Rate limits: understanding 429 errors

Edited

Apideck doesn't add its own rate limit to your Unify API calls. Your requests are bound by the rate limits of the downstream provider, such as QuickBooks, Xero or BambooHR. When you get a 429 Too Many Requests, it's almost always the provider telling us to slow down, and we pass that on to you.

What a 429 from Apideck looks like

When the provider returns a 429, Apideck returns a 429 with the error type ConnectorRateLimitError. The provider's own error message is included under detail.error, so you can see exactly which limit was hit.

For many connectors, Apideck also returns the provider's rate-limit information in standard headers, on both successful responses and 429s:

  • x-downstream-ratelimit-limit: the number of requests allowed in the current window

  • x-downstream-ratelimit-remaining: how many requests are left in the window

  • x-downstream-ratelimit-reset: when the window resets

  • retry-after: how many seconds to wait before trying again, when the provider sends it

These headers are available for connectors including QuickBooks, Intuit Enterprise Suite, Xero, Exact Online, Sage Intacct REST, Twinfield, HubSpot, Salesforce, Pipedrive, Close, Shopify, BigCommerce, HiBob and Lucca. Not every provider shares this information, so for others you may only get the 429 itself.

How to handle a 429

  1. Wait before retrying. If there's a retry-after header, wait at least that long. Otherwise, use exponential backoff, for example 1s, 2s, 4s, 8s.

  2. Slow down rather than retrying in a tight loop. Retrying immediately uses up the same limit and keeps you blocked for longer.

  3. Spread out large syncs. Many limits are per minute *and* per day. A full historical sync can use up a whole day's allowance on some providers.

  4. Use incremental syncs. Use filter[updated_since] so you only fetch what changed since your last sync. See How Pagination, Filtering, and Sorting Work.

  5. Prefer list calls over many single-record calls where you can. One list page usually costs far fewer provider calls than fetching each record one by one.

Limits are often shared with other apps

Most provider limits apply to the customer's whole account or company, not just to your app. If your customer has other integrations connected to the same QuickBooks company, NetSuite account or Lucca domain, those calls count against the same limit. This is the most common reason for a 429 when your own traffic looks low.

Limits by provider

These are the limits the providers publish. Providers can change them, so check their documentation for the latest figures.

Provider

Limit

QuickBooks Online

500 requests/minute per company, and 10 concurrent requests. Higher QuickBooks plans don't raise these limits.

Intuit Enterprise Suite

500 requests/minute per company, and 10 concurrent requests.

Xero

60 calls/minute and 5 concurrent calls per organisation. Daily cap of 1,000 calls on the Starter plan and 5,000 on Core and above.

NetSuite

Limited by concurrent requests per account rather than per minute: 5 (Standard), 15 (Premium), 20 (Enterprise/Ultimate), plus 10 per SuiteCloud Plus license.

Sage Intacct

100,000 API transactions per month per company on the default performance tier. This is shared between the XML and REST APIs.

Exact Online

60 requests/minute and 5,000 requests/day per app per division. Exact Online Premium raises the daily cap to 30,000.

Zoho Books

100 requests/minute per organisation. The daily cap depends on the customer's plan, from 1,000 (Free) to 10,000 (Premium).

Microsoft Dynamics 365 Business Central

6,000 requests per user per 5-minute window, and 5 concurrent requests per user.

HubSpot

110 requests per 10 seconds per connected account. CRM search is limited separately, to 5 requests/second.

Salesforce

100,000 requests per 24 hours (Enterprise), plus 1,000 per user license.

BambooHR

Not published. BambooHR throttles at its own discretion and returns a retry-after header. Since September 2026 it signals this with a 429 (previously 503).

HiBob

Varies by endpoint, around 50 requests/minute on people search.

Personio

2,000 requests/minute per IP overall, with tighter limits on some endpoints, such as 300/minute on the employee list.

Lucca

50 requests/minute per Lucca domain, shared by every integration connected to that domain.

Workday

No published hard limit. Workday throttles under high tenant load.

Still seeing 429s?

Contact Apideck support through the Customer Portal (the Requests link at the top of this help center), your Slack channel with us, or support@apideck.com. Include the connector, the consumer ID and roughly when it happened. You can also find the failing request in the request logs in your Apideck dashboard (see How to see the log of a request?). We can tell you which provider limit was hit and how much of the traffic came from your app.

Was this article helpful?

Sorry about that! Care to tell us more?

Thanks for the feedback!

There was an issue submitting your feedback
Please check your connection and try again.