> ## Documentation Index
> Fetch the complete documentation index at: https://docs.payra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Rate limits

> How many requests a key can make, and how to back off.

Limits apply per API key, per minute, with separate buckets for reads (`GET`, `HEAD`) and writes. They are
counted on each server instance, so treat the table as the rate you can rely on and `RateLimit-Remaining` as
approximate. A
publishable key is limited per key and browser IP address.

| Environment          | Reads per minute | Writes per minute |
| -------------------- | ---------------- | ----------------- |
| Sandbox (`sk_test_`) | 300              | 60                |
| Live (`sk_live_`)    | 1000             | 300               |

Every authenticated response carries these headers:

| Header                | Meaning                                 |
| --------------------- | --------------------------------------- |
| `RateLimit-Limit`     | Requests allowed in the current window  |
| `RateLimit-Remaining` | Requests left in the current window     |
| `RateLimit-Reset`     | Seconds until the window resets         |
| `RateLimit-Policy`    | The limit and window the bucket applies |

Past the limit, the API answers `429 rate_limit_exceeded` with a `Retry-After` header. Wait that many seconds, then
retry with exponential backoff. Do not load-test against sandbox.

## Failed authentication

An IP address that receives 60 `401` responses within a minute is refused with `429` for the rest of that minute,
whatever key it sends. Fix the key before retrying.
