Rate limits
MIOSA rate-limits API requests per workspace and per endpoint group. When you exceed a limit, the API returns HTTP 429 with a Retry-After header telling you how many seconds to wait before retrying.
This page covers request throttling only. Hard caps that are not about request rate - concurrent sandboxes, exec and upload limits, webhook retries, browser token TTL - and everything billable live on Pricing and limits.
Request limits
| Scope | Limit |
|---|---|
| Per workspace | 600 requests per minute |
| Per endpoint group | 60 requests per minute |
All /egress/* endpoints | Current limit returned in X-RateLimit-* headers |
Limits can vary by key and policy. Every response carries the current numbers in X-RateLimit-* headers, so read them rather than hardcoding the values above.
Handle a 429
import time, requests
def call(url, **kwargs):
while True:
res = requests.get(url, **kwargs)
if res.status_code != 429:
return res
time.sleep(int(res.headers.get("Retry-After", "1"))) Back off for the number of seconds in Retry-After, then retry. Do not retry in a tight loop; 429 is a signal to slow down, not to try harder.
On the opt-in runner endpoint there are two distinct 429s: rate_limited is the per-key or per-tenant limit, and runtime_busy (with Retry-After: 0) means the runner is at its admission limit and you should retry the request.