Rate limits
Shared, database-backed limits with standard headers and no extra service to configure.
Last updated · September 2026
On this page
Rate limiting is shared and distributed with no external service: fixed-window counters live in the same PostgreSQL database, so limits hold across all server instances. If the database is briefly unreachable, the app degrades to a per-instance in-memory limit instead of failing open.
Reading the headers
Every rate-limited response carries X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset (unix seconds). A 429 means the window is exhausted. Back off until the reset time instead of retrying immediately.
A throttled responsebash
HTTP/1.1 429 Too Many Requests
X-RateLimit-Limit: 10
X-RateLimit-Remaining: 0
X-RateLimit-Reset: 1757932800
{"error": "Too many attempts. Try again later."}What is limited
- Authentication endpoints are throttled per IP and per account, so one account cannot be hammered from rotating IPs.
- Admin actions are throttled per admin.
- Generation and checkout endpoints enforce their own windows; the exact budgets are tuned server-side and signalled through the headers above.
Was this page helpful?

