Overview
Rate limits are applied per account. Most are measured in requests per minute, and the lender directory endpoints also have daily caps. When you exceed a limit, the API returns 429 Too Many Requests.
Your current rate limits are visible in the GET /me response under platform.rate_limits.
Default limits
Authenticated Lev API endpoints use two minute-level buckets on every request:
| API tier | Account-wide limit | Per-endpoint limit |
|---|---|---|
free | 30 requests/minute | 10 requests/minute |
standard | 100 requests/minute | 20 requests/minute |
enterprise | 500 requests/minute | 60 requests/minute |
The account-wide bucket is shared across all authenticated v2 endpoints for the active account. The per-endpoint bucket is keyed by account and endpoint, so one busy endpoint does not consume the whole account budget.
Your current tier and limits are visible in GET /me under platform.api_tier and platform.rate_limits.
Public unauthenticated endpoints use fixed limits:
| Endpoint | Limit |
|---|---|
POST /api/external/v2/auth/validate-api-key | 10 requests/minute |
GET /api/external/v2/health | 100 requests/minute |
Lender directory daily caps
The lender directory endpoints also have a daily cap per account, on top of the minute-level buckets:
| Endpoint | Default daily cap |
|---|---|
GET /api/external/v2/lenders/directory | 30 requests/day |
GET /api/external/v2/lenders/{org_id} | 100 requests/day |
Every request to these endpoints counts toward the cap, including ones rejected with 400, 404, or 422. Past the cap, the endpoint returns 429 with limit_type set to lender_directory_daily_cap or lender_detail_daily_cap.
On a daily-cap 429, retry_after_seconds in the body is the length of the window (86,400 seconds), not the time left. Read the Retry-After header (seconds) or X-RateLimit-Reset (Unix time) to see when the cap resets, and don't retry before then. Backoff doesn't help with a daily cap.
Your account's caps are in GET /me under platform.rate_limits.lender_daily_caps. To request a higher cap, contact help@lev.com.
Handling rate limits
When rate limited, the API returns:
{
"request_id": "...",
"error": {
"status": 429,
"type": "rate_limit_exceeded",
"message": "Per-minute API rate limit reached. Contact help@lev.com if you need a higher tier.",
"details": {},
"limit_type": "requests_per_minute",
"retry_after_seconds": 60
}
}Best practices:
- Implement exponential backoff — wait progressively longer between retries
- Use bulk endpoints where available instead of many individual requests
- Cache responses for data that doesn't change frequently (e.g., market data, asset types)
- Use sparse fieldsets to reduce payload sizes and improve response times
- Monitor your usage via the
GET /meendpoint to stay within limits