API v1 · Operations

Rate limits and best practices

AccessIdentityQuotaWindow resetsAvailability
AnonymousIP address60 requests / hourTop of each UTC hourDefault, no signup
Free betaAPI key10,000 requests / dayUTC midnightExisting keys only, signup is paused
Key managementSigned-in account30 requests / minuteTop of each UTC minuteSame-origin only

The window is fixed, not rolling. Sixty anonymous requests at 10:59 UTC and sixty more at 11:01 UTC are both inside quota, and a burst that exhausts the hour at 10:05 UTC waits until 11:00 UTC. Budget against the window rather than against an average rate.

Quota state comes back on every successful response in the usage object as requests_used and requests_remaining.

What happens at the limit

The request is rejected with 429 before any data is read, and the rejected request is not counted against the window. The response carries a Retry-After header in seconds and an error body:

{
  "success": false,
  "error": {
    "code": "rate_limit_exceeded",
    "message": "Request quota exceeded. Retry after 2117 seconds."
  },
  "usage": { "requests_used": 60, "requests_remaining": 0 }
}

Wait at least Retry-After seconds before retrying. Because the window is fixed, Retry-After is the time left until it rolls over, so it can be most of an hour on the anonymous tier. Do not retry in a tight loop against it.

Cache intentionally

The API publishes meta.cached_at and meta.next_update. Keep the last successful payload until next_update instead of polling in a tight loop. GEX, sector rotation, and options flow update on a 25-second cache; slower official datasets such as the VIX settlement curve use longer windows.

Handle failure without hiding it

  • Branch on HTTP status before reading data.
  • Back off exponentially for 429 and transient 5xx responses.
  • Add jitter when many workers refresh the same resource.
  • Never replace unavailable real market data with simulated values in production.
  • Keep the previous timestamp visible when displaying stale data.

Protect keys

Use X-API-Key in server-side code. Do not commit keys, embed them in public JavaScript, or put them in query strings where reverse proxies may log them. Rotate a key immediately if it appears in a repository or client bundle.

CORS

Public read endpoints allow cross-origin GET requests. API-key management is same-origin only and also requires the signed-in account token.