Docs home

Headers

Authenticated requests send X-API-Key or Authorization: Bearer (see Authentication). Optionally send your own X-Request-Id for tracing. We echo it back, or generate one (e.g. req_...) if you don't.

X-API-Key: YOUR_API_KEY
X-Request-Id: req_01hxyz…

Authenticated responses include X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset, your per-minute limit, calls left in the current window, and seconds until it rolls over. Separate from your monthly quota. On rate_limited (429), Remaining is 0 and a Retry-After header (seconds) tells you how long to wait before trying again. Concurrent callers share the team allowance, so another request can use capacity during that wait.

X-Request-Id: req_01hxyz…
X-Served-From: Virginia
X-RateLimit-Limit: 60
X-RateLimit-Remaining: 59
X-RateLimit-Reset: 42

Burst capacity lets you briefly send requests faster than your sustained rate. Burst requests still count toward your monthly quota. When X-RateLimit-Burst is present, capacity replenishes continuously. Limit is the sustained requests per minute, Burst is the bucket capacity, Remaining is the current estimate, and Reset is seconds until full recovery if no more calls arrive. On a 429, use Retry-After for the next attempt; you do not need to wait for the bucket to fill completely.

X-Served-From is the edge that answered, where in plain language (Virginia, Tokyo, …), so you can see where your request was answered.

Error bodies include that same request_id, copy it from Activity in the dashboard if you contact support.

The Parse-Version response header identifies the API version that answered. Send an optional Parse-Version request header to pin your application to a supported contract. Requests that omit it use the team setting in Settings → API version. Your authentication and lookup URL stay the same.

Questions? Email