Platform limits
Request limits for builders and subscribers, and how to retry.
Request limits for builders and subscribers, and how to retry.
Farther Shore limits bursts of expensive actions so that shared capacity remains available. Reading dashboards and checking build status use separate request budgets. Your plan can also limit how many products, environments, API keys or team members you can have.
General request budgets also apply: 100 requests per minute per address for anonymous requests, 300 per minute per address for failed authentication, and 300 per minute per verified user across the ordinary authenticated API. Anonymous requests to management and agent APIs have a separate 60 per minute address budget. The tightest applicable budget wins.
These are the default action limits. Related actions in the same row share one budget. An account budget follows your verified identity or your builder organization; changing credentials, products or environments does not create a new allowance.
| Action | Account limit per minute | Address limit per minute |
|---|---|---|
| Look up, approve or deny CLI sign-in | 60 per user | 120 |
| Start a CLI sign-in | — | 10 |
| Poll or acknowledge CLI sign-in | — | 240 |
| Exchange or revoke a CLI session; list its organizations | — | 60 |
| Exchange a preview sign-in handoff | — | 60 |
| Create a product | 10 per builder organization | 120 |
| Create or refresh a preview environment | 10 per builder organization | 120 |
| Create an organization | 10 per user | 120 |
| Create preview sign-in handoffs or renew local preview sign-in | 60 per user or delegated organization | 120 |
| Change a product variable | 10 per builder organization | 120 |
| Create or rotate builder automation or preview credentials | 20 per builder organization | 120 |
| Create or rotate subscriber API keys | 20 per user | 120 |
| Onboard or create checkout, balance top-up or billing-management sessions | 10 per user | 120 |
| Send builder or subscriber team invitations | 20 per user | 120 |
| Submit access requests | 10 per user | 120 |
| Send a webhook test | 10 per user or delegated organization | 120 |
Account and address budgets both apply; people using the same address can share an address allowance. Operational adjustments may change these defaults.
When you reach a limit, the API returns HTTP 429 with error code
RATE_LIMIT_EXCEEDED and a Retry-After header in seconds. Wait at least that
long before retrying. Avoid retrying in a tight loop. CLI sign-in polling should
also respect the interval returned when sign-in starts.
Hosted sign-up and sign-in can have additional identity-service protections. Product-defined usage and resource limits are separate from these platform limits; consult the product's plan for those allowances.