Skip to main content

Rate Limiting

Three limits apply, innermost first:

ScopeLimit
Per OAuth client120 requests per minute
Whole application300 requests per minute per caller
Edge (per IP)50 requests per second, bursts of 100

When a limit is exceeded the API answers:

HTTP/1.1 429 Too Many Requests
Retry-After: 60
Content-Type: application/json

{"error": "RateLimited", "message": "Too many requests. Try again in a minute."}

There are no X-RateLimit-* headers and no per-plan tiers: back off for the Retry-After period and retry. Transactions are read from MagniFinance's synced store, so polling GET /transactions does not touch the bank and is limited only by the numbers above.