Skip to main content
Most of what an organization can send is its credit balance. This page covers the limits on top of it.

One allowance per organization

Limits are enforced per organization, not per key. Every key issued to the same org shares one allowance, so adding keys does not multiply it.

Hourly ceilings

A few endpoints carry an hourly ceiling on top of the plan, and job polling draws from a bucket of its own: On the free plan the ceilings are additional: a Research call spends one of its 10 hourly slots and 10 credits from your plan. On paid plans the credits are the only limit. Each endpoint’s page notes its limit.

Headers

Limit state comes back as HTTP headers on every response, not in the body:

Retries

Every Croma operation is a lookup: repeating a request with the same body returns the same result and never creates or changes a record, so retrying after a timeout or a dropped connection is always safe. An optional Idempotency-Key header (any string up to 255 characters, a UUID works) comes back in the response, so you can tie a retry to its first attempt in your logs. Each attempt that reaches the API counts; a 429 tells you to wait for Retry-After seconds rather than retry immediately.

When you exceed a ceiling

Requests over an hourly ceiling return 429 with a rate_limit_error envelope and a Retry-After header (seconds):
Back off until Retry-After elapses (or X-RateLimit-Reset), then retry.
The limiter fails open: if the rate-limit backend is briefly unavailable, requests are allowed through and no X-RateLimit-* headers are emitted. Don’t depend on the headers always being present.

Next: Errors

The error envelope and every error code.