Rate Limiting
SkyState has two request controls:
- Monthly API-request metering on authenticated state route groups. API-key and end-user requests are metered; developer bearer requests are exempt.
- Standard HTTP rate limiting on API route groups to protect service availability.
Project, account, and billing management endpoints stay available when the monthly API-request quota is over limit. Monthly limits vary by subscription tier.
| Tier | Monthly requests |
|---|---|
free | 500,000 |
hobby | 2,000,000 |
pro | 10,000,000 |
Requests above a tier limit keep being served through a short grace zone before they are blocked. The block threshold, the grace-zone policy, and the monthly counter reset are defined under Metering - Enforcement Thresholds.
Retry-After
Three responses carry a Retry-After header telling clients when to retry:
- A request blocked by the monthly API-request quota returns
402withRetry-Afterset to the seconds until the monthly counter resets and a non-nullresetAtISO 8601 timestamp in the body. This is the only402that carriesRetry-After: resource-limit402s (projects, API keys, end users) send noRetry-AfterandresetAt: null; see Quota responses (402). - Standard rate limiting is always on, in every environment, and allows 120 requests per credential (API key or bearer token) in a fixed one-minute window; a rejected request returns
429withRetry-After: 60. Unauthenticated (credential-less) requests are not rate limited. - A temporarily unavailable service returns
503withRetry-After: 5. This is a temporary service fault rather than a request control: no limit was exceeded, and the request can be retried unchanged. See Errors.
In every case, Retry-After is the number of seconds a direct HTTP caller should wait before sending the request again.
Quota responses (402)
Every 402, whether for the monthly API-request quota or a tier resource limit, returns a quota body. It does not use the {"error","message"} envelope described on Errors; client code should branch on code.
| Field | Meaning |
|---|---|
code | One of QUOTA_API_REQUESTS, QUOTA_PROJECTS, QUOTA_API_KEYS, QUOTA_END_USERS. Stable and machine-readable |
message | Human-readable explanation, not stable across releases |
resource | One of api_requests, projects, api_keys, end_users, matching code |
current | The caller's current usage of resource when the limit was checked |
limit | The tier's limit that current reached or exceeded |
resetAt | ISO 8601 timestamp of the next reset for QUOTA_API_REQUESTS only; null for the three resource codes, which free up when the caller deletes something rather than on a schedule |
Only the QUOTA_API_REQUESTS response also carries the Retry-After header described above.
Caching
The anonymous public-state endpoint used by SDK and browser clients sets Cache-Control headers. Production public-state responses are cached for 15 minutes; development and staging responses use a 10-second cache window.
Which requests count toward the monthly meter is defined under Billing - Metering; anonymous public-state reads are not metered.
For more detail on how metering works, see Billing - Metering.