Rate limits
Learn how many requests you can send to the Onna API and how to recover when you exceed a limit.
Limits
Unless an endpoint lists its own limit below, requests share a budget of 600 requests per minute for each access
token. Requests without a token aren't rate limited; they're rejected with 401. Legal Hold (/legalhold/*)
endpoints are not covered by these limits.
POST /oauth/token has its own limit of 30 requests per minute for each client_id. Failed attempts count toward it.
Reuse an access token until it expires instead of requesting a new one for each call.
POST /search has its own limit of 300 requests per minute for each access token.
Rate-limited responses
When you exceed a limit, the API responds with 429 Too Many Requests and a Retry-After header that gives
the number of seconds to wait before calling again:
HTTP/1.1 429 Too Many Requests
Retry-After: 17
Content-Type: application/json
X-Correlation-ID: 0b6c2a53-5f1e-4a8e-9a57-3c8a2f6d1e44
{
"code": "00429_too_many_requests",
"id": "0b6c2a53-5f1e-4a8e-9a57-3c8a2f6d1e44",
"title": "Too Many Requests",
"detail": "Too many requests: wait the number of seconds given in the Retry-After header, then retry",
"links": {"about": "https://dev.onna.com/fundamentals/response-codes#4XX"},
"source": null
}
The id in an error body matches the X-Correlation-ID response header. Quote it when you contact support about
a failed request.
Best practices
Wait for the Retry-After delay before retrying, and spread bulk work over time instead of sending it in bursts.
For the full list of status codes, see Response codes.