Skip to content
Limits & Quotas
.md

Limits & Quotas

The numeric limits the API enforces, in one place. Every value here is the current default; where a limit is tunable per environment the default is what a standard account sees. Each row links to the page that documents the behavior in context.

Rate limits

Every authenticated request is metered against a named bucket, keyed per caller token (two API clients of the same company get independent buckets). A request over the limit returns 429 with a Retry-After header.

BucketLimitApplies to
Read120 requests/minEvery GET (resource reads, reference lookups, polling).
Write30 requests/minEvery create and delete (POST).
MCP endpoint120 requests/minRequests to POST /api/v2/mcp itself. Proxied sub-requests also consume the read/write buckets.

See Polling and Rate Limits.

Build budget

Every create that starts a worker job - audiences, estimates, Lookalike Models, cohorts and activations - counts against one rolling budget per organization, on every channel (console, API and MCP alike). Scheduled replays do not count. Over the budget, the create is refused with 429 and a Retry-After header; nothing is created.

WindowDefaultNotes
Rolling hour60 buildsCounted from the rows created in the last 60 minutes.
Rolling day300 buildsCounted from the rows created in the last 24 hours.

Both values can be raised per organization by your Intuizi representative. GET /api/v2/usage returns build_budget with the limits, the live counts and retry_after_seconds when a window is exhausted, so a client can pace itself before hitting 429.

Authentication

LimitValueNotes
Login rate180 requests/min per IPPOST /api/v2/auth/login, metered per client IP, not per token.
MCP token mint / revoke rate10 requests/min per IPPOST /api/v2/auth/mcp-token and .../revoke.
Active MCP tokens10 per userFurther mints return 422 until you revoke one.
MCP token lifetime1 yearManual MCP tokens expire after 365 days by default.
API token mint / revoke rate10 requests/min per IPPOST /api/v2/auth/api-token and .../revoke.
Active API tokens10 per userFurther mints return 422 until you revoke one.
API token lifetime1 yearAPI tokens expire after 365 days by default.

See Authentication.

Idempotency

LimitValueNotes
Replay TTL24 hoursHow long a stored create response is replayable.
Endpoints honoring Idempotency-Key7 createsSee the full list on Idempotency.

Uploads

LimitValueNotes
POI submission file50 MBMax size for a poi_submission upload.
Cohort file1 GBMax size for a cohort upload.
Presigned URL expiry15 minutesWindow, from reserving the slot, to PUT the file and to claim the reference with a create.
Unclaimed upload cleanup24 hoursAn unclaimed object is removed after this horizon. It does not extend the window to claim the reference.

See Uploads.

Webhooks

LimitValueNotes
Delivery attempts6Attempt 1 is immediate, then 5 retries.
Retry backoff1 min, 5 min, 25 min, 2 h, 6 hWaits between attempts; the 6 attempts span roughly 8.5 hours.
Auto-disable threshold20 consecutive exhausted deliveriesThe endpoint is switched off and its creator notified.
Signature timestamp tolerance5 minutesThe replay window receivers should enforce on the signed timestamp.

See Webhooks and Webhooks API.

Audiences and Lookalike Models

LimitValueNotes
Minimum to activate500 unique devicesBelow this, an activation is rejected (is_activation_allowed is false).
Affinity device coverageunique EIDs > 2x unique SCIDsAudiences with AffinityTransactions data; eligibility.reasons[].code = affinity_device_coverage.
Mapping-key retention90 days after the latest dataset end dateStandard audiences only. MAID and IP mapping keys are retained for 90 days, so an older audience cannot be delivered as MAIDs or IPs: eligibility.notices[].code = audience_expired with blocks_identifiers = ["MAID", "IP"]. Other identifiers (EID, SCID, HEM) are unaffected; a MAID or IP pricing model is rejected with 422.
Web visitation lookback45 daysA WebDomain dataset’s start_date must fall within the 45-day window of available web data; an earlier date is rejected with 422. See Audiences.
Lookalike seed minimum1,000 devicesThe completed seed audience must hold at least this many.
Lookalike output minimum to activate1,000 devicesA lookalike result audience must reach this before it can be activated.
Lookalike target size1 to 4,000,000The config.target_size range on a Lookalike Model create.

See Audiences.

Usage

LimitValueNotes
Earliest reportable month2020-01GET /api/v2/usage rejects a yearmonth before this floor (or in the future).

See Usage.

Pagination

per_page defaults and caps depend on the surface.

SurfaceDefault per_pageCap
Resource lists (audiences, activations, cohorts, projects, schedules)25100
Reference reads (Common, Web, CTV)500500
Apps reference reads250uncapped

See Request & Response Envelope.