Skip to main content

Rate limits

Enforced limits​

SurfaceLimitWhen exceeded
Auth (/auth/v1/oauth2/*)60 requests / minute per IP429
Public (/api/v1/public/*)120 requests / minute per IP429
{ "success": false, "code": 429, "data": null, "error": "Too Many Requests", "message": "too many request" }

Authenticated REST (/api/v1/*) and the WebSocket have no fixed limit today. Each broker runs its own deployment and may add limits, so handle 429 everywhere: back off exponentially with jitter, then retry.

Fair use​

  • Don't log in per request. Reuse the access token and refresh it. Logging in repeatedly also burns through your 5 sessions.
  • Stream, don't poll. Prices, P/L, balance, and order/position changes are all pushed over the WebSocket. Polling GET /accounts/me or /positions/accounts/me in a loop is the most common cause of excess load.
  • Cache reference data. Load symbols once at startup.
  • Page through history. Use page/limit and from/to instead of pulling everything on every run.