Limits and locations
Usage quota
Each company has a monthly allowance of API calls. Every successful call counts against the company the credential belongs to, whether you use an API key or an OAuth token. Calls that fail authentication or authorization are not counted. A company without the Public API add-on has a small free allowance, and the add-on raises it. Both numbers are set per environment, and the add-on's plan determines yours. Check your plan, or ask support, for the exact figures.
When the allowance is used up, calls are refused with a 403 and a message saying so, until the month rolls over or the allowance is raised.
Token endpoint limits
- Each IP address may make 120 token requests per minute.
- Ten failed attempts against one client ID lock that credential for 15 minutes. A successful request clears the count, so the owner's integration is not affected by someone else guessing.
Cache the access token and reuse it until it is close to expiring.
Locations
A company can have several locations. Most operations act on the location the credential belongs to. Some can span locations:
- Multi-location operations return data for every location the credential can reach. Pass
restrictByLocations(a list of location IDs separated by commas or semicolons) to narrow the result. - Cross-location operations take a
locationId, and the credential must be allowed to act for that location. - Resellers can act as one of their merchants. With an API key, append
:LOCATION_IDto the key. With OAuth, passlocation=LOCATION_IDwhen you request the token, and the token is issued for that merchant.
Paging
List operations that return many rows are paged. They take a page number in the path and return {"data": [...], "pages": N, "version": V}, with 50 rows per page. Pass the version from your last full sync to receive only what changed since.
There is no bulk export of a whole catalogue in this reference, and pulling one page after another to copy it is not a supported pattern. To keep an external copy of your data current, subscribe to webhooks and fetch individual records when they change.