specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Citigroup providerId: citigroup created: '2026-05-04' # Provenance stamped 2026-08-11: this artifact was written by the API Evangelist # bulk sweep dated 2026-05-04, not harvested from the provider. See roadmap#35. method: generated modified: '2026-05-05' reconciled: false tags: - Banking - Financial Services - Payments - Rate Limiting description: Citi APIs (Citi Developer Hub, CitiConnect, Citi Velocity) enforce rate limits at the application / partner level. Public quantitative thresholds are not published in self-serve form; limits are negotiated and documented inside the partner agreement and developer portal once production access is provisioned. notes: Verify exact per-second / per-minute thresholds inside the Citi Developer Hub partner documentation after onboarding. Sandbox limits are usually lower than production. sources: - https://developer.citi.com - https://www.citibank.com/tts/sa/citiconnect/index.jsp responseCodes: throttled: 429 serviceUnavailable: 503 limits: - name: Sandbox limits scope: app metric: varies limit: see Citi Developer Hub partner documentation - name: Production limits scope: app/partner metric: varies limit: per partner agreement; documented inside Citi Developer Hub after onboarding policies: - name: Backoff Strategy description: Clients should implement exponential backoff with jitter on HTTP 429/503 responses and honor any Retry-After header. - name: Partner provisioning description: Higher production limits are configured per partner agreement and may require Citi relationship-manager approval and security review. - name: OAuth 2.0 token handling description: Reuse access tokens until expiry; do not re-issue tokens per request, which would consume Authorization-Server rate budget. maintainers: - FN: Kin Lane email: kin@apievangelist.com