Skip to main content
Stableyard limits how many requests a caller can make in a time window. Responses report the quota that applies to them, so read the headers rather than hardcoding numbers.

Rate limit headers

A request counts against every policy that applies to it. On a success, the headers describe the most constrained of those policies; on a 429, the policy that was exceeded. When a deployment does not enforce rate limits, responses carry no RateLimit-* headers.

Default policies

These are the defaults for requests made with your app’s credentials. Stableyard can configure them per deployment. A POST /v2/payments, for example, counts against writes per app environment, per app, and payments per app.

Handle a 429

  1. Wait for Retry-After before sending the request again.
  2. Reuse the same Idempotency-Key when you retry a write. See Retrying safely.
  3. Spread the load. React to webhooks instead of polling every resource, and page through lists with their cursors.
Not every 429 is a rate limit. payment_option_limit_reached means too many options were created for one payment. See Errors.

Errors

Every error code and which ones to retry.

Idempotency

Retry a write without doing it twice.

Webhooks

Learn about changes without polling.

Environments

Base URLs and what is isolated between environments.