Skip to content

Getting started

Rate limits

120 requests per minute per API key is plenty for polling a handful of orders at once. Every response tells you where you stand.

Limits

Limits use fixed one-minute windows and are shared across all servers, so they hold however you spread your traffic.

Per API key
120 requests per minute, every endpoint combined.
Per IP, unauthenticated
120 requests per minute for requests without a valid key (including failed authentication).
Creating orders
20 per minute per account, across all keys and the web app. Only orders that go through count.
Renting numbers
10 per minute per account.
Request body
16 KB of JSON. Larger bodies get 413 payload_too_large.

Headers

On every response, success or error:

X-RateLimit-Limit
Requests allowed per window.
X-RateLimit-Remaining
Requests left in the current window.
X-RateLimit-Reset
Unix time, in seconds, when the window resets.
Retry-After
Only on 429: seconds to wait before trying again.

When you hit a limit

You get a 429 with the rate_limited code. Nothing happened, so it’s always safe to retry — after Retry-After seconds. The per-account order limit answers the same way, and its X-RateLimit-* headers then describe that limit.

Response
HTTP/1.1 429 Too Many Requests
Retry-After: 23
X-RateLimit-Limit: 120
X-RateLimit-Remaining: 0
X-RateLimit-Reset: 1791325860

{
  "error": {
    "code": "rate_limited",
    "message": "Rate limit exceeded: 120 requests per minute. Retry after the time in Retry-After.",
    "details": { "limit": 120, "reset_at": "2026-10-06T14:31:00.000Z" }
  }
}
async function request(url, init, attempt = 0) {
  const res = await fetch(url, init);
  if (res.status === 429 && attempt < 5) {
    const wait = Number(res.headers.get("retry-after") ?? 1);
    await new Promise((resolve) => setTimeout(resolve, wait * 1000));
    return request(url, init, attempt + 1);
  }
  return res;
}

Polling lots of orders? A webhook is cheaper than polling: see Webhooks.