Skip to content

Rate limits

A few requests that send emails or codes are limited, to stop abuse:

Request Limit, by default
POST /v1/public/auth/sign-in-link 5 links an hour for one email, 20 an hour from one address
POST /v1/public/auth/passkeys/sign-in/options 20 an hour from one address
POST /v1/public/bookings/{ref}/contact-changes 5 an hour for one booking

Past a limit the answer is 429 RateLimited, with retry_after_seconds: wait that long before trying again, and tell the traveller when they can.

“One address” is the traveller’s IP address. Since your server makes the request, pass the traveller’s address on in X-Forwarded-For, first in the list; otherwise every traveller on your site shares your server’s limit.

Limits on every request, per key, are coming with issue #530, answered with 429 and a Retry-After header. The plan is 600 requests a minute for a website key and 120 for a secret key, by default.

  • Cache catalog reads (trips, pages, menus) on your server for a short time; never cache quotes, holds or bookings.
  • On a 429, wait as long as the answer says, then try again; don’t retry in a tight loop.
  • Spread batch jobs, such as rebuilding a sitemap, over time.