Developer

Rate limits & errors

One error shape, named codes, and limits per credential.

Limits

KindLimitKeyed by
Reads (GET)100 per minutethe credential (key or OAuth client)
Writes (POST / PATCH / DELETE)30 per minutethe credential
Token endpoint10 per 15 minutesIP

Responses carry RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset. On 429 rate_limit_exceeded, wait for the reset — do not hammer.

Errors

Every error, from any endpoint, is:

json
{ "error": "<code>", "error_description": "<what to do about it>", "details": [ { "field": "…", "message": "…" } ] }
HTTPerrorMeaning
400bad_requestMalformed request (e.g. no JSON object body)
400validation_errorA field is missing or wrong; every offending field is named in `details`
401unauthorizedNo bearer credential
401invalid_tokenCredential unknown, expired or revoked; or its user no longer exists
403insufficient_scopeThe credential was never granted this feature
403insufficient_permissionsGranted the feature but not this verb — or the bound user no longer holds it
404not_foundNot in your business (ids from other businesses are indistinguishable from missing ones)
409conflictAlready exists (e.g. a party with that email)
429rate_limit_exceededSlow down
5xxserver_errorOurs. Retry with backoff; the response carries a request id — quote it to support.
ℹ️A bad id is never a 5xx

If you can make the API answer 500 by changing an id or a field, that is a bug on our side — report it.