specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Apiary providerId: apiary created: '2026-05-04' modified: '2026-09-02' generated: '2026-09-02' method: searched source: https://help.apiary.io/tools/mock-server/#rate-limiting description: >- Published rate limits for Apiary's surfaces. Apiary documents limits for exactly one surface — the Mock Server — and documents the response headers it returns. It publishes no rate limit at all for the Apiary API itself (api.apiary.io), which is the surface an integrator actually calls to fetch and publish API description documents. note: >- THIS FILE REPLACES A SCAFFOLD. The previous revision (method: generated, 2026-05-04) carried invented free/professional/enterprise tiers of 10/100/1000 requests per minute and generic X-RateLimit-* headers. None of that was published by Apiary. Every value below is quoted from Apiary's own Mock Server help page, and the gaps are recorded as gaps. tags: - API Blueprint - API Design - Mock Servers - Rate Limiting headers: limit: X-Apiary-Ratelimit-Limit remaining: X-Apiary-Ratelimit-Remaining reset: null retryAfter: null policy: null header_note: >- Apiary uses vendor-prefixed headers, not the RFC 9331 `RateLimit-*` family and not the de-facto `X-RateLimit-*` family. The documented example response is: `X-Apiary-Ratelimit-Limit: 120` / `X-Apiary-Ratelimit-Remaining: 119`. No reset header and no Retry-After are documented, so a client cannot compute when the window reopens — it can only observe `Remaining` fall to zero. responseCodes: throttled: null note: >- Apiary does not document the status code returned when the mock server limit is exhausted. Not probed to exhaustion — deliberately, since that would mean knowingly flooding a live provider surface. limit_count: 2 limits: - name: Mock Server — anonymous surface: Mock Server scope: per-mock-server (anonymous, private URL) metric: requests_per_minute limit: 120 burst: null timeFrame: minute authenticated: false source: https://help.apiary.io/tools/mock-server/ quote: 'By default the Mock Server allows for 120 requests per minute.' - name: Mock Server — authenticated surface: Mock Server scope: per-token metric: requests_per_minute limit: 5000 burst: null timeFrame: minute authenticated: true auth_header: 'Authentication: Token ' token_source: https://login.apiary.io/tokens source: https://help.apiary.io/tools/mock-server/ quote: >- A higher limit is available with authentication ... The Mock Server should now allow for 5000 requests per minute. undocumented: - surface: Apiary API (https://api.apiary.io) note: >- No rate limit is published for the Apiary API itself. The API description document (jsapi.apiary.io/apis/apiary, fetched 2026-09-02) declares no 429 response and no rate-limit headers on any of its nine operations, and the error enum it publishes contains no throttling member. An integrator writing against /me, /me/apis or /blueprint/publish has no documented ceiling and no documented runtime signal. policies: - name: Raising the mock-server limit description: >- Authenticating the mock-server request with a token raises the ceiling from 120 to 5000 requests per minute. Generate the token at https://login.apiary.io/tokens and send it as `Authentication: Token `. maintainers: - FN: Kin Lane email: kin@apievangelist.com