Default limits
Limits are applied per API key, not per user. If you have multiple keys, each has its own quota.
Rate limit headers
Every response includes rate limit metadata so you can track your consumption:Handling 429 responses
When you exceed the limit, the API returns429 Too Many Requests with a Retry-After header:
Retry-After before retrying.
Best practices
Use exponential backoff
Use exponential backoff
When you receive a 429, don’t retry immediately. Wait
Retry-After seconds on the first retry, then double the wait on subsequent retries up to a maximum (e.g. 60 seconds).Cache responses
Cache responses
Cache responses that don’t change frequently - session lists, template configs, org settings. Use
Cache-Control or a local TTL to avoid unnecessary requests.Batch operations
Batch operations
Instead of making one request per resource, use list endpoints with filters and pagination. A single
GET /api/sessions?limit=100 replaces 100 individual GET /api/sessions/{id} calls.Monitor your usage
Monitor your usage
Check
X-RateLimit-Remaining in responses proactively. If you are consistently running close to the limit, consider requesting a higher tier or optimizing your request patterns.