Limits
When developing an integration with Spendesk please respect the following rate limits:
- 1,000 requests per minute for each Spendesk company (entity) and each credential (API key or OAuth2 connection) - both for customers calling APIs and for partners calling APIs on behalf of connected customers;
- 10 requests per minute for dynamic client registration;
- 500 concurrent requests at any given time for any API consumer;
- 100 concurrent requests at any given time for MCP, per company;
- 200 concurrent requests at any given time for MCP, per organisation.
HTTP Headers
Each API response contains the following headers, which mention applicable rate limits and remaining values:
x-ratelimit-limit: <maximum number of requests in the current window>
x-ratelimit-remaining: <requests left in the current window>
x-ratelimit-reset: <seconds until the window resets>Read the values from the headers rather than hard-coding the limits above: they describe the limit that applies to your request.
When one of the limits is reached, all subsequent API requests will return error 429 until the x-ratelimit-reset interval (in seconds) passes.
Guidance
Partners are required to address rate limiting before going liveSpendesk will ask partners to explain how they intend to keep the frequency of API calls within limits.
When building an integration that will be used by more than a couple of companies, please design a mechanism that will prevent reaching these rate limits. Typical mistakes include triggering the flow for all connected companies each day at 6am, each Monday at 6am or each 1st of the month at 6am etc. Introducing randomness in the time of API calls, respecting off-peak hours (9pm to 6am on weekdays) and sleep intervals between subsequent pages of multi-page responses are highly recommended.