# Limits and quotas

Daily calls per key, keys per account, one call at a time, the X-Quota-Remaining header and what a 429 means.

| Limit | Today | When you reach it |
|---|---|---|
| Calls per day | 2,000 per key, and 2,000 per connected app | `429` until 00:00 UTC |
| Calls at once | 1 per key or connected app | `429` until the running call finishes |
| Active keys | 3 per account | Creating a fourth fails; revoke one first |
| Rows per call | Set per tool (for example `limit` up to 100, `years` up to 20) | `400` naming the parameter |

## Calls per day

- Each key, and each connected app, may make **2,000 successful calls per UTC day**. The count resets at **00:00 UTC**.
- REST and MCP calls with the same credential count together.
- **Only successful calls count.** A call that fails (a bad parameter, an unknown ticker, a busy key) does not use quota.
- The limit is per credential, not per account: your keys and connected apps each have their own 2,000.

When the day's calls are used, every call with that credential gets a `429` until midnight UTC:

```json title="429 Too Many Requests"
{"detail": "This API key has used today's 2000 calls. The quota resets at 00:00 UTC (2026-10-08 00:00 UTC)."}
```

Over MCP the same sentence comes back as the tool's error text, so the assistant can tell you.

## One call at a time

Each key, and each connected app, runs **one call at a time**. A second call that arrives while the first is still running is refused straight away, without being counted:

```json title="429 Too Many Requests"
{"detail": "Another call with this API key is still running; the API serves one call at a time per key. Retry when it finishes."}
```

Make calls one after another. If you do meet this message, wait a moment and retry; the [Python](/developers/quickstart/python) and [JavaScript](/developers/quickstart/javascript) quickstarts include a helper that does it. Assistants that call several tools at once get a tool error saying the same thing, and usually retry on their own.

## The X-Quota-Remaining header

Every successful REST response carries the calls the credential has left today, after the one just made:

```http title="Response header"
X-Quota-Remaining: 1987
```

The header is left out when the daily limit is switched off, or when the count cannot be read at that moment; that never fails the call. MCP responses have no headers you can see, so check usage in your account instead.

## Keys per account

An account holds up to **3 active keys**. Creating a fourth gives "You already have 3 active API keys. Revoke one to create another." Revoked keys do not count.

## Seeing your usage

[Account → API & MCP](/account/api) shows today's calls against the daily limit, and the last 30 days per day and per key or connected app.

## Fair use

The quotas are generous for research, notebooks and assistants. They are not meant for copying the dataset: using the API to mirror our data, or spreading calls over extra keys or accounts to get around the limits, is against the [Terms](/terms#api). We may change the limits; when a change affects you, we email you first, and it is noted in the [API changelog](/developers/changelog).

Credits are a separate meter that does not block anything today: see [Credits](/developers/concepts/credits).
