# A2P Messaging API rate limits

A2P Messaging HTTP traffic is rate-limited per account and per endpoint. Each response reports the current window through X-RateLimit headers, and breaching the limit returns 429.

**Language:** en
**Audience:** developer
**TLDR:** Limits are counted per account and per endpoint over a 60-second window, shared by all the account's tokens: 1200 requests for POST /sms, POST /sms/bulk (one call is one request, with its own counter) and most endpoints, but only 10 for GET /sms and 20 for GET /sms/{id}, so track delivery with DLR webhooks instead of polling. Going over returns 429 with a plain-text body; retry after X-RateLimit-Reset. For a higher ceiling, open a ticket.
**Docs index (every page):** https://staging-instasent-docs-nextjs.oscar-284.workers.dev/llms.txt
**This zone's index:** https://staging-instasent-docs-nextjs.oscar-284.workers.dev/a2p-messaging-api/llms-full.txt
**This page:** https://staging-instasent-docs-nextjs.oscar-284.workers.dev/a2p-messaging-api/http/rate-limits/ (HTML) · https://staging-instasent-docs-nextjs.oscar-284.workers.dev/a2p-messaging-api/http/rate-limits.md (Markdown)

Every A2P Messaging endpoint enforces a ceiling of requests per 60-second window. The counter is kept per account and per endpoint: all the tokens of an account share one counter for each endpoint, so spreading traffic across several tokens does not add capacity. If you need more throughput on a specific endpoint, open a ticket with the expected peak rate and we will raise the ceiling on your account.

## Limits per endpoint

| Endpoint                                                                        | Requests per 60 seconds                                                                                                        |
| ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| `POST /sms`                                                                     | 1200                                                                                                                           |
| `POST /sms/bulk`                                                                | 1200. One call counts as one request, however many messages it carries, and it has its own counter, separate from `POST /sms`. |
| `GET /sms`                                                                      | 10                                                                                                                             |
| `GET /sms/{id}`                                                                 | 20                                                                                                                             |
| `POST /lookup`, `GET /lookup`, `GET /lookup/{id}`                               | 1200 each                                                                                                                      |
| `GET /organization/account`                                                     | 1200                                                                                                                           |
| `GET /sms/price-profile/me/countries`, `GET /lookup/price-profile/me/countries` | 1200 each                                                                                                                      |

With so few reads allowed on `GET /sms` and `GET /sms/{id}`, track delivery through [DLR webhooks](/a2p-messaging-api/http/dlrs) instead of polling.

## Reading the headers

Every response includes three headers with the current window state. Log them in production — they are the cheapest way to spot a client that is about to hit the wall.

```
X-RateLimit-Limit      1200
X-RateLimit-Remaining  1195
X-RateLimit-Reset      1893452400
```

| Header                  | Meaning                                       |
| ----------------------- | --------------------------------------------- |
| `X-RateLimit-Limit`     | Total requests allowed in the current window. |
| `X-RateLimit-Remaining` | Requests left before the window tightens.     |
| `X-RateLimit-Reset`     | Unix timestamp when the counter resets.       |

## When you hit the limit

Requests that exceed the window return **`429 Too Many Requests`**. The body is the plain text `You exceeded the rate limit` (not JSON); the `X-RateLimit-Reset` header tells you when to retry.

> **Tip**: Back off exponentially rather than retrying in a tight loop. A client that hammers a 429 response keeps the window full and never recovers — waiting until `X-RateLimit-Reset` resolves the situation cleanly.

## What's next

- **[Errors](/a2p-messaging-api/http/errors)** — every status code you might receive, including `429`.
- **[API Reference](/a2p-messaging-api/http/reference)** — per-endpoint documentation.

---

This is one page of the Instasent documentation. For the complete machine-readable index of every guide and API reference, fetch https://staging-instasent-docs-nextjs.oscar-284.workers.dev/llms.txt — start there for full context.
