Every live API key is limited per minute. The number comes from your Kilo Business plan and is enforced consistently across your integration.
| Plan | Requests / min per key |
|---|---|
| Starter | 60 |
| Growth | 180 |
| Enterprise | Custom (set on the account) |
There is also a network-level protection layer to prevent abusive bursts.
GET /capabilities includes rateLimits.requestsPerMinute (null means a custom/unlimited per-key cap).
When you hit the cap
HTTP 429:
{
"ok": false,
"error": "Too many requests. Slow down and retry after Retry-After seconds.",
"code": "rate_limited",
"retryAfterSeconds": 12
}{
"ok": false,
"error": "Too many requests. Slow down and retry after Retry-After seconds.",
"code": "rate_limited",
"retryAfterSeconds": 12
}Headers:
Retry-After— seconds to waitRateLimit-Limit— your plan capRateLimit-RemainingRateLimit-Reset— unix time when the window ends
Backoff and retry. Do not tight-loop.
Unusual key activity
Kilo may flag unusual key activity and notify owners/admins before access is suspended. If you confirm the traffic is yours, dismiss the warning in Settings → API & Webhooks. If not, revoke the key and issue a new one.
Changing the numbers
Plan defaults are set by your Kilo Business plan. For custom contracts, Kilo support can set an organization-specific ceiling.