# Rate limits

To ensure fair usage and maintain the stability of the API, rate limits are enforced on every request. Rate limits are applied **per API key**. If an API key exceeds these limits, requests may be temporarily blocked or rejected with an error response.

## Request limits

- 10,000 requests per hour, per API key
- Maximum 10 requests per second, per API key (burst limit)


## Payload limits

- Up to 500 rows per request, or
- Up to 10 MB per request (whichever limit is reached first)


## Best practices

To avoid hitting rate limits:

- Implement exponential backoff or retry-after handling when a request is rejected.
- Batch data where possible to reduce the number of requests.
- Monitor your application's request volume and adjust accordingly.


## Idempotent retries

Retrying a request after a timeout or a dropped connection is normal—but retrying a POST that creates a resource or triggers a side effect can otherwise result in duplicates (a duplicate ingestion, a duplicate dataset, a repeated purge).

POST endpoints that create a resource or trigger a side effect accept an optional `Idempotency-Key` header to make retries safe:

```
POST /v2/datasets/{id}/data
Headers:
  Idempotency-Key: "3f29b6a2-1c44-4e7a-9b8a-5d6e2f1c9a3d"

→ First call: processes the request and returns a new result.
→ Retry call (same key): returns the original response without re-processing.
```

- Supply a client-generated unique value in the `Idempotency-Key` header—a UUID is recommended.
- If a request is retried with the same key within 24 hours of the original request, the API returns the original response instead of re-executing the operation.
- A different key (or no key) is always treated as a new request.
- Supported on: account, data source, dataset, and metric creation; dataset ingestion and duplication; and data source and dataset purge.


## Exceeding the limits

If your API key exceeds any of the above limits, the API will return an error indicating that the rate limit has been reached. You can retry your request after the specified cooldown period.