# Rate limits

> The per-minute request limit per token, the 429 response, and the Retry-After header.

The REST API, MCP, and SCIM endpoints accept **300 requests per minute per token**. The counter resets at the start of each calendar minute. When you exceed the limit, the response is `429`, and the `Retry-After` header gives the number of seconds until the next minute begins:

```http
HTTP/1.1 429 Too Many Requests
Retry-After: 9
Content-Type: application/json
```

```json
{ "ok": false, "error": "rate_limited", "message": "Dakikalık istek sınırı aşıldı (300 istek / dk). Retry-After saniye sonra yeniden deneyin." }
```

## Other limits

| What | Limit |
|---|---|
| Mobile sign-in | 60-second lock after 5 failed attempts from the same IP (`429 locked`) |
| OAuth client registration | 60 registrations per hour per IP (`429 slow_down`) |
| OAuth token endpoint | 600 requests per hour per IP (`429 slow_down`) |
| Ask (AI) | 40 questions per hour per user (`429 limit`) |
| Inbound webhooks | 120 requests per hour per connection (Segment: 3,000; data sync, Aircall, RingCentral, Stripe: 600) |
| List endpoints | Up to 100 rows per page; people, fair lead, and thread lists return at most 300 / 100 rows |
| Sending email | Up to 10 recipients per message (to + cc); bulk sending is available only on the web |

An installation admin can change the per-minute limit on the server with the `API_RATE_PER_MIN` environment variable.

## Recommended practices

- When you receive a `429`, wait for the `Retry-After` interval and then retry; retrying without waiting keeps filling the counter.
- Instead of bulk reads, paginate lists with `per=100` and fetch changes with `sort=update`.
- Instead of constantly polling for events, receive notifications through [webhooks](/guides/webhooks).
- To import a large number of records, use the [data sync webhook](/guides/inbound#sync) (500 rows per request) instead of individual `POST` requests.