Skip to main content

Rate limits

Learn how many requests you can send to the Onna API and how to recover when you exceed a limit.


Limits​

Unless an endpoint lists its own limit below, requests share a budget of 600 requests per minute for each access token. Requests without a token aren't rate limited; they're rejected with 401. Legal Hold (/legalhold/*) endpoints are not covered by these limits.

POST /oauth/token has its own limit of 30 requests per minute for each client_id. Failed attempts count toward it. Reuse an access token until it expires instead of requesting a new one for each call.

POST /search has its own limit of 300 requests per minute for each access token.

Rate-limited responses​

When you exceed a limit, the API responds with 429 Too Many Requests and a Retry-After header that gives the number of seconds to wait before calling again:

HTTP/1.1 429 Too Many Requests
Retry-After: 17
Content-Type: application/json
X-Correlation-ID: 0b6c2a53-5f1e-4a8e-9a57-3c8a2f6d1e44

{
"code": "00429_too_many_requests",
"id": "0b6c2a53-5f1e-4a8e-9a57-3c8a2f6d1e44",
"title": "Too Many Requests",
"detail": "Too many requests: wait the number of seconds given in the Retry-After header, then retry",
"links": {"about": "https://dev.onna.com/fundamentals/response-codes#4XX"},
"source": null
}

The id in an error body matches the X-Correlation-ID response header. Quote it when you contact support about a failed request.

Best practices​

Wait for the Retry-After delay before retrying, and spread bulk work over time instead of sending it in bursts.

For the full list of status codes, see Response codes.