Skip to main content

How rate limiting works

Gorillaa Mail enforces rate limits per API key and per organization to ensure fair usage and platform stability. When you exceed a limit, the API returns 429 Too Many Requests. All authenticated responses include rate limit headers:

Per-endpoint limits


Organization-wide limit

In addition to per-endpoint limits, there is a global organization-wide cap:

Test mode limits

API keys prefixed with grl_test_ have reduced limits:
Test mode daily/lifetime limits count each recipient separately. An email to 5 recipients counts as 5 against the limit.

Handling rate limits

When you receive a 429 response:
  1. Read the X-RateLimit-Reset header to know when the window resets
  2. Use exponential backoff with jitter for retries
  3. Include an X-Idempotency-Key for send requests to prevent duplicates on retry

Monitoring your usage

Check remaining quota before making requests:

Tips for staying within limits

Instead of calling POST /v1/emails 100 times, use POST /v1/emails/batch with up to 100 emails in a single request.
If you poll GET /v1/emails/:id for delivery status, cache results for terminal states (delivered, bounced, failed).
For aggregate delivery metrics, use GET /v1/stats instead of fetching individual email statuses.
Avoid burst patterns. Distribute API calls evenly throughout the hour window.