Rate limits
Each API key can make 120 requests a minute. That is far more than a normal sync needs: a full month of invoices for a busy workspace is around 10 requests.
Headers on every answer
| Header | Meaning |
|---|---|
RateLimit-Limit |
Requests allowed per minute for this key |
RateLimit-Remaining |
Requests left in the current minute |
RateLimit-Reset |
Seconds until the minute resets |
curl -i https://api.trued.io/v1/me -H "Authorization: Bearer $TRUED_API_KEY"
HTTP/1.1 200 OK
RateLimit-Limit: 120
RateLimit-Remaining: 118
RateLimit-Reset: 41
When you go over
The request is refused with 429 and a Retry-After header giving the seconds to wait:
HTTP/1.1 429 Too Many Requests
Retry-After: 12
Content-Type: application/problem+json
Wait that long, then continue. Nothing is lost: every endpoint only reads data, so the request can simply be sent again.
Refused requests are counted per minute in your request log, not listed one by one.
Staying well under
- Use
limit=100to read lists in fewer pages. - Use
updated_sinceto read only what changed since your last sync, rather than everything. See Pagination. - Use webhooks instead of checking for changes in a tight loop.
- Give each system its own key. Each key has its own limit, so a busy report never slows down your payroll sync.
The limit is approximate during a sudden burst: a few requests over may be allowed before 429
starts. Do not rely on that.
Failed sign-ins are limited separately: an address that sends more than 20 refused keys in a
minute is slowed down with 429.
Need more
If your integration genuinely needs more, contact TRUED support with what it does and how many requests a minute it needs. Limits can be raised for a single key.