Rate limits
Two limits protect the service from a misbehaving agent or script. Neither is something a working fleet comes near: an agent checks in about once a minute, and the portal makes a handful of requests per page.
The limits
Section titled “The limits”| Who | Where | At once | Sustained |
|---|---|---|---|
| Each host | agents.updawg.net (the agent) |
300 | 2 a second |
| Each organization | api.updawg.net (portal and API tokens) |
600 | 20 a second |
They are the same on every plan — Free, Team, Business and Enterprise. A plan changes how many hosts you may enrol and which features you have, not how fast you may ask. If an Enterprise integration needs more, talk to us.
Each limit is a bucket: it holds the “at once” number of requests, every request takes one, and it refills at the sustained rate. A burst after a quiet spell is fine; a loop that never stops is not.
What counts
Section titled “What counts”- Hosts are counted at the gateway as soon as the agent’s certificate is read, before any other work. Each host has its own bucket; one noisy host never slows down another.
- Organizations are counted at the API once the caller is known to belong to
the organization. Everything under
/v1/orgs/{org}counts, whether it comes from someone in the portal or from an API token, so a busy script shares its allowance with the people using the portal. A request for an organization you are not a member of is a404and costs that organization nothing.
When you are over
Section titled “When you are over”The answer is 429 Too Many Requests with these headers:
| Header | Meaning |
|---|---|
Retry-After |
Seconds until the next request will be allowed. |
RateLimit-Limit |
The “at once” size of the bucket. |
RateLimit-Remaining |
0. |
RateLimit-Reset |
The same number of seconds as Retry-After. |
The API’s body is a problem document with type ending in rate-limited. The
gateway’s body also carries retry_after_s.
Wait at least Retry-After seconds, then try again. Retrying sooner is
refused the same way. The agent does this on its own: it waits for the longer of
Retry-After and its usual backoff, and nothing needs configuring.
Every /v1/orgs/{org} operation in the API reference lists the 429.