Rate limits
A rate limit bounds how fast requests arrive. It is counted per IP address or per email address, not per credential, and it is the same on every plan.
| Limit | Applies to | Over the limit |
|---|---|---|
| 3,000 requests per IP address, trailing 5 minutes | Every request to api.naturali.ai | 429 too_many_requests, Retry-After: 60 |
| 20 requests per IP address, trailing 5 minutes | POST /v1/auth/code and POST /v1/auth/code/verify, together | 429 too_many_requests, Retry-After: 60 |
| 1 code per minute, 10 per day per email address | POST /v1/auth/code | 429 too_many_requests |
| A bounded number of wrong guesses per code | POST /v1/auth/code/verify | 429 too_many_attempts — the code is destroyed; request a new one |
| 50 invitations per inviter, trailing 24 hours | POST /v1/projects/{project_id}/members | 429 rate_limited |
3,000 requests in 5 minutes is about ten a second, sustained. The window slides, so a burst is forgiven once it falls out of the last five minutes.
The sign-in limits exist because each request mails a real inbox; why they are shaped as they are is in Auth.
Retrying
Every 429 carries the error envelope. Where a Retry-After
header is present, wait that many seconds before retrying; where it is absent,
waiting alone does not help, and the code says what will. Retrying sooner
keeps the IP address over the limit.
Limits that are not about rate
Other refusals bound how much work a project does or spends, not how fast it asks. They are per project or per account, and waiting rarely clears them.
| Refusal | Set by | Cleared by | Where |
|---|---|---|---|
429 QUOTA_EXCEEDED, with Retry-After | You, as a quota on a windowed metric | The window resetting | Quotas |
409 QUOTA_STORAGE_EXCEEDED | You, as a storage quota | Deleting content or raising the quota | Quotas |
403 plan_limit_reached | Your plan: projects, channels, triggers, schedule interval, storage, runs, retention | Upgrading, or removing resources | Users → Plan and credit |
403 plan_feature_not_included | Your plan: guardrails, approvals, exceptions, audit log | Upgrading | Users → Plan and credit |
402 insufficient_credit | A negative credit balance, on naturali-managed models and priced marketplace listings | A top-up | Users → Plan and credit |
A plan or credit refusal applies to every member of a project, because the project's billing owner's plan and balance are the ones read.