Skip to Content
API ArchitectureRate Limits

Rate Limits

How rate limits work with the Adesic API.

Rate Limits: All API keys are subject to rate limiting

Rate Limit for REST API

The Adesic REST API enforces rate limits to ensure fair usage and maintain system performance. When a rate limit is exceeded, a response with a status of 429 Too Many Requests will be returned.

By default, all API endpoints are throttled based on the requesting IP address. The general rate limit is set to 10 requests per second, with the ability to handle bursts of up to 15 requests per second. Please note that certain endpoints may have custom rate limits depending on their specific usage and requirements.

Higher Rate Limits

If you require a higher rate limit for your application or have specific business needs, we offer custom rate limit options. To discuss a higher rate limit tailored to your requirements, please contact our team at support@adesic.com. We will be happy to assist you with your request.

How It Works

Our rate limiting uses a lazy-fill token bucket implementation. A TokenBucket stores a maximum amount of tokens which is the burst size and fills at a given rate called the refresh rate. The bucket will start full and as requests are received a token is removed for each request. Tokens are continuously added to the bucket at the refresh rate until full.

When a user sends a request, here’s how TokenBucket calculates whether or not to rate limit the user:

  1. Fill the user’s TokenBucket to a token size based on the following formula:
    token_amount = min(burst, previous_token_amount + (current_time - previous_request_time) * refresh_rate)
  2. Remove 1 token if possible, otherwise rate limit the request.
  3. Repeat Steps 1 and 2 for each subsequent request.

Example

Let’s say you have a TokenBucket with burst = 3 and refresh_rate = 1. The table below represents the state of your token bucket after a series of requests


ActionTimeTokensNotes
Initial State0.03.0New TokenBucket is initialized to max capacity (burst)
Request 10.52.0First fill the TokenBucket, then remove a token. Because we are at max capacity, just subtract 1 token from 3
Request 20.81.3Fill the TokenBucket to 2.3 (min(3, (2 + (.8 - .5) * 1.0)) = min(3, 2.3) = 2.3), then subtract 1
Request 30.90.4Fill the TokenBucket to 1.4 (min(3, (1.3 + (.9 - .8) * 1.0)) = min(3, 1.4) = 1.4), then subtract 1
Request 41.00.5Fill the TokenBucket to 0.5 (min(3, (.4 + (1.0 - .9) * 1.0)) = min(3, 0.5) = 0.5). Ratelimit because we don’t have enough tokens available
Request 51.40.9Fill the TokenBucket to 0.9 (min(3, (0.5 + (1.4 - 1.0) * 1.0)) = min(3, 0.9) = 0.9). Ratelimit because we don’t have enough tokens available
Request 61.80.3Fill the TokenBucket to 1.3 (min(3, (0.9 + (1.8 - 1.4) * 1.0)) = min(3, 1.3) = 1.3), then remove 1
Request 75.02.0Fill the TokenBucket to 3.0 (min(3, (0.3 + (5.0 - 1.8) * 1.0)) = min(3, 3.5) = 3) since we would “overflow” with our calculations. Then subtract 1 token

© Adesic LLC. All Rights Reserved