specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Bancomat providerId: bancomat created: '2026-05-04' modified: '2026-09-17' generated: '2026-09-17' method: searched source: https://github.com/FlowPay/client-openapi/blob/main/docs/general.md ("Rate limits" section, commit 2025-04-03) sources: - https://github.com/FlowPay/client-openapi/blob/main/docs/general.md - https://docs.flowpay.it/ tags: - Open Banking - Payments - Italy - Rate Limiting description: >- Published rate limits for the FlowPay open-banking API (FlowPay S.r.l., a BANCOMAT company). The v2 documentation states exactly two limits — 100 requests per minute per source IP and a burst ceiling of 10 requests per second — and the status code on exhaustion (429). No rate-limit response headers are documented in either contract, and the v1 contract on docs.flowpay.it documents no limits at all. The BANCOMAT scheme publishes no public API and therefore no limits. This file REPLACES a 2026-05-04 scaffold whose tiers and numbers were placeholders, not provider-published values. limit_count: 2 headers: limit: null remaining: null reset: null retryAfter: null policy: null note: no RateLimit-* / X-RateLimit-* / Retry-After headers are documented; agents must count locally and back off on 429. responseCodes: throttled: 429 quotaExceeded: null serviceUnavailable: null limits: - name: Per-IP steady-state limit scope: source-ip metric: requests_per_minute limit: 100 timeFrame: minute window: 1 minute burst: null applies: - FlowPay API (v2) evidence: '"Requests are limited to 100 requests per minute per source IP, if you exceed this limit you will receive a 429 error." — docs/general.md' - name: Per-IP burst limit scope: source-ip metric: requests_per_second limit: 10 timeFrame: second window: 1 second burst: 10 applies: - FlowPay API (v2) evidence: '"There is also a burst limit of 10 requests per second." — docs/general.md' policies: - name: Backoff on 429 description: The documentation names the 429 status but no Retry-After header; clients should apply exponential backoff with jitter and stay under 100 req/min per source IP. - name: Webhook receiver timeout description: Inbound webhook deliveries must be answered within 10 seconds or they count as failed and are retried with randomised exponential backoff (v1 contract, Webhooks chapter). - name: v1 undocumented description: The v1 contract (app.flowpay.it/api) documents no request limits; the 429 code does not appear in its responses. maintainers: - FN: Kin Lane email: kin@apievangelist.com