Rate limits
Requests are limited per key, per minute. All requests made with the same key share one allowance, whichever server or visitor sends them.
| Key type | Default limit |
|---|---|
| Secret key | 120 requests per minute |
| Publishable key | 300 requests per minute |
| OAuth access token | 120 requests per minute |
Your dealership's current limit is shown in the DMS under Administration > Developers.
The OAuth endpoints (/v1/oauth/authorize, /v1/oauth/token and /v1/oauth/revoke) are called without a key and are limited to 60 requests a minute.
Publishable keys have a second, smaller limit on the public writes (POST /v1/public/enquiries and POST /v1/public/valuation-requests): 10 per minute from any one visitor's IP address. This stops a single browser from spending a website's whole allowance.
Headers
Every response carries the state of the key's allowance:
| Header | Description |
|---|---|
X-RateLimit-Limit | Requests allowed per minute for this key. |
X-RateLimit-Remaining | Requests left in the current window. |
Retry-After | On a 429 only: seconds to wait before retrying. |
When you hit the limit
A request over the limit is refused with 429:
{
"success": false,
"message": "Too many requests. Slow down and retry after the number of seconds in Retry-After.",
"code": "rate_limited",
"request_id": "0b7c9d4e-6f1a-4c3b-8e2d-5a9f7b1c3e60"
}
Wait for the number of seconds in Retry-After, then retry. Do not retry in a tight loop, and spread steady background work out rather than sending it in bursts.
Staying within the limit
- Page with
limit=100. Fewer, larger pages use less of the allowance than many small ones. - Sync incrementally. Use
updated_sinceinstead of re-reading everything. - Use webhooks for changes you need quickly, instead of polling tightly. See Webhooks and events.
- Use batch upload for stock.
POST /v1/vehicles/batchtakes up to 500 vehicles in one request. - Cache public data on your own website's server where you can, rather than calling the API on every page view.
- Use separate keys for separate jobs, so a busy ETL job cannot starve your website.