Rate limits
Enforced limits
| Surface | Limit | When exceeded |
|---|---|---|
Auth (/auth/v1/oauth2/*) | 60 requests / minute per IP | 429 |
Public (/api/v1/public/*) | 120 requests / minute per IP | 429 |
{ "success": false, "code": 429, "data": null, "error": "Too Many Requests", "message": "too many request" }
Authenticated REST (/api/v1/*) and the WebSocket have no fixed limit today.
Each broker runs its own deployment and may add limits, so handle 429
everywhere: back off exponentially with jitter, then retry.
Fair use
- Don't log in per request. Reuse the access token and refresh it. Logging in repeatedly also burns through your 5 sessions.
- Stream, don't poll. Prices, P/L, balance, and order/position changes are
all pushed over the WebSocket. Polling
GET /accounts/meor/positions/accounts/mein a loop is the most common cause of excess load. - Cache reference data. Load symbols once at startup.
- Page through history. Use
page/limitandfrom/toinstead of pulling everything on every run.