Rate Limiting
Three limits apply, innermost first:
| Scope | Limit |
|---|---|
| Per OAuth client | 120 requests per minute |
| Whole application | 300 requests per minute per caller |
| Edge (per IP) | 50 requests per second, bursts of 100 |
When a limit is exceeded the API answers:
HTTP/1.1 429 Too Many Requests
Retry-After: 60
Content-Type: application/json
{"error": "RateLimited", "message": "Too many requests. Try again in a minute."}
There are no X-RateLimit-* headers and no per-plan tiers: back off for the Retry-After period and retry. Transactions are read from MagniFinance's synced store, so polling GET /transactions does not touch the bank and is limited only by the numbers above.