specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Justworks providerId: justworks created: '2026-05-25' modified: '2026-05-25' reconciled: false tags: - PEO - Payroll - HR - Rate Limiting description: | Rate-limit posture for the Justworks Partner API. Justworks does not publish a per-key request-per-second ceiling in its public documentation; instead it enforces token validity windows, cursor-paginated reads, and bounded write batches as the primary throughput controls. Webhook delivery is at-least-once with automatic retries and per-installation circuit breaking that closes a webhook after sustained failures. sources: - https://public-api.justworks.com/v1/docs responseCodes: throttled: 429 quotaExceeded: 429 algorithm: undocumented tokens: accessTokenTtlSeconds: 86400 refreshTokenTtlSeconds: 2592000 pagination: style: cursor maxPageSize: 100 defaultPageSize: 100 limits: - surface: Read endpoints (members, payrolls, paystubs, deductions, time-off, company) pageSize: 100 paginationStyle: cursor note: All list endpoints cap limit at 100 and return a next_cursor for continuation. - surface: Deductions create/update/cancel batchSize: bounded note: Bulk operations accept multiple items per request with per-item operation_id idempotency. webhooks: deliverySemantics: at-least-once retryStrategy: automatic closeOnSustainedFailure: true resumeEndpoint: /v1/webhooks/{webhook_id}/resume idempotencyKey: event.id signatureHeader: X-Justworks-Webhook-Signature signatureTimestampHeader: X-Justworks-Webhook-Signature-Timestamp notes: - No published per-second or per-minute request ceiling. - Token expiry is the primary throughput governor on long-running integrations. - Partners should debounce around the 24-hour access-token TTL and refresh ahead of expiration.