Rate limits
Counted per address per rolling minute, and per endpoint, so a burst of reads does not use up your write allowance. Exceeding one is a 429 with a retry-after header.
The allowance
| Endpoint | Per minute | Why it is what it is |
|---|---|---|
/api/check | No limit | Reads one key and returns three booleans. Safe to poll. |
/api/unshorten | No limit | Reads one key. This is the page behind /reveal/, which people use interactively. |
/api/stats, /api/version, /api/changelog | 60 | Either a small fixed document or one that walks the namespace. |
/api/links | 30 | Walks the namespace and assembles every link. |
/api/export | 20 | Same walk, rendered as text. |
/api/preview | 20 | The only endpoint that fetches something outside this server. |
/api/remove | 20 | Deletes. Deliberately not the strictest, because being unable to delete is worse than an extra call. |
/api/unlock | 12 | Password attempts. This is the one number worth keeping tight. |
/api/create | 10 | Writes. |
/api/bulk | 5 | Ten writes per call, so five calls is fifty links a minute. |
/api/sweep GET, DELETE | 4 | See the note below. |
/api/sweep POST | 2 | See the note below. |
The sweep shares one allowance
The three methods on /api/sweep share a single counter rather than having one each. Otherwise a run of that route would multiply the limit by three, and it is the one endpoint that does the most work per call.
How they are counted
Each counter is a key in the same namespace as everything else, named for the endpoint, the address and the current sixty-second bucket, and it expires on its own after the bucket has passed. Nothing is kept about you beyond the counter, and the counter is gone within a couple of minutes.
There is no way to raise a limit. If yours is too low for what you are building, the answer is to batch — ten links per bulk call rather than ten create calls — or to poll the unlimited read endpoints instead of the listing ones.
retry-after value at face value.
One limit that is not ours
Nothing on this site calls GitHub, so there is nothing to document here. On the other site's docs the equivalent page covers GitHub's anonymous limit, which is the one that bites first.