Rate Limiting
Cresora API request limits and how to handle 429 responses gracefully.
Cresora rate-limits API requests per Partner key to protect platform stability.
Limits
The budget is per Partner key, measured over a 60-second sliding window, and depends on the rate-limit tier Cresora Operations assigns to your partner account. You cannot change the tier yourself; new partners start on STANDARD.
| Tier | Requests / minute |
|---|---|
STANDARD (default) | 600 |
PREMIUM | 6,000 |
ENTERPRISE | Negotiated |
There is no separate burst allowance. The window slides continuously, so on STANDARD any 60-second span holds at most 600 requests, however they are spaced — a spike that spends the budget in the first ten seconds leaves nothing for the remaining fifty. Contact Cresora if your integration needs a higher tier.
429 response
When you exceed the budget, Cresora returns a 429 carrying the error code rate_limit_exceeded and a Retry-After header:
HTTP 429 Too Many Requests
Retry-After: 12The Retry-After header gives the number of seconds to wait before retrying.
Handling rate limits
Implement exponential backoff with jitter:
async function requestWithRetry(fn, maxRetries = 3) {
for (let attempt = 0; attempt <= maxRetries; attempt++) {
try {
return await fn();
} catch (err) {
if (err.status === 429 && attempt < maxRetries) {
const retryAfter = parseInt(err.headers?.["retry-after"] ?? "1", 10);
const jitter = Math.random() * 1000; // 0–1 second jitter
await new Promise(resolve => setTimeout(resolve, retryAfter * 1000 + jitter));
continue;
}
throw err;
}
}
}import time, random, requests
def request_with_retry(fn, max_retries=3):
for attempt in range(max_retries + 1):
resp = fn()
if resp.status_code == 429 and attempt < max_retries:
retry_after = int(resp.headers.get("Retry-After", 1))
jitter = random.random()
time.sleep(retry_after + jitter)
continue
return resp
return respIf you consistently hit rate limits, batch operations where possible or distribute load across time. Contact Cresora if your use case requires higher limits.
Rate limit headers
Every response to an authenticated request includes headers so you can track your usage proactively. The one exception is 401: authentication runs ahead of the rate limiter, so a rejected credential is refused before any per-partner budget exists to report.
| Header | Value |
|---|---|
X-RateLimit-Limit | Your tier's per-minute limit |
X-RateLimit-Remaining | Requests remaining in the current window |
X-RateLimit-Reset | Unix timestamp when the window resets |