Rate limits
Per-minute request ceilings that scale with your volume.
Write endpoints are rate limited per minute. Every response carries your current ceiling, so you never have to guess it.
X-RateLimit-Limit- Requests allowed in the current minute
X-RateLimit-Remaining- Requests left in it
X-RateLimit-Tier- Your workspace's tier
Exceeding a limit returns 429 with a Retry-After header in seconds. Wait that long and retry. A 429 means the request was not processed, so retrying is always safe: no charge, payout, or token was created.
Tiers
Limits scale with the workspace's own volume, so integrations do not have to ask for a raise as they grow. The tier is recalculated from approved live charges and payouts over the last 30 days. Sandbox activity does not count toward it.
| Tier | Approved live charges + payouts (30d) | Limit |
|---|---|---|
| new | Under 50 | Base |
| established | 50 or more | 3x base |
| scaled | 500 or more | 8x base |
| high_volume | 5,000 or more | 20x base |
Base limits by endpoint
| Endpoint | Base limit |
|---|---|
| POST /charges | 100 / minute |
| POST /payouts | 30 / minute |
| POST /tokens | 60 / minute |
| POST /three-ds/authenticate | 20 / minute |
A tier change takes up to 15 minutes to apply. If you need a higher ceiling than your tier gives you, contact support rather than retrying into the 429.