Skip to content

API Policies

The complete, product-wide rules of engagement: request-rate limits (and which layer enforces each), the token-metering / quota model, WebSocket connection limits, the versioning and deprecation promise, request size and timeout limits, and per-data-family freshness. Every published number is enforced in configuration. Two things to read carefully: (1) a 429 from the gateway-enforced families (Company Financials, XBRL) does NOT carry Retry-After / X-RateLimit-* headers — only the app-wide default limiter and the tighter per-route limits do; (2) point-in-time data selection is available for covered XBRL companies on the standardized annual/quarterly base-metric cells only, not on every cell. No authentication required; served free.