Skip to main content
Limitguard enforces rate limits to ensure fair access and API stability. They are abuse limits, not a quota you buy: every call is paid for, either per call with x402 or from an API key’s prepaid balance. A key’s tier (bought as a prepaid top-up) only selects its burst limits.

Rate Limits by Tier

Both windows are rolling: the per-minute limit over the last 60 seconds, the daily limit over the last 24 hours. Nothing resets on a calendar boundary. Entity checks also have a per-entity limit per caller, against enumeration.

Middleware Execution Order

Rate limiting runs early in the stack — before sandbox bypass and x402 payment verification:
This means a sandbox request that exceeds 10 req/min is rejected at the Rate Limit step, before the sandbox middleware ever runs.

HTTP 429 — Rate Limit Exceeded

When a rate limit is hit, the API returns HTTP 429 Too Many Requests with a Retry-After header and a JSON error body.

Response Headers

Example: Sandbox Limit Exceeded

Example: Free Tier Daily Limit Reached

Always read the Retry-After header rather than hard-coding a wait time: it is 60 seconds for a per-minute limit and 3600 seconds for the rolling 24-hour limit.

x402 Payers Have No Daily Cap

Callers paying per call with x402 have no daily request cap: each successful payment authorizes exactly one API call, so cost is the throttle. A verified payer is still limited to 60 requests per minute, and entity checks keep their per-entity limit.
If you are building an AI agent that may need to make bursts of requests, x402 is the right choice. You pay per call and have no daily cap. See the x402 Protocol guide for implementation details.

Cost-Based Throttling vs. Count-Based Throttling

Best Practices

1. Always Respect Retry-After

Never retry before Retry-After seconds have elapsed. Retrying too early counts against the same window and triggers the same 429 immediately.

2. Implement Exponential Backoff

For transient errors (5xx) use exponential backoff. For 429 specifically, always use the exact Retry-After value — do not apply additional multipliers on top of it.

3. Monitor X-RateLimit-Remaining

Poll X-RateLimit-Remaining on each response to detect approaching limits before they are hit. Shed load or switch to x402 before reaching zero.

4. Never Load Test Production

Use a sandbox key (lg_sandbox_...) for load testing. The 10 req/min sandbox limit exists to prevent accidental load on real data sources.

Code Examples: Handling 429 with Retry Logic

Upgrading Your Tier

If you are consistently hitting rate limits on a subscription key, you have two options:

Upgrade Your Plan

Top up to Indie, Starter, Growth, or Pro for higher per-minute and daily limits.

Switch to x402

Pay per call with USDC. No daily cap; 60 requests per minute per payer.
To create a key, then upgrade it:
Available tiers: free, sandbox, indie, starter, growth, pro. See Authentication for top-up prices and limits.