Rate Limiting

Rate limiting is a strategy to manage API usage, ensuring system stability and consistent user experience by imposing limits on the number of API calls.

Global Rate Limit

In addition to the module-specific limits below, every endpoint enforces a flat limit of 200 requests per 10 seconds per user, applied across all endpoints. This limit exists to prevent excessive request rates and applies regardless of which module-specific limit also applies to a given endpoint.

API Module Rate Limits

The table below describes module specific rate limits.

If not specified, the "All others" rate limit is applied.

EndpointHourly User LimitHourly Database Limit
POST /api/v2/stop-analytics/stop-events5 calls20 calls
POST /api/v2/origin-destination/matrix5 calls20 calls
POST /api/v2/rtm/vdt5 calls20 calls
POST /api/v2/stop-analytics/rda30 calls60 calls
POST /api/v2/origin-destination/route30 calls60 calls
POST /api/v2/origin-destination/segment5 calls20 calls
POST /api/v2/traffic/speed-per-segment60 calls120 calls
POST /api/v2/zones/by-ids30 calls60 calls
POST /api/v2/rtm/demand-generation30 calls60 calls
POST /api/v2/rtm/observed-counts30 calls60 calls
POST /api/v2/expansion-factors/analysis50 calls1000 calls
All others400 calls20,000 calls

Rate Limit Response Headers

When a request is rate limited, the API returns 429 Too Many Requests along with headers describing the current limit state:

HeaderDescription
retry-afterNumber of seconds to wait before retrying. Honour this header when deciding when to retry.
ratelimit-remainingNumber of calls remaining in the current window at the time of this response.
ratelimit-resetNumber of seconds until the current rate limit window resets.
Important:

retry-after is the authoritative signal for when to retry. ratelimit-remaining can appear inconsistent with the enforced limit on a 429 response; do not rely on it to determine whether you are currently rate limited.