API Rate Limit
An API rate limit caps how many requests a client can make in a set period. Requests over the limit are rejected, usually with HTTP 429 Too Many Requests.
The request quota an API enforces, and why posting tools and scripts must slow down and retry when they hit it.
Key Points
- ✓Exceeding a rate limit usually returns HTTP 429 Too Many Requests
- ✓Retry-After and x-rate-limit-* headers tell you when you can try again
- ✓Back off and retry instead of sending the same request again immediately
- ✓Social networks limit API calls and posting volume per app and per account
An API rate limit caps how many requests a client can make in a set period, such as 100 requests per 15 minutes. When you go over it, the API rejects the extra requests, usually with HTTP status 429 Too Many Requests. 1
Why APIs limit requests
Limits keep a service fast and fair for everyone and protect it from runaway scripts and abuse. Unlimited resource use is on the OWASP list of top API security risks. 4
How to tell you hit a limit
- Status 429: the request was refused because of the limit.
- Retry-After: a header that says how long to wait before trying again. 2
- Quota headers: many APIs report the limit, what is left and when it resets. The X API sends
x-rate-limit-limit,x-rate-limit-remainingandx-rate-limit-resetwith every response. 3
How to handle rate limits
- Read the headers and slow down before you reach zero.
- On a 429, wait for Retry-After, or back off with growing delays (1, 2, 4, 8 seconds).
- Queue posts instead of sending them in bursts, for example with bulk scheduling.
- Make retries safe with an idempotency key, so a retry cannot publish the same post twice.
Rate limits in Publora
Publora enforces plan limits: posts per month, posts waiting in the schedule and how far ahead you can schedule. Attaching media by URL is limited to 60 URLs per hour, and going over returns 429 with a Retry-After header. Per-request API rate limiting is planned but not enforced yet. Each social network still applies its own limits, which Publora reports on the post if a publish fails. 5
Publora and API Rate Limit
The Publora API and MCP server publish and schedule posts to 10 networks from your own code or from AI assistants like Claude, ChatGPT and Cursor.
See the Publora API →Related Terms
- API
An API (Application Programming Interface) is a set of rules that enables software applications to communicate and exchange data, allowing social media platforms to integrate with third-party marketing tools.
- API Key
An API key is a secret string that identifies the app or person calling an API. It is sent with every request so the service knows who is asking.
- Bulk Scheduling
The process of creating, uploading, and scheduling multiple social media posts at once across platforms using CSV/Excel imports for future publication over extended periods.
- Idempotency Key
An idempotency key is a unique value a client sends with a request so that retrying the same request does not perform the action twice.
- Webhook
Automated HTTP callbacks that send real-time data between applications when specific events occur, enabling instant integration without constant polling.