Skip to content

Rate limits

Rate limiting and CORS for the Partner API are enforced at the edge gateway, in front of the application — not in the API code itself.

When you exceed your allowance the gateway returns 429 Too Many Requests. Build your client to:

  • Respect Retry-After if present, otherwise back off exponentially (e.g. 1s, 2s, 4s… with jitter).
  • Never hard-loop on a 429 — repeated immediate retries make it worse.
  • Treat throttling as expected under load, not an error to surface to end users.

Browser-origin calls are restricted to your brand’s verified domains. Server-to-server integrations (the intended use of the Partner API) are unaffected by CORS.