Rate limits and best practices
| Access | Identity | Quota | Window resets | Availability |
|---|---|---|---|---|
| Anonymous | IP address | 60 requests / hour | Top of each UTC hour | Default, no signup |
| Free beta | API key | 10,000 requests / day | UTC midnight | Existing keys only, signup is paused |
| Key management | Signed-in account | 30 requests / minute | Top of each UTC minute | Same-origin only |
The window is fixed, not rolling. Sixty anonymous requests at 10:59 UTC and sixty more at 11:01 UTC are both inside quota, and a burst that exhausts the hour at 10:05 UTC waits until 11:00 UTC. Budget against the window rather than against an average rate.
Quota state comes back on every successful response in the usage object as requests_used and requests_remaining.
What happens at the limit
The request is rejected with 429 before any data is read, and the rejected request is not counted against the window. The response carries a Retry-After header in seconds and an error body:
{
"success": false,
"error": {
"code": "rate_limit_exceeded",
"message": "Request quota exceeded. Retry after 2117 seconds."
},
"usage": { "requests_used": 60, "requests_remaining": 0 }
}
Wait at least Retry-After seconds before retrying. Because the window is fixed, Retry-After is the time left until it rolls over, so it can be most of an hour on the anonymous tier. Do not retry in a tight loop against it.
Cache intentionally
The API publishes meta.cached_at and meta.next_update. Keep the last successful payload until next_update instead of polling in a tight loop. GEX, sector rotation, and options flow update on a 25-second cache; slower official datasets such as the VIX settlement curve use longer windows.
Handle failure without hiding it
- Branch on HTTP status before reading
data. - Back off exponentially for
429and transient5xxresponses. - Add jitter when many workers refresh the same resource.
- Never replace unavailable real market data with simulated values in production.
- Keep the previous timestamp visible when displaying stale data.
Protect keys
Use X-API-Key in server-side code. Do not commit keys, embed them in public JavaScript, or put them in query strings where reverse proxies may log them. Rotate a key immediately if it appears in a repository or client bundle.
CORS
Public read endpoints allow cross-origin GET requests. API-key management is same-origin only and also requires the signed-in account token.