Rate limits
Per key, per minute, from your plan.
Limits are counted per key, per minute. The ceiling comes from your plan,
and GET /account reports it as rate_limit.
Every response carries the current state:
| Header | Meaning |
|---|---|
X-RateLimit-Limit | Requests you may make this minute |
X-RateLimit-Remaining | Requests left in the current window |
X-RateLimit-Reset | Unix seconds at which the window resets |
Retry-After | Seconds to wait — present on 429 |
Going over answers 429 with rate_limit_exceeded. Back off for Retry-After
seconds and retry; the request was not processed.
Reading these from a browser
All of the above, plus X-Request-Id and Idempotent-Replay, are listed in the
API's CORS exposed_headers. Without that list a browser can read only the
seven headers CORS allows by default, and fetch would return null for these
even though they are on the response.
Spreading load
Batching beats parallelism: POST /messages takes up to 100 recipients and
POST /messages/batch takes up to 500 independent messages, each one call
against your limit.