Enumeration prevention
To prevent enumeration attacks, the following limits are applied.
When a token or checkout session exceeds the limit, the API returns a
429 response with a
Retry-After header that holds the number of seconds to wait before you retry.
Traffic peaks
There’s no fixed request quota for server-to-server API calls. Capacity scales automatically with your traffic. During a very sudden spike, some requests can be slower or return a429 response
while capacity scales up.
- Retry
429responses with an exponential back-off, and send anIdempotency-Keyon requests that support it so a retry can’t create a duplicate. - Tell support about planned peaks, such as a sale or a seasonal event, ahead of time. Include the dates and the volume you expect so capacity can be raised in advance.