Rate limits
Rate limiting and CORS for the Partner API are enforced at the edge gateway, in front of the application — not in the API code itself.
Throttling
Section titled “Throttling”When you exceed your allowance the gateway returns 429 Too Many Requests. Build your
client to:
- Respect
Retry-Afterif present, otherwise back off exponentially (e.g. 1s, 2s, 4s… with jitter). - Never hard-loop on a
429— repeated immediate retries make it worse. - Treat throttling as expected under load, not an error to surface to end users.
Allowed origins (CORS)
Section titled “Allowed origins (CORS)”Browser-origin calls are restricted to your brand’s verified domains. Server-to-server integrations (the intended use of the Partner API) are unaffected by CORS.