specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: BB&T Corp (Truist) providerId: bbandt-corp created: '2026-05-04' modified: '2026-09-04' generated: '2026-09-04' method: searched source: https://developer.truist.com/assets/data/swagger-prod/retail-accounts.yaml and the other 14 published Truist OpenAPI contracts (429 response definitions and examples) sources: - https://developer.truist.com/assets/data/swagger-prod/retail-accounts.yaml - https://developer.truist.com/assets/data/swagger-prod/commercial-credit-transfers-oas-v2.yaml - https://developer.truist.com/ reconciled: true tags: - Banking - Open Banking - Truist - Rate Limiting limit_count: 0 description: 'Truist publishes NO numeric rate limits. What the contracts do publish is the SHAPE of the throttling: 25 of the 31 operations declare a 429 response, and the examples name two distinct Apigee-style mechanisms — a spike arrest (code 1207, "Traffic spike, too many requests") and a quota (code 1207/1208, "Quota violation, too many requests"). Neither the per-second rate nor the quota size nor the window is stated anywhere on the anonymous surface; capacity is set per application during onboarding. No RateLimit-*, X-RateLimit-* or Retry-After header is declared on any 429 response, so a client cannot read its remaining budget at runtime — it only learns, after the fact, which of the two limiters it hit.' headers: requestId: x-fapi-interaction-id rateLimitRemaining: null retryAfter: null headers_note: No rate-limit headers are declared in any published spec. x-fapi-interaction-id is a correlation id, not a budget signal. responseCodes: throttled: 429 limits: [] limits_note: 'Empty on purpose: Truist states that throttles exist but publishes no number, window or burst for either one. An unnumbered entry here would read as a documented limit.' mechanisms: - name: Spike arrest scope: application status: 429 code: '1207' message: Traffic spike, too many requests limit: null window: null evidence: openapi/bbandt-corp-retail-accounts-openapi.yml#/components/responses/429/content/application~1json/examples/SPIKE_ARREST_VIOLATION - name: Quota scope: application status: 429 code: 1207 (retail) / 1208 (Credit Transfers) message: Quota violation, too many requests limit: null window: null evidence: openapi/bbandt-corp-commercial-credit-transfers-oas-v2-openapi.yml#/components/responses (QUOTA_VIOLATION example, code 1208) business_limits: - name: Per-transaction limit api: Credit Transfers signal: HTTP 400, code 8027 TRANSACTION_LIMIT_EXCEEDED value: null - name: Daily limit api: Credit Transfers signal: HTTP 400, code 8026 DAILY_LIMIT_EXCEEDED value: null - name: User daily limit api: Credit Transfers signal: HTTP 400, code 8029 USER_DAILY_LIMIT_EXCEEDED value: null - name: Maximum payment amount api: Credit Transfers signal: HTTP 400, code 8002 AMOUNT_MORE_THAN_10MILLION — "Amount shouldn't be more than 10 million" value: 10000000 currency: USD business_limits_note: These are payment ceilings, not API throughput limits, and they are recorded separately so they are not counted as rate limits. Only the 10 million cap states a number; the transaction/daily/user-daily thresholds are enforced but unpublished. policies: - name: Backoff strategy description: Use exponential backoff with jitter on 429. Truist declares no Retry-After header, so the client must choose its own interval. - name: Capacity is set at onboarding description: Per-application capacity is registered during application creation and promotion to production; raise it through the Truist engagement team via https://developer.truist.com/contact-us. - name: Consent windows description: Retail endpoints are scoped to a customer consent grant. A revoked or expired consent ends access independently of any throughput limit.