# Rate limits Interfold applies an account-wide request budget to authenticated API traffic. ## Current limit API-key traffic is limited to **600 requests per account per 60-second fixed window**. Every API key for an account shares that one budget: there are no separate limits for reads, writes, resources, or plans. API-key requests to the `/v0` REST API and `/mcp` consume the same budget. Browser-authenticated dashboard sessions and unauthenticated routes are not subject to this API-key limit. ## Headers Responses can include: | Header | Meaning | | ----------------------- | ---------------------------------------------- | | `X-RateLimit-Limit` | Requests allowed in the current window. | | `X-RateLimit-Remaining` | Requests remaining in the current window. | | `X-RateLimit-Reset` | Unix timestamp when the current window resets. | | `Retry-After` | Seconds to wait after a `429` response. | ## Exceeded limits A request over the limit returns `429 Too Many Requests` with the standard error envelope. ```json { "error": { "code": "too_many_requests", "message": "Too many requests" } } ``` Wait for `Retry-After`, add jitter, and retry only operations that are safe to repeat. Avoid tight polling loops; prefer durable status fields and bounded reconciliation calls. ## Scope The budget follows the account rather than an individual API key. Rotating keys does not create a second request budget.