Reference

Rate limits

Limits protect the platform and your account. They are generous for normal integrations; batches are the right tool for high volume.

Limits#

ScopeLimit
Per API key (all endpoints)600 requests / minute
Authentication routes, per IP120 requests / minute
Payout creation, per organization300 requests / minute

Need to pay more people at once? Use a payout batch — one request can carry up to 10,000 payouts.

Headers#

HeaderMeaning
x-ratelimit-limitRequests allowed in the current window.
x-ratelimit-remainingRequests left in the current window.
x-ratelimit-resetSeconds until the window resets.
retry-afterOn 429 responses: seconds to wait before retrying.
429 Too Many Requests
{
  "error": {
    "type": "rate_limit_error",
    "code": "rate_limited",
    "message": "Rate limit exceeded, retry in 12 seconds",
    "request_id": "req_41c0e7d2b9aa"
  }
}

Retrying#

  • Wait for retry-after, then retry with exponential backoff and jitter.
  • Always retry writes with the same idempotency key — a retried payout is never paid twice.
  • Spread scheduled jobs instead of firing everything at the top of the minute.

Built into the SDK

@muny/sdk automatically retries network errors, 429 and 5xx responses with backoff (2 retries by default), honouring retry-after. Writes are only retried when they carry an idempotency key.