Rate limits
A few requests that send emails or codes are limited, to stop abuse:
| Request | Limit, by default |
|---|---|
POST /v1/public/auth/sign-in-link |
5 links an hour for one email, 20 an hour from one address |
POST /v1/public/auth/passkeys/sign-in/options |
20 an hour from one address |
POST /v1/public/bookings/{ref}/contact-changes |
5 an hour for one booking |
Past a limit the answer is 429 RateLimited, with retry_after_seconds:
wait that long before trying again, and tell the traveller when they can.
“One address” is the traveller’s IP address. Since your server makes the
request, pass the traveller’s address on in X-Forwarded-For, first in
the list; otherwise every traveller on your site shares your server’s
limit.
Coming: limits per key
Section titled “Coming: limits per key”Limits on every request, per key, are coming with
issue #530, answered
with 429 and a Retry-After header. The plan is 600 requests a minute
for a website key and 120 for a secret key, by default.
Be ready now
Section titled “Be ready now”- Cache catalog reads (trips, pages, menus) on your server for a short time; never cache quotes, holds or bookings.
- On a
429, wait as long as the answer says, then try again; don’t retry in a tight loop. - Spread batch jobs, such as rebuilding a sitemap, over time.