Rate Limits
Request limits per API key, what a 429 looks like, and how publishing to platforms is paced.
Two different limits matter when you build on the API. One is ours: how many requests a key can make per minute. The other belongs to the social platforms: how often one connected account may post. They behave differently, and this page covers both.
Requests per API key
Every API key has a per-minute budget, counted in a fixed one-minute window. Each key gets its own bucket, so a busy key never eats another key's allowance.
The ceiling scales with how many social accounts your billing account has connected. The more you've scaled, the more headroom your keys get. API requests are free within the ceiling; you pay for connected accounts, never per call.
| Connected accounts | Requests per minute, per key |
|---|---|
| Up to 2 | 60 |
| 3–2,000 | 600 |
| 2,001+ | 1,200 |
Browser and unauthenticated traffic is limited per IP. Need more for a key? Contact support with the volume you expect; ceilings are published here whenever they change.
Rate limit headers
Every response carries the current state of your budget:
X-RateLimit-Limit: 600
X-RateLimit-Remaining: 587
X-RateLimit-Reset: 1724328000| Header | Description |
|---|---|
X-RateLimit-Limit | Requests allowed in the current window |
X-RateLimit-Remaining | Requests left in the current window |
X-RateLimit-Reset | Unix timestamp when the window resets |
Retry-After | Seconds to wait. Sent on a 429 only |
When you go over
Exceed the budget and you get 429 Too Many Requests with a body that tells you exactly how long to wait:
{
"error": "too_many_requests",
"message": "Rate limit of 600 requests per minute reached. Retry in 23 seconds.",
"retry_after": 23
}The same number is in the Retry-After header. Nothing is queued on our side; the request simply did not run, so retry it after the wait.
The official SDKs wait out one 429 automatically using Retry-After and only throw if the retry is limited too. Set maxRateLimitRetries on the client to change that.
Best practices
- Wait for
Retry-Afteron a 429, then retry. Add exponential backoff if you get a second one - Check
X-RateLimit-Remainingbefore firing a burst of requests - Use the bulk endpoints instead of one request per post
- Cache reads you repeat, such as account lists
Publishing to platforms
We do not hold your posts. A post you publish now is handed to the platform immediately, and a scheduled post is handed over at its time. There is no pacing, spacing, or daily cap on our side.
Each social platform enforces its own limits on how often one account may post. When a platform throttles an account, the delivery waits exactly as long as the platform asked, and the post shows the platform's own message, for example "Waiting for TikTok, retrying at 12:35". The API reports the same on the delivery:
{
"publish_status": "delayed",
"delay_reason": "platform_rate_limit",
"delay_message": "TikTok: too many posts in a short window",
"scheduled_publish_at": "2026-08-22T12:35:00.000Z"
}A delivery.delayed webhook fires at the same moment, and delivery.published or delivery.failed follows once the retry runs. Limits that the platforms publish include a per-minute request cap per user token on TikTok, a daily publishing cap on Instagram and Threads, and a daily post cap per member on LinkedIn; most platforms publish none. When a platform rejects a post for a reason no retry can fix, such as a missing permission or an unverified media domain, the delivery fails immediately with that reason instead of retrying.
Related documentation
- API Overview
Base URL, envelopes, pagination, and errors for the FoPost REST API.
- Authentication
API keys, scopes, and workspace binding.
- Publishing
Create a post, target accounts, publish it, and read the per-account result.
- Scheduling
Schedule a post, repeat it, and import a batch from a spreadsheet.
- Media
Upload files, list the media library, and attach media to a post.
- Validation
Check content, text length, and media against platform rules before a post exists.
- Accounts
List connected social accounts, check their health, and refresh credentials.
- Workspaces
Workspaces, labels, and how isolation works across them.