specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Ortto providerId: ortto created: '2026-06-25' modified: '2026-08-13' generated: '2026-08-13' method: searched source: https://help.ortto.com/a-235-rate-limits reconciled: true tags: - Marketing Automation - CDP - Customer Data Platform - Analytics - Email - Rate Limiting - Quotas - Throttling description: >- Ortto publishes a dedicated rate-limit reference. The request-rate ceiling is tied to the subscription plan — 10 requests per second on Professional and 30 requests per second on Business and Enterprise (negotiable) — layered on top of a per-IP ceiling of 2,000 requests per 10 seconds and 6,000 per 60 seconds. A separate bad-request limiter bans an IP for 15 seconds after 15 malformed or 15 failed-credential requests in a 15-second window. Payload caps apply independently: 100 contacts or 100 activities per request, 2 MB per payload, 16 kB per individual activity, and 50 events per custom activity per contact per 24 hours. On exhaustion the API returns 429 with a JSON body carrying the error code "rate-limit" and a try-in-seconds field; Ortto returns no X-RateLimit-* or RateLimit-* response headers, so a client's only runtime signal is the body of the 429 itself. notes: >- The Starter plan is not listed in the rate-limit table; only Professional, Business and Enterprise carry published request-rate ceilings. Enterprise limits are negotiable on request. sources: - https://help.ortto.com/a-235-rate-limits - https://help.ortto.com/a-714-api-error-responses - https://help.ortto.com/a-257-create-or-update-one-or-more-people-merge - https://help.ortto.com/a-271-create-a-custom-activity-event-create responseCodes: throttled: 429 headers: request: [] response: [] note: >- No rate-limit response headers are documented. Retry timing is carried in the 429 JSON body as try-in-seconds, not in Retry-After. retryAfter: header: false bodyField: try-in-seconds limits: - name: Professional Plan Request Rate scope: account plan: Professional metric: requests limit: 10 window: 1s notes: 10 requests per second on the Professional plan. - name: Business Plan Request Rate scope: account plan: Business metric: requests limit: 30 window: 1s notes: 30 requests per second on the Business plan. - name: Enterprise Plan Request Rate scope: account plan: Enterprise metric: requests limit: 30 window: 1s notes: 30 requests per second, negotiable upon request. - name: IP Request Rate (10s) scope: ip metric: requests limit: 2000 window: 10s - name: IP Request Rate (60s) scope: ip metric: requests limit: 6000 window: 60s - name: Bad Request Limiter scope: ip metric: bad_requests limit: 15 window: 15s penalty: 15-second IP ban notes: 15 malformed requests in 15 seconds triggers a 15-second IP ban. - name: Failed Credential Limiter scope: ip metric: failed_auth_requests limit: 15 window: 15s penalty: 15-second IP ban notes: 15 failed-credential requests in 15 seconds triggers a 15-second IP ban. - name: People Per Merge Request scope: request metric: records limit: 100 notes: Up to 100 people per /person/merge call. - name: Activities Per Create Request scope: request metric: records limit: 100 notes: Up to 100 activity events per /activities/create call. - name: Payload Size scope: request metric: bytes limit: 2097152 notes: 2 MB maximum total payload size. - name: Individual Activity Size scope: request metric: bytes limit: 16384 notes: 16 kB maximum per individual activity. - name: Custom Activity Events Per Contact scope: contact metric: events limit: 50 window: 24h notes: 50 events per custom activity per contact per 24 hours. - name: Activity Backdating Window scope: request metric: days limit: 90 notes: >- Activities may be backdated up to 90 days or the configured data-retention period. - name: Transactional Email Attachments scope: request metric: attachments limit: 5 notes: Up to 5 base64-encoded attachments per transactional email. policies: - name: Regional Endpoints description: >- Use the AU or EU service endpoints for accounts whose instance region is set accordingly; limits are enforced per instance. - name: Async Processing description: >- Set async true on large merge batches so Ortto queues processing instead of handling it inline. - name: Backoff Strategy description: >- Clients should back off for the number of seconds returned in the try-in-seconds field of the 429 body, with jitter. There is no Retry-After header to honor. limit_count: 14 maintainers: - FN: Kin Lane email: kin@apievangelist.com