- Public API group: 600 requests per minute.
- Chat turns: 60 requests per minute.
- OAuth token attempts: 60 requests per minute per client address.
- MCP protocol requests: 600 requests per minute per credential.
429 with code rate_limit_exceeded. Retry with exponential backoff and jitter. For chat retries, include a stable requestId so a network retry cannot create a second turn.
Management routes also enforce their own operation, credential and workspace limits. Follow a returned numeric Retry-After when present. The CLI does not automatically retry requests; reconcile the server outcome before retrying a write after a timeout.