The DSS Public API rate-limits per client_id on a sliding window. There are two windows; whichever has the tighter remaining budget wins.

Default budgets

These apply to every authenticated /v1/* endpoint. Public endpoints (/healthz, OAuth, OpenAPI) are not rate-limited per-partner — they have infrastructure-level protection instead. Need higher limits? Premium-tier partners can negotiate. Talk to your DSS account contact.

Headers we return

Every authenticated response (success, 304, or 429) carries: The values reflect the tightest window at the time of the response — when the per-minute budget is healthier than the per-day budget, you’ll see the per-day numbers, and vice versa.

The 429 response

See Errors / rate_limit_exceeded for the detail.

Staying under budget

The default budget is generous for any reasonable integration. Here’s how to not waste it.

1. Use webhooks instead of polling

Webhooks cost zero rate-limit budget. A well-integrated partner sets up webhooks on day one and only calls the API in response to events (or when the user actively opens a page that needs fresh data). See Webhooks overview.

2. Use conditional GETs

Every resource endpoint returns ETag and Last-Modified and supports If-None-Match / If-Modified-Since. A 304 Not Modified response counts as one request against your budget but returns no body — much cheaper than the alternative of “always full payload.”
If you’re polling on a schedule, cache the ETag per (user, endpoint) and replay it on every request.

3. Don’t tight-loop on 429

A retry loop that ignores Retry-After will keep hitting 429 and never recover. Always respect the header.

4. Batch background work to natural intervals

If you’re refreshing N users’ records every M minutes, schedule the batches so they don’t pile up in the same second. Spreading 1,000 users evenly across a minute is a much smaller blast radius than 1,000 requests in the same second. If you must poll (no webhooks available on your side): Combined with If-None-Match, the realistic cost of these is small — sea-time records change a few times per month for the average crew member.

What happens on persistent overuse

If your client_id consistently saturates its budget we’ll get in touch before anything changes. We may suggest pushing more of your reads onto webhooks + conditional GETs, or talk through a higher-tier plan. We don’t hard-suspend partners for rate-limit reasons without a conversation first.