Rate Limits

Request limits per API key, what a 429 looks like, and how publishing to platforms is paced.

Two different limits matter when you build on the API. One is ours: how many requests a key can make per minute. The other belongs to the social platforms: how often one connected account may post. They behave differently, and this page covers both.

Requests per API key

Every API key has a per-minute budget, counted in a fixed one-minute window. Each key gets its own bucket, so a busy key never eats another key's allowance.

The ceiling scales with how many social accounts your billing account has connected. The more you've scaled, the more headroom your keys get. API requests are free within the ceiling; you pay for connected accounts, never per call.

Connected accountsRequests per minute, per key
Up to 260
3–2,000600
2,001+1,200

Browser and unauthenticated traffic is limited per IP. Need more for a key? Contact support with the volume you expect; ceilings are published here whenever they change.

Rate limit headers

Every response carries the current state of your budget:

X-RateLimit-Limit: 600
X-RateLimit-Remaining: 587
X-RateLimit-Reset: 1724328000
HeaderDescription
X-RateLimit-LimitRequests allowed in the current window
X-RateLimit-RemainingRequests left in the current window
X-RateLimit-ResetUnix timestamp when the window resets
Retry-AfterSeconds to wait. Sent on a 429 only

When you go over

Exceed the budget and you get 429 Too Many Requests with a body that tells you exactly how long to wait:

{
  "error": "too_many_requests",
  "message": "Rate limit of 600 requests per minute reached. Retry in 23 seconds.",
  "retry_after": 23
}

The same number is in the Retry-After header. Nothing is queued on our side; the request simply did not run, so retry it after the wait.

The official SDKs wait out one 429 automatically using Retry-After and only throw if the retry is limited too. Set maxRateLimitRetries on the client to change that.

Best practices

  • Wait for Retry-After on a 429, then retry. Add exponential backoff if you get a second one
  • Check X-RateLimit-Remaining before firing a burst of requests
  • Use the bulk endpoints instead of one request per post
  • Cache reads you repeat, such as account lists

Publishing to platforms

We do not hold your posts. A post you publish now is handed to the platform immediately, and a scheduled post is handed over at its time. There is no pacing, spacing, or daily cap on our side.

Each social platform enforces its own limits on how often one account may post. When a platform throttles an account, the delivery waits exactly as long as the platform asked, and the post shows the platform's own message, for example "Waiting for TikTok, retrying at 12:35". The API reports the same on the delivery:

{
  "publish_status": "delayed",
  "delay_reason": "platform_rate_limit",
  "delay_message": "TikTok: too many posts in a short window",
  "scheduled_publish_at": "2026-08-22T12:35:00.000Z"
}

A delivery.delayed webhook fires at the same moment, and delivery.published or delivery.failed follows once the retry runs. Limits that the platforms publish include a per-minute request cap per user token on TikTok, a daily publishing cap on Instagram and Threads, and a daily post cap per member on LinkedIn; most platforms publish none. When a platform rejects a post for a reason no retry can fix, such as a missing permission or an unverified media domain, the delivery fails immediately with that reason instead of retrying.

Related documentation
  • API Overview

    Base URL, envelopes, pagination, and errors for the FoPost REST API.

  • Authentication

    API keys, scopes, and workspace binding.

  • Publishing

    Create a post, target accounts, publish it, and read the per-account result.

  • Scheduling

    Schedule a post, repeat it, and import a batch from a spreadsheet.

  • Media

    Upload files, list the media library, and attach media to a post.

  • Validation

    Check content, text length, and media against platform rules before a post exists.

  • Accounts

    List connected social accounts, check their health, and refresh credentials.

  • Workspaces

    Workspaces, labels, and how isolation works across them.

Was this helpful?

On this page