Getting started
Rate limits
120 requests per minute per API key is plenty for polling a handful of orders at once. Every response tells you where you stand.
Limits
Limits use fixed one-minute windows and are shared across all servers, so they hold however you spread your traffic.
- Per API key
- 120 requests per minute, every endpoint combined.
- Per IP, unauthenticated
- 120 requests per minute for requests without a valid key (including failed authentication).
- Creating orders
- 20 per minute per account, across all keys and the web app. Only orders that go through count.
- Renting numbers
- 10 per minute per account.
- Request body
- 16 KB of JSON. Larger bodies get 413 payload_too_large.
Headers
On every response, success or error:
- X-RateLimit-Limit
- Requests allowed per window.
- X-RateLimit-Remaining
- Requests left in the current window.
- X-RateLimit-Reset
- Unix time, in seconds, when the window resets.
- Retry-After
- Only on 429: seconds to wait before trying again.
When you hit a limit
You get a 429 with the rate_limited code. Nothing happened, so it’s always safe to retry — after Retry-After seconds. The per-account order limit answers the same way, and its X-RateLimit-* headers then describe that limit.
HTTP/1.1 429 Too Many Requests
Retry-After: 23
X-RateLimit-Limit: 120
X-RateLimit-Remaining: 0
X-RateLimit-Reset: 1791325860
{
"error": {
"code": "rate_limited",
"message": "Rate limit exceeded: 120 requests per minute. Retry after the time in Retry-After.",
"details": { "limit": 120, "reset_at": "2026-10-06T14:31:00.000Z" }
}
}Retry after a 429
async function request(url, init, attempt = 0) {
const res = await fetch(url, init);
if (res.status === 429 && attempt < 5) {
const wait = Number(res.headers.get("retry-after") ?? 1);
await new Promise((resolve) => setTimeout(resolve, wait * 1000));
return request(url, init, attempt + 1);
}
return res;
}Polling lots of orders? A webhook is cheaper than polling: see Webhooks.