# Rate limits

The Lazy Embedded API limits how many requests it accepts per minute. Two limits apply at once:

| Limit       | Requests per minute | Counted by                                 |
| ----------- | ------------------- | ------------------------------------------ |
| Per API key | 1,200               | The `Authorization` header of the request. |
| Per IP      | 3,000               | The IP address the request comes from.     |

Every request counts, including requests that fail. A request without an `Authorization` header
counts only toward the per-IP limit.

If your servers send requests with several API keys from one IP address, the per-IP limit caps
them together.

## When you exceed a limit

Lazy answers `429 Too Many Requests` with a `Retry-After` header that gives the number of seconds to
wait:

```http
HTTP/1.1 429 Too Many Requests
Retry-After: 60
Content-Type: application/json

{"error": {"code": "rate_limited", "message": "Too many requests", "request_id": null}}
```

The body is the usual [error envelope](https://developers.lazyinvoice.co.il/embedded/errors/), except that `request_id` is null: the
request was refused before it reached the API, so it has no request ID.

Wait for the `Retry-After` seconds, then send the request again. A refused request changed nothing,
so it is always safe to retry.

## Staying under the limits

- Spread bulk work, such as creating many businesses at once, over time instead of sending it in a
  burst.
- Use `limit=100` when you walk a list, so the walk takes fewer requests. See
  [Pagination](https://developers.lazyinvoice.co.il/embedded/pagination/).
- Cache what you read often, such as a business's `biz_id`, instead of looking it up on every
  request.
