Skip to content

Rate limiting

How the BoxHero API limits request rates per team and how to back off and retry.

To keep the service stable for everyone, the BoxHero API limits how many requests a team can send.

All API tokens that belong to the same team share the same limits. Issuing more tokens in one team does not raise the limit.

The API responds with 429 and an error envelope whose type is /errors/too-many-requests. The response headers tell you when you can try again:

HeaderDescription
Retry-AfterSeconds to wait before retrying
RateLimit, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-ResetThe current limit, the requests left, and when the limit resets

Back off and retry after the time in Retry-After. If you send many requests in a row, spread them out instead of sending them all at once.