# Rate limits

How many requests you can make, and what happens past that.

HTML version: https://dyme.earth/affiliates/build/limits

Limits are counted in requests. Each call counts as one, except `POST /links`, which counts one per URL you send.

## Limits

| Tier | Limit | Window | Counted per |
|---|---|---|---|
| No key | 30 requests | 1 hour | IP address |
| Standard key | 2,000 requests | 1 day | key |
| Partner key | 20,000 requests | 1 day | key |

The window resets on the hour (no key) or at midnight UTC (keys). The API and the MCP server draw on the same allowance for a key.

## Headers

Every response tells you where you stand:

```http
X-RateLimit-Limit: 2000
X-RateLimit-Remaining: 1994
X-RateLimit-Reset: 1790208000
```

`X-RateLimit-Reset` is a Unix timestamp.

## Over the limit

You get a `429` with `Retry-After` in seconds and the usual error body:

```json
{ "error": { "code": "rate_limited", "message": "Without a key the limit is 30 requests an hour. Apply at https://dyme.earth/affiliates; approved affiliates can ask for an API key." } }
```

Refused requests don't count against you.

## Need more?

If you'll need more than 2,000 requests a day, tell us what you're building and we'll move you to the partner tier. See [authentication](https://dyme.earth/affiliates/build/authentication).
