REST
Each client IP address gets a budget of 20 requests per second, with bursts of up to 40. Every response tells you where you stand:
Over the limit, you get HTTP
429 with code RATE_LIMITED. Wait Retry-After seconds, then continue.
Failed API-key attempts have their own, much smaller budget. An address that keeps sending invalid keys is locked out for at least a minute and gets 429 until then.
Websocket
Staying under the limits
- Use the websocket for anything live. One connection with a series subscription replaces polling every market, and updates arrive as they happen.
- Use REST for a one-off read or to seed state, then follow changes on the websocket.
- Back off on
429; don’t retry in a tight loop.