Rate limits
Limits are generous for real integrations; they exist to stop runaway loops. They are counted per Cloudflare location and are approximate, so treat them as a ceiling rather than a quota to spend exactly.
Updated September 26, 2026
Limits
| What | Limit |
|---|---|
| REST API, per API key (per IP address for calls without a key) | 120 requests a minute |
| REST API and MCP together, per workspace | 600 requests a minute |
| REST API and MCP together, per IP address | 600 requests a minute |
| MCP server, per API key or access token | 120 requests a minute |
| OAuth client registration, per IP address | 10 requests a minute |
| OAuth authorize and token, per IP address and endpoint | 60 requests a minute |
When you hit one
The API answers 429 with a Retry-After header (seconds) and the usual error body:
HTTP/1.1 429 Too Many Requests
retry-after: 60
content-type: application/json; charset=utf-8
{
"error": {
"code": "rate_limited",
"message": "Too many requests. Try again in 60 seconds.",
"details": { "retry_after": 60, "limit": 120, "period": 60 }
}
} Wait Retry-After seconds, then carry on. The MCP server answers 429 with a JSON-RPC error instead: code -32029, the same message, and data with code: "rate_limited", retry_after, limit and period.
Staying under
- Subscribe to REST hooks or webhooks instead of polling for new comments.
- When you do poll, once a minute is plenty: pass
sinceso each call returns only what is new. - Ask for up to 100 items per page with
limitrather than many small pages.