Skip to content

API rate limits

Stay under 600 requests a minute per key, read the RateLimit headers, and back off when you get a 429.

Each API key may send 600 requests per minute. When you pass the limit, Avaloi returns 429 with Retry-After in seconds and RateLimit headers.

Read the headers

Header Meaning
RateLimit-Limit Maximum requests in the window.
RateLimit-Remaining Requests left in this window.
RateLimit-Reset Unix time when the window resets.
Retry-After Seconds to wait after a 429.

The headers tell you which window you hit.

Limits

  • 600 requests per minute per key.
  • 60 requests per minute for routes that create a job, such as POST /v1/sites or POST /v1/environments/{id}/tools/cache/clear.
  • Auth routes on the dashboard: 20 attempts per 10 minutes per IP, and 10 per account.

Back off

Wait for Retry-After before you try again. Do not retry in a tight loop. For a watcher, follow a job's event stream instead of polling it; see Jobs and progress.

Quick answers

I got 429 with requests to spare. You hit the job-creating window, 60 per minute. Check RateLimit-Limit to see which window answered.

Does the limit apply per company or per key? Per key. Two keys in one company have separate windows.

Does a 429 count against the window? Read RateLimit-Remaining and RateLimit-Reset, then wait for the reset.

API

  • GET /v1/jobs/{id}/events
  • GET /v1/jobs/{id}

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.