Every authenticated response includes these headers for the key’s bucket:
Handle a 429
Over a limit, you get429 rate_limited with a Retry-After header in seconds. Wait that long, then retry with the same Idempotency-Key.
Retry-After is 60 seconds or less. For longer waits they raise RateLimitError with retryAfter (Node.js) or retry_after (Python).
Stay under the limits
- Use
limit=100on list endpoints. - Use webhooks or the
GET /invoices?status=...filters instead of polling single invoices. - Spread large email batches over several hours.