shortn
Docs/Limits

Rate limits

Counted per address per rolling minute, and per endpoint, so a burst of reads does not use up your write allowance. Exceeding one is a 429 with a retry-after header.

Counted per address · per endpoint · per rolling minute

The allowance

EndpointPer minuteWhy it is what it is
/api/checkNo limitReads one key and returns three booleans. Safe to poll.
/api/unshortenNo limitReads one key. This is the page behind /reveal/, which people use interactively.
/api/stats, /api/version, /api/changelog60Either a small fixed document or one that walks the namespace.
/api/links30Walks the namespace and assembles every link.
/api/export20Same walk, rendered as text.
/api/preview20The only endpoint that fetches something outside this server.
/api/remove20Deletes. Deliberately not the strictest, because being unable to delete is worse than an extra call.
/api/unlock12Password attempts. This is the one number worth keeping tight.
/api/create10Writes.
/api/bulk5Ten writes per call, so five calls is fifty links a minute.
/api/sweep GET, DELETE4See the note below.
/api/sweep POST2See the note below.

The sweep shares one allowance

The three methods on /api/sweep share a single counter rather than having one each. Otherwise a run of that route would multiply the limit by three, and it is the one endpoint that does the most work per call.

How they are counted

Each counter is a key in the same namespace as everything else, named for the endpoint, the address and the current sixty-second bucket, and it expires on its own after the bucket has passed. Nothing is kept about you beyond the counter, and the counter is gone within a couple of minutes.

There is no way to raise a limit. If yours is too low for what you are building, the answer is to batch — ten links per bulk call rather than ten create calls — or to poll the unlimited read endpoints instead of the listing ones.

A 429 is not a queue Requests over the limit are refused, not held. Nothing is waiting for you on the other side, so there is no reason to retry quickly — take the retry-after value at face value.

One limit that is not ours

Nothing on this site calls GitHub, so there is nothing to document here. On the other site's docs the equivalent page covers GitHub's anonymous limit, which is the one that bites first.