Skip to main content
Limits apply per API key, per minute, with separate buckets for reads (GET, HEAD) and writes. They are counted on each server instance, so treat the table as the rate you can rely on and RateLimit-Remaining as approximate. A publishable key is limited per key and browser IP address. Every authenticated response carries these headers: Past the limit, the API answers 429 rate_limit_exceeded with a Retry-After header. Wait that many seconds, then retry with exponential backoff. Do not load-test against sandbox.

Failed authentication

An IP address that receives 60 401 responses within a minute is refused with 429 for the rest of that minute, whatever key it sends. Fix the key before retrying.