specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Connexis Cash providerId: connexis-cash generated: '2026-09-05' method: searched source: >- openapi/connexis-cash-account-information-psd2-stet-mock-openapi.yml, https://developers.cib.bnpparibas.com/index.php/api-docs/account-information-psd2-stet-mock, https://developers.cib.bnpparibas.com/index.php/docs/psd2, https://developers.cib.bnpparibas.com/index.php/docs/get-started created: '2026-05-04' modified: '2026-09-05' description: >- BNP Paribas CIB publishes NO numeric rate limit for the Connexis Cash PSD2 Account Information API, on the developer portal or inside the contract. The contract does declare the exhaustion status — HTTP 429 "Too many requests" on all four operations, with a typed application/json ErrorModel body — but it declares no Retry-After, no RateLimit-* and no X-RateLimit-* response header. An agent therefore receives a stop signal with no recovery hint and must supply its own backoff policy. limit_count: 0 limits: [] responseCodes: throttled: 429 throttledBody: application/json (ErrorModel — status, message, error, path, timestamp) serviceUnavailable: 503 requestTimeout: 408 headers: limit: null remaining: null reset: null retryAfter: null policy: null headers_published: false correlation: request: X-Request-ID (required, max 70 chars) response_on_429: x-correlation-id response_on_other_errors: X-Request-ID observed: note: >- No limit could be observed live either. The production gateway (https://psd2.api.cib.bnpparibas.com) refuses every anonymous request with HTTP 400 "No required SSL certificate was sent" before any rate-limiting layer is reached, and the sandbox requires an authorised app, so no unauthenticated response headers exist to read. regulatory_context: note: >- Under the PSD2 RTS an ASPSP may not discriminate against third-party access, and BNP Paribas publishes quarterly availability and performance statistics for these APIs at https://developers.cib.bnpparibas.com/index.php/docs/psd2-kpi. Those PDFs report availability and response time, not a request quota. guidance: - Honour 429 immediately; do not retry tight. - Exponential backoff with jitter, since no reset time is signalled. - >- Prefer incremental transaction sync via afterEntryReference over re-pulling full history, which is the single biggest reduction in call volume available on this API. note: >- limit_count is 0 because the provider documents no limits — an honest zero, recorded. A previous version of this file carried five invented tiers (free/professional/enterprise at 10/100/1000 requests per minute with 1k and 100k monthly quotas) and a full set of X-RateLimit-* headers, all written by a 2026-05-04 bulk scaffold sweep. None of it came from BNP Paribas, and none of those headers is returned by this API. It has been removed. maintainers: - FN: Kin Lane email: kin@apievangelist.com