specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/Plans provider: Snyk providerId: snyk created: '2026-05-08' modified: '2026-08-27' generated: '2026-08-27' method: searched reconciled: true tags: - Security - DevSecOps - Rate Limiting - Throttling description: >- Snyk publishes an exact numeric ceiling: 1,620 requests per minute per API key, with a one-minute rate-limiting interval. Exceeding it returns 429 Too Many Requests, and Snyk states that all requests above the limit are rejected until requests stop for the duration of the interval. Snyk also reserves the right to introduce new limits without treating it as a breaking change, and tells clients to handle 429 and retry safely. Runtime signalling is thin: the REST OpenAPI declares a `retry-after` response header on the 429 responses of the two asynchronous export operations, but there are NO RateLimit-* or X-RateLimit-* headers anywhere in the contract, so a client cannot see how much budget it has left before it hits the wall - only that it has hit it. sources: - https://docs.snyk.io/developer-tools/snyk-api/rest-api/about-the-rest-api - https://api.snyk.io/rest/openapi/2026-03-25 - https://docs.snyk.io/developer-tools/snyk-api/authentication-for-api limit_count: 3 responseCodes: throttled: 429 unauthorized: 401 serverError: 5xx headers: request: - name: Authorization note: The rate-limit bucket is keyed on the API key presented here. response: - name: retry-after type: integer unit: seconds example: 45 declared_on: 429 responses of POST /orgs/{org_id}/export and POST /groups/{group_id}/export source: components/headers/RetryAfter in the live REST OpenAPI - name: snyk-request-id type: uuid note: >- Returned on every response including 429. Not a rate-limit header, but it is the identifier Snyk asks you to quote when reporting throttling problems. absent: - RateLimit-Limit - RateLimit-Remaining - RateLimit-Reset - X-RateLimit-Limit - X-RateLimit-Remaining - X-RateLimit-Reset absent_note: >- Confirmed by scanning the full 2026-03-25 REST OpenAPI document - zero occurrences of any RateLimit-* or X-RateLimit-* header name - and by an unauthenticated live request to https://api.snyk.io/rest/self on 2026-08-27, whose 401 carried no rate-limit headers either. limits: - name: Per-API-key request rate scope: api-key metric: requests limit: 1620 burst: null timeFrame: minute window: 60 status_on_exhaustion: 429 source: https://docs.snyk.io/developer-tools/snyk-api/rest-api/about-the-rest-api notes: >- "There is a limit of 1620 requests per minute, per API key. All requests above the limit will get a response with the status code 429 - Too many requests until requests stop for the duration of the rate-limiting interval (one minute)." Applies to the REST API; Snyk documents no separate published figure for the V1 API. - name: API entitlement by plan scope: account metric: tier_eligibility limit: enterprise-only notes: >- Not a throughput limit but the gate in front of it. Snyk states that for Free and Team plan users the personal token does not have access to the API and may be used only for IDE, CLI and CI/CD authentication. API use is an Enterprise entitlement, with service accounts recommended for automation. - name: Asynchronous export jobs scope: organization metric: export_jobs limit: unpublished status_on_exhaustion: 429 notes: >- POST /orgs/{org_id}/export and POST /groups/{group_id}/export are the only two operations in the contract that declare a 429 response, and they are the only two carrying a retry-after header. Snyk does not publish the concurrency number; the contract only tells you that these operations can be throttled and will tell you how long to wait. policies: - name: Retry on 429 description: >- Snyk states that clients are expected to handle 429 correctly and that such requests can be retried later safely. Where retry-after is present, honour it; elsewhere back off for the remainder of the one-minute interval. - name: New limits are not breaking changes description: >- Snyk reserves the right to introduce new rate limits from time to time to maintain system health, and explicitly says this is not considered a breaking change. Clients must not treat the 1,620/min figure as a contract guarantee. - name: Prefer the Export API over pagination description: >- For large data pulls use the asynchronous Export API rather than paginating issue lists, which is the pattern that most often exhausts the per-key budget. - name: Regional endpoint selection description: >- Call the base URL for your tenant's region - api.snyk.io, api.us.snyk.io, api.eu.snyk.io or api.au.snyk.io. Tokens do not cross regions. maintainers: - FN: Kin Lane email: kin@apievangelist.com