Rate limits

Generous by default, since scan stations fire fast, with a few sensitive routes held much tighter.

Global limit

Every route defaults to 600 requests per minute. A busy factory floor with several stations scanning at once sits comfortably under this.

Login and pairing routes

Sign up, staff and retailer login, password reset requests, and swapping a pairing code for a station token are limited far more tightly, to slow down anyone guessing at credentials or codes.

The 429 response

Every response carries your current standing, whether or not you are close to the limit:

Shell
x-ratelimit-limit: 600
x-ratelimit-remaining: 583
x-ratelimit-reset: 42

Once the limit is reached, a request gets 429 instead of running, with a retry-after header giving the number of seconds to wait:

JSON
{
  "statusCode": 429,
  "error": "Too Many Requests",
  "message": "Rate limit exceeded, retry in 1 minute"
}