---
title: "Rate limits"
description: "Each workspace can make 600 requests a minute. How the limit is counted, which headers show it, and how to handle a 429."
canonical: https://docs.rumoro.dev/rate-limits
markdown: https://docs.rumoro.dev/rate-limits.mdx
---

# Rate limits

Each workspace can make 600 requests a minute. How the limit is counted, which headers show it, and how to handle a 429.

Each workspace can make 600 requests a minute, counted over the last 60 seconds. All its API keys and OAuth tokens share this, and [MCP](/mcp) requests count too. The dashboard doesn't.

Counted responses have three headers.

| Header | Meaning |
| --- | --- |
| `X-RateLimit-Limit` | Requests allowed per minute (600) |
| `X-RateLimit-Remaining` | Requests left right now |
| `X-RateLimit-Reset` | When the next request frees up, in Unix seconds |

Over the limit you get `429 rate_limited` with a `Retry-After` header and `retryAfterSeconds` in the body. Nothing is changed and the request isn't counted.

```json
{
  "error": {
    "code": "rate_limited",
    "message": "This workspace made more than 600 requests in a minute. Wait 8 seconds and send the same request again; nothing was applied.",
    "requestId": "9e4c2a1f-6d07-4b38-a5c2-0f81d3e7b264",
    "retryAfterSeconds": 8
  }
}
```

## Endpoint limits

| Endpoint | Limit per workspace |
| --- | --- |
| Mention exports (CSV and JSON together) | 6 a minute, up to 10,000 rows |
| People export | 6 a minute, up to 5,000 rows |
| Usage breakdown | 30 a minute, dashboard not counted |
| Keyword health | 30 a minute, dashboard counted |
| Keyword health with `ai=true` | 20 model calls an hour |
| Top-up checkouts | 5 a minute |
| Invitations | 50 a day |
| Test emails | 5 per channel an hour |

Most return `429 rate_limited` with the same wait fields. Two don't. Over the `ai=true` limit, the health report still returns 200, with AI status `rate_limited` and no model context. Over the test email limit, the test returns 200 and the email shows `email_test_rate_limited`.

## Handling a 429

Wait `Retry-After` seconds, then send the same request again. The [SDKs](/sdks) and [CLI](/cli) don't retry for you. Spreading a big job out works better than retrying. 600 a minute is ten a second, enough to page through a busy workspace.

The limit is per workspace, so two scripts with different keys share it. Dashboard use doesn't count, so a busy script can't lock you out of the app.
