API key request limits
Requires a license with the
apikey-profeature. See pricing.
A request limit caps how many requests one API key may make in a
calendar month. Once the key reaches it, every further request answers 429
until the next month starts or you raise the limit. Everything else about keys,
from creating them to reading their history, stays free on every install.
In the admin console
Section titled “In the admin console”Open Access > API keys. The Usage (this month) column shows each key's
requests, with a bar for a key that has a monthly limit. To change a key's
limits, choose its Request limits button. The drawer has Per hour,
Per day and Per month, where 0 sets no ceiling, and Save applies
them. The New key form has the same three fields.

The sections below cover the monthly limit over the API.
How it works
Section titled “How it works”| Question | Answer |
|---|---|
| What is counted | Every request the key makes on the Content API, whatever it answers, except the ones refused at the limit. |
| When the count resets | At the start of each calendar month, in UTC. |
| What a key over its limit gets | 429 with X-RateLimit-Exceeded: true and {"error": "monthly request limit (100000) exceeded"}. |
What 0 means | No limit. It is the default. |
| Who counts | Usage and quotas, which runs on every install. If the count cannot be read, the request goes through. |
Try it
Section titled “Try it”Run this on an install whose license carries apikey-pro. You need an admin
token in TOKEN. The quickstart shows how
to get one, and creates the post content type used here.
-
Create a key that may make three requests this month:
Terminal window curl -X POST http://localhost:3001/api/admin/api-keys \-H "Authorization: Bearer $TOKEN" \-H "Content-Type: application/json" \-d '{"name": "partner-feed", "roles": ["site-reader"], "scopes": ["content:read"], "monthly_limit": 3}'The answer is
201with"monthly_limit": 3. Copyraw_keyintoKEYandidintoKEY_ID. Thesite-readerrole needs an access rule that readspost, as step 1 of API keys creates. -
Call the Content API four times with it:
Terminal window for i in 1 2 3 4; docurl -s -o /dev/null -w "%{http_code}\n" http://localhost:3002/api/v1/content/post \-H "X-API-Key: $KEY"doneYou see
200,200,200, then429. -
Read the key's use this month:
Terminal window curl http://localhost:3001/api/admin/usage/api-key/$KEY_ID \-H "Authorization: Bearer $TOKEN"{ "api_key_id": "bab86a15-...", "tenant_id": "default", "billing_period": "2026-10", "requests": 3, "bytes_in": 0, "bytes_out": 9 }The refused fourth call is not counted.
-
Clear the limit, and the key is served again:
Terminal window curl -X PATCH http://localhost:3001/api/admin/api-keys/$KEY_ID/monthly-limit \-H "Authorization: Bearer $TOKEN" \-H "Content-Type: application/json" \-d '{"monthly_limit": 0}'The answer is the key with
"monthly_limit": 0.
Set or change a limit
Section titled “Set or change a limit”Give a new key a limit with monthly_limit on POST /api/admin/api-keys, as in
step 1, or change the limit of an existing key:
curl -X PATCH http://localhost:3001/api/admin/api-keys/$KEY_ID/monthly-limit \ -H "Authorization: Bearer $TOKEN" \ -H "Content-Type: application/json" \ -d '{"monthly_limit": 50000}'Both routes take an admin or super_admin with a signed-in session. An admin
token or another API key is refused.
| Write | Needs apikey-pro |
|---|---|
Create a key with a monthly_limit above 0 | Yes |
| Give a key with no limit its first one | Yes |
| Raise a key's limit | Yes |
| Lower a key's limit | No |
Clear a limit with 0 | No |
| Send back the value the key already holds | No |
If the license lapses
Section titled “If the license lapses”Every limit you set keeps being enforced, because it caps what a client can
spend and a lapse must not lift it. Lowering and clearing a limit stay free, so
you can still tighten a key you worry about. Setting a first limit or raising
one needs apikey-pro again.
Errors
Section titled “Errors”| Status | Message | Cause |
|---|---|---|
400 | validation failed on field "monthly_limit" | The limit is below 0. |
402 | payment_required, naming feature:apikey-pro | The write sets a first limit or raises one without apikey-pro. Nothing is stored. |
404 | api key not found | No key with that id in your tenant. |
429 | monthly request limit (<n>) exceeded | The key used its limit for this month. |
The 402 body in full:
{"error": "payment_required", "plugin": "apikey", "feature": "feature:apikey-pro", "upgrade_url": ""}The other errors of the key routes are on API keys.
Related
Section titled “Related”- API keys: scopes, roles, expiry and each key's request history.
- Usage and quotas: the counts behind the limit, and billing snapshots.
- Tenant quotas: limits on a whole tenant.
- Rate limiting: limits per second and per minute.