remaining | Requests remaining in that window |
X-RateLimit-Reset | Unix timestamp when the window resets |
X-Request-Id | Request identifier for support and logs |
When you hit the limit
If either the minute or day window is exhausted, the API returns 429 TOO_MANY_REQUESTS:
The response also includes Retry-After, in seconds. Wait at least that long before retrying. Include requestId when contacting aclipp support.
Client guidance
- Treat
Retry-Afteras authoritative for429responses. - Add backoff and jitter when retrying automated jobs.
- Cache stable reads, especially project configuration and metadata lists.
- Paginate list requests instead of making many narrow repeated calls.