Skip to content

Rate Limiting ​

SkyState has two request controls:

  • Monthly API-request metering on authenticated state route groups. API-key and end-user requests are metered; developer bearer requests are exempt.
  • Standard HTTP rate limiting on API route groups to protect service availability.

Project, account, and billing management endpoints stay available when the monthly API-request quota is over limit. Monthly limits vary by subscription tier.

TierMonthly requests
free500,000
hobby2,000,000
pro10,000,000

Requests above a tier limit keep being served through a short grace zone before they are blocked. The block threshold, the grace-zone policy, and the monthly counter reset are defined under Metering - Enforcement Thresholds.

Retry-After ​

Three responses carry a Retry-After header telling clients when to retry:

  • A request blocked by the monthly API-request quota returns 402 with Retry-After set to the seconds until the monthly counter resets and a non-null resetAt ISO 8601 timestamp in the body. This is the only 402 that carries Retry-After: resource-limit 402s (projects, API keys, end users) send no Retry-After and resetAt: null; see Quota responses (402).
  • Standard rate limiting is always on, in every environment, and allows 120 requests per credential (API key or bearer token) in a fixed one-minute window; a rejected request returns 429 with Retry-After: 60. Unauthenticated (credential-less) requests are not rate limited.
  • A temporarily unavailable service returns 503 with Retry-After: 5. This is a temporary service fault rather than a request control: no limit was exceeded, and the request can be retried unchanged. See Errors.

In every case, Retry-After is the number of seconds a direct HTTP caller should wait before sending the request again.

Quota responses (402) ​

Every 402, whether for the monthly API-request quota or a tier resource limit, returns a quota body. It does not use the {"error","message"} envelope described on Errors; client code should branch on code.

FieldMeaning
codeOne of QUOTA_API_REQUESTS, QUOTA_PROJECTS, QUOTA_API_KEYS, QUOTA_END_USERS. Stable and machine-readable
messageHuman-readable explanation, not stable across releases
resourceOne of api_requests, projects, api_keys, end_users, matching code
currentThe caller's current usage of resource when the limit was checked
limitThe tier's limit that current reached or exceeded
resetAtISO 8601 timestamp of the next reset for QUOTA_API_REQUESTS only; null for the three resource codes, which free up when the caller deletes something rather than on a schedule

Only the QUOTA_API_REQUESTS response also carries the Retry-After header described above.

Caching ​

The anonymous public-state endpoint used by SDK and browser clients sets Cache-Control headers. Production public-state responses are cached for 15 minutes; development and staging responses use a 10-second cache window.

Which requests count toward the monthly meter is defined under Billing - Metering; anonymous public-state reads are not metered.

For more detail on how metering works, see Billing - Metering.