What you get back
A throttled request returns429 Too Many Requests. Identity endpoints tag
the body with the error code identity.too_many_requests.
Sign-in and account creation
Keyed per IP address, so these apply before anyone is authenticated.
Note the asymmetry between requesting a code and submitting one: requesting is
capped at 5/minute because each request sends an email, while submitting is
capped at 10/minute with a longer block, because that endpoint is where a
token would be brute-forced.
Two-factor and phone verification
Keyed per user, and enforced after authentication.The 2FA budget is shared across all three sign-in paths — email, social and wallet. Alternating between them does not give you three separate allowances.
Trading and wallet
Keyed per member.
Order placement is the loosest limit on the API at two per second sustained,
because it is the one endpoint where a legitimate client is genuinely fast.
The relay limit is tighter than it looks because the operator pays the gas for
every relayed transaction — it is a spend limit as much as a rate limit. The
5-per-hour class covers enrolment and one-off setup actions, which no correct
client repeats in a loop.
Market data
Public market-data reads are not currently rate-limited, but they are cached — see theCache-Control table in the API overview.
Polling inside the TTL returns the same bytes and gains you nothing.
Backing off
Retry with exponential backoff and jitter, and treat the block duration — not the measurement window — as your floor.- Add jitter. Without it, every client that failed together retries together, and the retry storm is worse than the original burst.
- Never retry a 429 immediately, even once. On the endpoints with a block, an immediate retry lands inside the block and can extend it.
- Do not retry a
422at all. It is a validation failure; the same body will fail every time. Only429,5xxand network errors are worth retrying.