# Rate limits

> border.bot API rate limits per API key and per IP address, the RateLimit-Policy and Retry-After headers, and how to back off.

Source: https://border.bot/docs/rate-limits
Last updated: 2026-10-09

> Documentation index: https://border.bot/llms.txt. Every page is Markdown at its URL + `.md`.


## Limits

| Who                                                               | Limit                                       |
| ----------------------------------------------------------------- | ------------------------------------------- |
| Calls with an API key                                             | 120 requests per 60 seconds, per key        |
| Public endpoints (no key)                                         | 120 requests per 60 seconds, per IP address |
| OAuth endpoints (`/authorize`, `/oauth/token`, `/oauth/register`) | 30 requests per 60 seconds, per IP address  |

Batch endpoints count as one request, so use `/classify/batch`, `/origin/batch` or a [bulk run](https://border.bot/docs/api/start-bulk-run) for volume.

## Headers

Responses follow the IETF HTTPAPI RateLimit header fields:

```http
RateLimit-Policy: "key";q=120;w=60
```

`q` is the number of requests allowed in a window of `w` seconds. When you go over it, the response is `429 rate_limited` with:

```http
RateLimit: "key";r=0;t=60
Retry-After: 60
```

`r` is what's left (zero) and `t` the seconds until you can send again. Wait at least `Retry-After` seconds before retrying, then send with the same `Idempotency-Key` so a retried billable call is never charged twice. Requests refused for rate limiting are never charged.
