Reference

Rate limits

One limit is actually enforced against your traffic today: 600 requests per minute per IP. Everything else on this page is either a narrower cap on one endpoint family, or a budget we design against and have not switched on yet. This page says which is which, so you do not build a retry strategy around a number we do not apply.

Updated Sep 3, 2026

What is enforced today

600 / min / IPGlobal. Applies to every request from one address, whatever your token holds. This is the one you will hit first, and it is shared across everything your server sends.
120 / minSubscription endpoints. The only per-endpoint throttle in force.

Velora is designed to rate-limit per action, per client— each budget tied to a specific write-heavy endpoint, or to the OAuth scope behind it, counted against your application's access token over a rolling one-minute window. Read endpoints are not individually throttled today.

Handling a rate limit

When you exceed a limit you get a 429 Too Many Requests. Where a Retry-After header is present it tells you how many seconds to wait — honor it. Do not depend on it being there: back off exponentially either way, so your client behaves whether or not the header arrives.

Response 429
HTTP/1.1 429 Too Many Requests
Content-Type: application/json
Retry-After: 45

{
  "statusCode": 429,
  "message": "ThrottlerException: Too Many Requests"
}
Retry logic — JavaScript
async function makeRequestWithRetry(url, options, maxRetries = 3) {
  for (let attempt = 0; attempt < maxRetries; attempt++) {
    const response = await fetch(url, options);

    if (response.status === 429) {
      const retryAfter = parseInt(
        response.headers.get('Retry-After') || '60',
        10
      );
      console.log(`Rate limited. Retrying after ${retryAfter}s...`);
      await sleep(retryAfter * 1000);
      continue;
    }

    return response;
  }

  throw new Error('Max retries exceeded');
}

function sleep(ms) {
  return new Promise(resolve => setTimeout(resolve, ms));
}

Best practices

Respect Retry-After

It is the exact wait in seconds — do not retry sooner.

Use webhooks and the Events API instead of polling

Subscribe to events rather than repeatedly reading a resource.

Cache what does not change

Badges, profile data, and rosters change rarely — cache them.

Ask before you engineer around a limit

If a real integration needs more, a per-app raise is faster than a workaround.

Budgets by category — not yet enforced

Write and action endpoints are budgeted per category, tied to their OAuth scope. All windows are one minute unless stated. These are the budgets we design against and intend to enforce per app — treat them as the ceiling to build toward, not as a limit that will stop you. We would rather tell you that than let you design a retry strategy around a number we do not apply.

CategoryScopeLimitCovers
Chatchat:write30 / minSending chat messages on your channel
Channel roleschannel:roles:write30 / minGranting / removing VIP and moderator
Subscriptionssubscriptions:read120 / minSubscriber count and roster reads
Events API—120 / minEvent subscription management (per client)
Botsbot:write30 / minBot registration and management
Botsbot:commands10 / minSyncing bot command lists
OAuth—10 / minAccess-token generation
App management—5 / hourCreating new applications

A scope or endpoint not listed here has no dedicated per-minute cap today. We add caps as endpoints ship; this page is the source of truth and is dated at the top.

Endpoint reference

POST/api/developer/oauth/token10 / min

Token generation

POST/api/integrations/oauth/chat/channels/:channelId/messages30 / min

Chat messages (chat:write)

POST/api/integrations/oauth/channel-roles30 / min

Grant VIP / moderator (channel:roles:write)

GET/api/developer/subscriptions120 / min

Subscriber roster (subscriptions:read)

POST/api/developer/apps5 / hour

App creation

Sandbox, Production & Partner

TierLimitsNotes
SandboxStandard limits aboveEvery new app starts here. Full functionality, scoped to channels you select for testing.
ProductionStandard limits aboveApproved for public use across any authorizing user's channel. Same per-action limits as sandbox.
PartnerCustom, per-appRaised limits set on your specific application. Arranged with Velora staff — see below.

Need a higher limit? Custom rate limits can be arranged by communicating with Velora staff. Tell us your app, the endpoint or scope, the throughput you need, and why — email support@velora.tv or request a private session with Velora staff in the Velora Discord. We raise limits on a per-application basis for real integrations.

Next steps