Docs / Platform

Rate limits & usage

Current beta burst protection and retry behavior.

Each beta account can make 500,000 authenticated API requests per UTC calendar month, shared across all of its keys. The account portal shows current-month usage and the reset date. At the limit, API requests return HTTP 429 with code quota_exceeded; Retry-After gives the seconds until the next UTC month, and X-Quota-Limit, X-Quota-Used, and X-Quota-Reset report the limit, usage, and reset time (Unix seconds). The monthly count is enforced atomically per account, including when requests arrive at the same time.

The API also applies a burst limit of 600 requests per 60 seconds per key. Logo, search, and company requests share that key’s burst limiter. It is configured beta protection, not a throughput or SLA guarantee; distributed enforcement should not be treated as an exact global burst count. On HTTP 429, read Retry-After, pause until the stated time, and retry only if appropriate. Cache images, debounce search, and do not rotate keys to bypass limits.

Every request that passes parameter validation, authentication, the burst check, and the monthly quota admission is counted before lookup or image delivery. This includes authenticated requests that return not_found and conditional image responses; malformed requests, failed authentication, burst- or quota-rejected requests, disabled accounts, account-management routes, and direct static image URLs are not counted. Daily usage is recorded by account and UTC date for logo, company, and search requests. The account portal displays the monthly total and daily counts for the latest 30 days.

Static R2 URLs have separate host-level limits and do not use API-key or account quota accounting. Contact us before a large launch.

Need a hand? Get help · Technical content reviewed October 2, 2026