429 before the individual limit is reached.
Act allows 1,000 requests per minute and 20,000 per hour, per operation and verified account. These are admission limits, not a promise that an external provider is available or will accept an action. Authentication, credential, payment, and provider-callback protections have separate safeguards.
A limited request returns 429 Too Many Requests and, when supported, a Retry-After signal.
1
Wait for the server signal
On
429, respect Retry-After or the returned reset value before sending another request.Success: the client does not retry inside the same exhausted window.2
Retry with a bound
Use exponential backoff with jitter, a maximum delay, and a maximum attempt count. Do not retry
400, 401, 403, or 404 without correcting the request or authority.Success: transient failures recover without an unbounded retry loop.3
Preserve the logical operation
Debounce interactive Search and cache identical read-only requests. For a retried Act write, reuse its
idempotencyKey with the same inputs; do not create a new key merely because the response was lost.Success: retries do not create duplicate work or unnecessary Search traffic.Read the limit signals
Search API responses advertise the current caller limit. Successful responses also include the remaining budget and reset interval. A429 may instead reflect shared capacity, so always follow Retry-After when it is present.
Reuse an Act write’s
idempotencyKey only with identical inputs. The requestId returned for a provider approval or payment is a different identifier; use it to address that exact pending request, not as the write’s idempotency key.