Skip to main content
Cresora Commerce
Core Concepts

Rate Limiting

Cresora API request limits and how to handle 429 responses gracefully.

Cresora rate-limits API requests per Partner key to protect platform stability.

Limits

The budget is per Partner key, measured over a 60-second sliding window, and depends on the rate-limit tier Cresora Operations assigns to your partner account. You cannot change the tier yourself; new partners start on STANDARD.

TierRequests / minute
STANDARD (default)600
PREMIUM6,000
ENTERPRISENegotiated

There is no separate burst allowance. The window slides continuously, so on STANDARD any 60-second span holds at most 600 requests, however they are spaced — a spike that spends the budget in the first ten seconds leaves nothing for the remaining fifty. Contact Cresora if your integration needs a higher tier.

429 response

When you exceed the budget, Cresora returns a 429 carrying the error code rate_limit_exceeded and a Retry-After header:

HTTP 429 Too Many Requests
Retry-After: 12

The Retry-After header gives the number of seconds to wait before retrying.

Handling rate limits

Implement exponential backoff with jitter:

Node.js
async function requestWithRetry(fn, maxRetries = 3) {
  for (let attempt = 0; attempt <= maxRetries; attempt++) {
    try {
      return await fn();
    } catch (err) {
      if (err.status === 429 && attempt < maxRetries) {
        const retryAfter = parseInt(err.headers?.["retry-after"] ?? "1", 10);
        const jitter = Math.random() * 1000; // 0–1 second jitter
        await new Promise(resolve => setTimeout(resolve, retryAfter * 1000 + jitter));
        continue;
      }
      throw err;
    }
  }
}
Python
import time, random, requests

def request_with_retry(fn, max_retries=3):
    for attempt in range(max_retries + 1):
        resp = fn()
        if resp.status_code == 429 and attempt < max_retries:
            retry_after = int(resp.headers.get("Retry-After", 1))
            jitter = random.random()
            time.sleep(retry_after + jitter)
            continue
        return resp
    return resp
💡Tip

If you consistently hit rate limits, batch operations where possible or distribute load across time. Contact Cresora if your use case requires higher limits.

Rate limit headers

Every response to an authenticated request includes headers so you can track your usage proactively. The one exception is 401: authentication runs ahead of the rate limiter, so a rejected credential is refused before any per-partner budget exists to report.

HeaderValue
X-RateLimit-LimitYour tier's per-minute limit
X-RateLimit-RemainingRequests remaining in the current window
X-RateLimit-ResetUnix timestamp when the window resets